The Privacy Responsibility Episode
Transcript
Introduction to the Guest and Topic:
Host Allie Krings introduces Mark Hinely, JD, Vice President of Privacy Assurance Services at Kirkpatrick Price. The conversation focuses on privacy responsibility across organizations and how privacy should be viewed as a shared responsibility rather than a function owned by a single department. Mark shares his background, explaining that his role is centered on helping companies protect personal data and develop privacy programs that build trust and reduce risk.
What Is Data Privacy?:
Data privacy is the practice of protecting information that can identify an individual, either directly or indirectly. This includes obvious identifiers such as names, email addresses, Social Security numbers, financial information, and healthcare data, as well as combinations of data points that can be used to identify a specific person.
Privacy is about ensuring personal information is collected, used, stored, shared, and retained appropriately based on the expectations established when the data was collected.
What Does Data Privacy Look Like Up Close?:
For Individuals:
Personal data includes information such as names, email addresses, IP addresses, location information, account numbers, healthcare records, financial information, and Social Security numbers. Individuals expect organizations to collect only the information necessary for a specific purpose and to protect that information appropriately.
For Companies:
Organizations must identify what types of personal data they collect and develop rules around how each category is handled. Different types of data require different levels of protection, and companies should determine who needs access and how long the information should be retained.
Why Is Privacy Everyone’s Responsibility?:
Many organizations mistakenly believe privacy belongs solely to the IT department, legal team, or a designated privacy officer. In reality, personal information flows throughout the entire organization.
Human Resources manages employee information, marketing collects customer information, product teams build systems that handle personal data, leadership approves business decisions involving data, and IT implements the controls that protect it. Because privacy impacts every department, every department has a role to play.
What Are the Biggest Gaps in Compliance?:
One of the most common gaps is organizations believing privacy does not apply to them because they operate in a business-to-business environment rather than directly serving consumers.
Another significant gap occurs when privacy is treated as an all-or-nothing compliance exercise. Mark explains that presenting privacy only as a threat of fines, lawsuits, or penalties often creates resistance instead of engagement.
Organizations also frequently fail to build even basic privacy checkpoints into their processes. Many departments simply do not have a step where they ask: “Are there any privacy considerations here?”
How Should Leadership View Privacy?:
Leadership teams often focus on costs, growth, operational efficiency, and risk management. Privacy programs should therefore be presented using those same business perspectives.
Privacy investments can:
- Build customer trust
- Improve organizational efficiency
- Reduce regulatory risk
- Support sales opportunities
- Strengthen reputation
- Differentiate the organization in competitive markets
Mark notes that privacy should not be viewed simply as an expense. Research and industry experience increasingly show that organizations often receive measurable returns on privacy investments.
How Should Marketing Teams Approach Privacy?:
Marketing teams gather and use substantial amounts of personal information. Their challenge is balancing customer engagement with responsible data use.
Key considerations include:
Collecting Only Necessary Data: Ask only for information needed to achieve a business purpose.
Honoring Consent Choices: If a customer opts out of tracking, newsletters, or marketing communication, those preferences should be respected.
Monitoring Third-Party Tracking: Marketing teams should understand what pixels, cookies, and tracking technologies are running on company websites and whether they were intentionally approved.
Protecting Customer Trust: Poor privacy practices create frustration and can damage a company’s relationship with customers before a sale even occurs.
How Should HR Teams Approach Privacy?:
Human Resources departments often collect and store large amounts of sensitive personal information.
Examples include:
- Social security numbers
- Compensation data
- Background checks
- Candidate information
- Interview recordings
- Employment records
One major privacy concern is data retention. Organizations should periodically review what employee and candidate data they continue to store and ask whether it is still necessary. Retaining unnecessary information increases the risk and impact of potential data breaches.
How Should Product and Development Teams Approach Privacy?:
Product and engineering teams are responsible for designing systems that collect, process, and store personal data.
Mark explains that privacy professionals are often viewed as “the fun police” because they raise questions that can slow development. However, privacy considerations are far easier and less expensive to address during design than after a product is launched.
Examples of privacy-aware design include:
- Supporting deletion requests
- Limiting data collection
- Building proper consent mechanisms
- Restricting data access
- Auditing data usage
Incorporating privacy from the beginning generally results in more efficient and secure products.
How Should Organizations Assess Personal Data?:
Organizations should regularly evaluate:
What Data They Collect
Understand exactly what personal information is being gathered.
Why They Collect It
Ensure every category of information has a legitimate purpose.
How Long They Keep It
Delete data that is no longer needed to reduce risk.
Who Has Access
Limit access to appropriate personnel and implement technical safeguards to prevent unauthorized use.
How Can Companies Ensure Compliance?:
Compliance begins by establishing clear policies that define how personal information is collected, stored, shared, and protected.
Organizations should:
- Define privacy responsibilities across departments
- Create clear rules for different types of personal data
- Establish privacy checkpoints within business processes
- Train employees on privacy obligations
- Conduct regular reviews of data retention practices
- Incorporate privacy considerations into product development and marketing activities
Perhaps most importantly, organizations should create opportunities for employees to simply ask: “Are there any privacy concerns here?” Mark emphasizes that even this small step can significantly improve privacy outcomes across the organization.
Final Thoughts:
Privacy is not solely a legal, technical, or compliance issue. It is a business responsibility that touches leadership, HR, marketing, product development, IT, and every employee who handles personal information.
Organizations that view privacy as a collaborative effort are better positioned to build trust, reduce risk, improve efficiency, and protect the personal information entrusted to them.
Notes
In this episode, host Allie Krings sits down with Vice President of Privacy Assurance Services Mark Hinely to challenge some of the biggest misconceptions organizations have about privacy.
From the common belief that “privacy doesn’t apply to us,” to the struggle of identifying what data truly requires protection, Mark explains why privacy is more than a checkbox exercise. Mark walks through how organizations should think about sensitive information, why compliance isn’t just a matter of black and white, and how establishing clear rules for handling different types of data can reduce risk while supporting business goals. A thoughtful approach to privacy often pays off in ways that leaders don’t expect (like true, measurable value).
At KirkpatrickPrice, we’re on a mission to help 10,000 organizations raise the bar for cybersecurity and compliance. Join Our Cybersecurity Mission. If you’re going to invest in an audit, it should deliver real value. That’s why we partner with you from audit readiness to final report, ensuring you get the assurance you deserve.
Ready to strengthen your security and compliance posture? Connect with an expert today and learn how we can help you meet your toughest goals.
Send a Question
Do you have a question for our podcast? Send it to us here.
