Episode 152
Listen to this episode on
Episode Transcript
Speaker 1 00:02
This is CyberSound, your simplified and fundamentals-focused source for all things cybersecurity.
Jason Pufahl 00:11
Welcome to CyberSound. I’m your host, Jason Pufahl, joined today by Alex Cox, attorney at Troutman Pepper Locke. You’ve been on before. I appreciate you joining again. I think the first time we chatted a bit informally around the idea of the risks for exercise-based tech and what some of that data is used for. I enjoyed the conversation as we come back, so I appreciate you joining again.
Alex Cox 00:41
Yeah, likewise. It was fun. Actually, it’s funny. I forgot that that’s what we talked about the last time. With Google’s new… I don’t kno…
Speaker 1 00:02
This is CyberSound, your simplified and fundamentals-focused source for all things cybersecurity.
Jason Pufahl 00:11
Welcome to CyberSound. I’m your host, Jason Pufahl, joined today by Alex Cox, attorney at Troutman Pepper Locke. You’ve been on before. I appreciate you joining again. I think the first time we chatted a bit informally around the idea of the risks for exercise-based tech and what some of that data is used for. I enjoyed the conversation as we come back, so I appreciate you joining again.
Alex Cox 00:41
Yeah, likewise. It was fun. Actually, it’s funny. I forgot that that’s what we talked about the last time. With Google’s new… I don’t know if you follow the new stuff that comes out in that space, but there’s the Fitbit now. All the whoop people are freaking out about it. It’s a big thing. How accurate are these trackers even? It’s fun, but from a privacy perspective, yeah, there isn’t any real new hot issues on that front. It’s just the same traditional.
Jason Pufahl 01:20
In a way, I think what we’re going to talk about today isn’t that far afield. It’s trackability. I have this argument regularly internally around voluntary surveillance to some degree, but maybe… What’s that?
Alex Cox 01:40
That’s just the world we live in. It’s all voluntary.
Jason Pufahl 01:43
A hundred percent.
Alex Cox 01:43
Yeah.
Jason Pufahl 01:44
You say something out loud and all of a sudden your phone perks up and tries to answer you. You’re like, man, I wasn’t even talking to you, right?
Alex Cox 01:51
Yeah. I always paranoidly turn off all the voice activated based things. Although sometimes there’s an update and a default gets triggered and you’re just like, wait, what? I didn’t know that.
Jason Pufahl 02:04
So actually, this is slightly different that we were going to talk about, but I think a really, really useful segue, which is privacy policies and privacy settings change all the time. So you may think you’ve done the right thing six months ago only for a setting to revert or the click-through policy to change and you’re committing to something different.
How often do you run into that as a challenge for people?
Alex Cox 02:32
I mean, honestly, pretty frequently and more frequently now. It’s funny, we didn’t think about talking about this, but July 1st, this next coming month, Connecticut’s amended privacy law goes into effect. The new amendments to the privacy law, which really do fundamentally change privacy compliance for large companies in the US or anyone who’s processing just data across all 50 states, including health data. So Connecticut’s law is going to trigger now. It used to be that…
So backing up just for one second, the state consumer privacy laws in the US have these various thresholds for when they apply. And typically it’s like, I process 100,000 or 50,000 or 25,000 residents’ data, and then I have to worry about the law applying. Or like in California, revenue threshold, like, oh, I have 25 million in revenue, I do business in California, got to worry about CCPA, right? Some scheme like that.
Connecticut sort of took a page out of Texas’s book, which had a really low threshold, like, just if you’re in Texas, you’re processing Texas personal information, the law probably applies to you. It’s like this weird SBA designation where if you’re not… And if you’re designated as a small business under the federal SBA designation, which is this really squishy concept that has a really low floor, like the revenue numbers are just super tiny, like any small business at any scale is going to…
Jason Pufahl 04:05
Any revenue, yeah.
Alex Cox 04:06
Yeah, is going to suddenly fall prey. And there’s some weird exceptions to that where like certain businesses have a really high threshold for just sort of accidents of history. And if you can claim you’re in one of those categories, maybe not, but whatever, long story short. And Connecticut just decided like, this game is annoying me.
If you process one iota of SPI from a Connecticut resident, our law applies to you. And it’s actually nice from a compliance regulatory perspective, because it used to be we would offer this menu of options on how to comply with US consumer privacy, right? In Europe, where we have the GDPR, there’s the establishment criterion, the targeting criterion, there’s a whole framework for how to figure out if you’re worried about GDPR from an extraterritorial basis.
But then in the US, it was always this annoying patchwork, right? And now it’s a little easier now with this Connecticut threshold, because it used to be that like, most people had California to worry about, Texas to worry about. And then there was this question like, what else do you have to worry about, right? And some people would take a piecemeal approach, some people would, you know, sort of throw their hands up and try to do a one size fits all approach. But there’s really two like styles of consumer privacy law in the US, it’s California’s version, the CCPA. And then it’s everybody else who kind of copied each other and made a vaguely similar law with mostly similar requirements, which is similar to California in the vast majority of ways. And in most like common, most people would see them as like, the same kind of thing. But California has their own magic words, which are different from the magic words everyone else agreed on. And so when you like don’t say the California magic words, you draw the ire of California’s dedicated regulatory agency that they’re the also the only state with their own special state agency, purely dedicated to enforcing the privacy law, and that gets its funding through enforcement of the price.
Like, the incentives are just way different there. So we’re always like, okay, it’s always worth doing the extra bit just to make sure they see you’re checking their boxes. And now it’s like, we can just say, look, do the California thing, do a multi state disclosure, which now, like Connecticut is the threshold I’m using for everyone, because everyone’s processing sensitive personal data of someone, right? I mean, a biometric data, any sort of health data, any sort of financial payment information, anything like that is going to make you processing sensitive personal information. They even made the concept of biometric information less precise. It used to be more, like more clear what they meant.
And then they were like, you know what, let’s make this vague, because then more things can be biometric, even if they’re not, like, really in the way we would think of them from a consumer risk perspective. And, you know, the amendments in some ways are challenging for clients. And in some ways, it makes it easier. Like, you just don’t spend as much time worrying about, you know, this applicability game and this sort of shell game that you’re doing where you’re like, okay, we apply here, we don’t apply there, we, you know, whatever.
Jason Pufahl 07:12
And if it feels like biometrics, it probably is biometrics. I mean, it kind of simplifies in that regard.
Alex Cox 07:17
Right. And it’s just a more direct thing. So it’s like, while I don’t love the additional obligations, I kind of like the simplicity of the threshold question now. You know, we don’t have this complicated conversation. And so, you know, someone with health tracker information now really does have to worry about making sure you disclose that you’re using those health trackers in your privacy notice in a more expansive way that maybe you wouldn’t have had to in the past. Like, maybe you weren’t doing business in Texas, didn’t have significant Texas resident data, or you’re outside of California, or you’re in California, but you’re under the thresholds for, you know, for business. Maybe you’re under 25 million in revenue because you’re a startup and you’ve got some new fitness tracker or some new little like AI product that does something, you know, that’s pretty common. A lot of startups aren’t at that revenue threshold. And so this now, it’s like, now I’m just like, look, just here’s your document. Let’s fill it out. Move on. We don’t have to like waste attorney time discussing if we think this applies. Let’s just assume you’re going to process health data because I know that you’re doing a health tracker and like, you know, let’s move past that. And so it’s kind of- Employee rate of return.
Jason Pufahl 08:28
Yeah.
Alex Cox 08:28
And it gets you to the meat of the question more quickly, which, you know, I think is constructive. So I guess that’s changed a bit in that way. Oh, and circling back to the defaults question, where this gets interesting is Connecticut requires, which is different than some of the other states, but again, this was added in this recent amendment, you to make it like crystal clear that, and again, this like was included in the prior version of the law that just made it like very clear, like this, we want this, you know, and they’ve added guidance to their site. They made it crystal clear that there’s this Global Privacy Control concept. I don’t know if you know about the GPC.
Jason Pufahl 09:09
Yeah. Not in depth. I mean, if you want to spend a second on it.
Alex Cox 09:12
Yeah. It’s basically this standard that websites can deploy that allows people to trigger a default on their application. So like in Safari or in Firefox or whatever you’re using to browse the site, you trigger a default and now your sort of privacy, it’s kind of like the old school do not track thing where you would like, your browser would just spew out this like, don’t track me, don’t track me, don’t track me signal. And every website would just say, we don’t respect them. Do not track signals.
Jason Pufahl 09:43
Yeah, we’re going to ignore that.
Alex Cox 09:44
And that was the whole thing. And now Connecticut’s like, look, you have to implement some standard way of allowing consumers to set a setting once and not have to constantly submit requests all the time everywhere.
Jason Pufahl 10:00
So in practical purposes, is that essentially then like auto select the don’t use cookies to track me type of like, you know, those types of things would work. You know, basically, I feel like that’s what GDPR did, right? It essentially made me click on the cookie banner, you know, for every website that I go to. Does it solve that problem?
Alex Cox 10:18
Sort of. And this gets, this is fun because this is what all the misinformation says on the internet. I say misinformation. It’s not, it’s not bad faith, but every like cookie banner description conversation conflates like these concepts, right? So everyone thinks like you reasonably do that the GDPR is what added the cookie banner requirement. Technically, there’s this separate law called the EU cookie law, or the UK cookie law, which is not exactly the GDPR, but it is now effectively, they’re enforced side by side, they’re talked about side by side, it’s basically the same thing.
But it’s not technically the GDPR with the cookie banner. And then in the US, the cookie banner proliferation is actually not motivated by these requirements. So Connecticut’s, you know, saying the do not track signals thing or requiring you to offer people rights to opt out of certain sorts of tracking activities. That’s actually has nothing to do with the tracking technology banners you’re seeing.
Jason Pufahl 11:22
Okay.
Alex Cox 11:22
The reason those are popping up, because you don’t need a tracking technology banner, right? First, California’s law for Connecticut’s law for none of these laws. I mean, you do in Europe, but in the US, you don’t need a cookie banner for sort of like a regulatory compliance reason. It’s all just trying to fight back against the state wiretapping litigation thing. So if, yeah, so you’re going to just get a nastygram from some private litigant who’s going to say, ah, we you shared data with Facebook or with LinkedIn through your tracker, your web tracker that you deployed on your site. You didn’t do that with my consent. Therefore, I’m going to claim I have a cause of action.
And in California, it’s CIPA. And the state courts have been happy to allow those cases to move forward. There’s some movement in Florida and in Pennsylvania on letting those cases move forward, but it’s not like California does. But then they got clever and they found this federal law that basically is the same thing as California law, but it just requires you allege a tort. So now everyone just, they say you’ve committed a tort and whatever tort they think is the best one to allege, they’ll find one and they’ll allege it. And then they’ll claim you violated the federal version of California’s SIPA law, which is like the wiretapping law. And so you just get these litigations now in every state. It used to be just California and now it’s everywhere. They still prefer California plaintiffs, but now what they do is they just bolt on a federal claim too. So they just cover all their base.
Jason Pufahl 13:11
Okay. Now, is there a thresholding for that? You’ve got integrated data to Facebook for tracking purposes, or you’re trying to collect all of that. Is it, hey, you’re a small business and the reality is your impact is low and so it’s not a big deal versus a larger business or does that matter?
Alex Cox 13:27
Yeah. I mean, you’re really up to how aggressive are private litigants going? So I’ve seen everything under the sun from the most unreasonable litigation ever, where they weren’t tracking anything. They even had a consent banner up. They did everything right. The people sued them and said, yeah, we’re going to file a complaint. And they filed a complaint in court and we’re trying to go after them. And they fought and won, but $80,000 later, who really won? And so this is kind of the problem. How much does it cost to… So it’s really a deterrence game.
Jason Pufahl 14:11
So actually, I’m going to segue a tiny bit because I’m curious about your opinion on this, and it just occurred to me.
Alex Cox 14:16
Yeah, sure.
Jason Pufahl 14:16
With the cookie banners, you get typically maybe one of three options. Hey, we collect cookies, accept or deny. Hey, we’re collecting cookies. I want the critical cookies tracked only, but not other cookies. And then sometimes it’s simply like we collect cookies and you literally have the okay button where you can’t opt out at all. And frankly, there’s a big part of me that always feels like, man, at least I appreciate that you’re not giving me a choice. Like you’re just saying, I’m collecting them. You can go to my website or not.
Alex Cox 14:52
Your no button is the X button on top of your browser.
Jason Pufahl 14:55
That’s it, right? But I’m always intrigued by what are the requirements? Because while I appreciate the honesty that you don’t give me an option, it also doesn’t quite really feel like it’s within the spirit of disclosure that way.
Alex Cox 15:11
Well, you’re kind of noticing the key here, which is there aren’t. There’s not a centralized… It’s not like the CCPA is saying, this is what we want to see your banner, or sorry, CPPA, the agency. It’s not like some centralized body is saying, this is what we want it to look like, like they do in the UK or in the EU, right? Which is why you’d see those necessary cookies, and then there’s the different criteria. And then it’s like a standardized form, right?
They’ve developed templates where they’re like, this is what we want to see. And funnily enough, the CCPA does allow you to accept what are called opt-out requests, which is like a category of consumer requests you can make under the CCPA. You can make those through a banner and the CPPA has issued guidance on how they like that to look. And when offering this type of process, there’s rules about what’s a pattern, what isn’t a dark pattern. And one of those rules is like you have to give binary options. So you can’t say like allow and allow less. You have to be like allow, disallow. You know, it doesn’t have to be countered.
Jason Pufahl 16:18
Yeah, concrete and clear.
Alex Cox 16:20
Right. And very frequently, you see like accept all, accept only necessary.
Jason Pufahl 16:25
That’s super common.
Alex Cox 16:26
Yeah. That would be a dark pattern if that was used to comply with the CCPA. So you get this funny quirk where like some companies can get away with doing that. Some companies are violating the CCPA when they’re doing that, and they might be doing this exact thing. And they might also both be subject to the CCPA. But one company is just not using their banner to effectuate opt-out requests.
They’re just saying, no, no, no, no. To make an opt-out request, go here. You know, we comply with the opt-out request standard. We just don’t do it through a cookie banner. So that gets kind of confusing for clients. You know, obviously, of course, it’s just confusing inherently. So, but yeah, that’s kind of how that works. Now, you can do the okay thing. Now, the point is, anything you’re seeing from a cookie banner from a U.S. company that’s not worrying about other compliance concerns, they’re doing it to deter litigation. So the people who say, okay, they’re the people who are saying, you know, direct, you know, online marketing is just super valuable for our business. Don’t want people to be able to turn off the trackers. So what we’re going to do is we’re going to put a banner that says, okay, we are tracking. What this does is it gives us an argument that people are being put on notice that we’re doing this. They’re confirming. Now there’s also, even within that, there’s gradients of that. I’m sure, you know, like you can go into a browser, you can see what trackers are running on any site through the magic of like knowing a tiny bit of HTML.
Like I’ve shown that to lots of people who are all shocked, by the way. Like it’s like they never, I don’t know.
Jason Pufahl 18:08
They never knew they were tracked and they’re wondering how they get all that great marketing.
Alex Cox 18:13
Like people think I’m like some sort of hacker man bringing this up. And I’m like, guys, like this is in the browser.
Jason Pufahl 18:17
Like just click your settings. You can look at it.
Alex Cox 18:19
Oh, jeez here. And I had a partner say to me like, well, I don’t, I’m going to be careful here. I don’t want to give advice on technology. And I’m like, guys, this is fine. Trust me. Like you’re so out of your depth that like, you don’t even know how crazy what you just said sounds like.
Jason Pufahl 18:33
Yeah.
Alex Cox 18:33
I’m, I’m looking at a, like, I know it looks like code, but all this is, is just LinkedIn, like Facebook. Like I’m just reading off of the list. What track is they’re running on this site? Like it requires no technical knowledge, but you know, the second something looks like it’s computery, a lot of people just freeze up.
Jason Pufahl 18:53
Yeah. Well, as soon as you click those, the ellipses that brings you into your settings, you’re probably doing something technical.
Alex Cox 18:58
Yes. Oh, naturally. I went developer settings. It’s a real dangerous, dangerous place. But yeah. So, I mean, it’s a prophylactic that you’re just trying to reduce the likelihood of someone suing you. You know, obviously the litigation people tell me that it’s not as good to have an okay button. You know, they’d rather have a yes, no button. That’s like express informed consent. You know, that’s really good. That’s a really high consent bar. You’re going to always win with that. The okay button, like someone might fight you. Like, is that really legit?
And then the question is like, does your website mechanically even do what it promises? You’d be shot probably like seven out of ten clients, like do this wrong. Like where they implement a banner. And then I always just go to the site afterward and I’m like, yeah. So like your banner fires, but like the cookies that fire no matter what, and they don’t, and your interaction with the banner has no effect on them. Or if it doesn’t work, correct. Like it fires and then you hit okay. And then it turns out like just weird stuff like that is often done wrong.
Jason Pufahl 20:03
So to some degree in the interest of time too, because I think you and I could easily chat through this for a while. One of the things that I love to do is, hey, what’s a practical thing? If you are a company that has a website, which I think is pretty much everybody, you can’t just present a banner that when you click okay, the banner goes away, but nothing actually happens. What is the expected behavior of that? What would you expect to see from a well-implemented banner? And I think maybe we should end there so people have a sense of, all right, I should make sure I do this.
Alex Cox 20:39
What I would recommend, and people take risk-based choices all the time, but what I would recommend to just put this to bed as best as you can, you know, a symmetric choice for consumers, yes or no, to tracking technologies. Make the banner only really talk about the tracking technologies. You don’t have to say like all cookies. You don’t have to do the GDPR thing. You can just say like, we will turn off marketing. We track you through whatever, whatever, blah, blah, blah. Here’s our privacy policy for more information. You can, usually people have their cookies, tracking technologies, like disclosures in their privacy policy. So you link to that, you know, and then you say, you know, say yes if you accept or say no, if you reject, and then you have to know. Something like that is what everyone should be doing.
They’re not, right? And there’s a risk gradient from there to nothing, right? But you’re just deterring litigation, you know? And that’s kind of like nice for business people, I find, they’re like, oh, I get this. I understand this concept. I’m not trying to do some sort of weird Kremlinology to understand what the regulators are thinking and what they’re going to do, right? I’m just figuring out who’s going to sue me and who’s not.
Jason Pufahl 21:54
Yeah, that’s fair. And, you know, anecdotally, because I know we’re not a large company and we don’t have huge traffic volumes, but I absolutely have an increase in people opting out now of, you know, please remove my data from your CRM, from whatever sources you maintain it. I feel like people are now starting to pay a little bit more attention to it. Clearly, right? It’s the minority, no doubt. But where I probably got, you know, a handful of requests a year, now I’m getting, you know, eight or ten a month. And, you know, that’s a definite increase. And I feel like people are more mindful of it.
Alex Cox 22:33
Are those coming from people or are they coming from third-party services?
Jason Pufahl 22:38
A mixture of both. Yeah, a mixture of both.
Alex Cox 22:41
Yeah. We’ve seen a real uptick in the sort of, you know, data management or kind of companies, you know, and those can be both privacy protective in the sense that they are making deletion requests like across the board. The dangerous part is like they often sort of do that thoughtlessly. And then so like you’re getting a bunch of people’s contact information that you like wouldn’t add previously.
Jason Pufahl 23:07
Yeah. And we’ve seen that for sure.
Alex Cox 23:09
When you wonder, you’re like, is this even helping these people? I mean, you know, there’s probably ways of doing that that are better. There are probably better providers and worse providers, right?
Jason Pufahl 23:19
Well, and you know, right, part of their value prop is to say, hey, I made 100, you know, data deletion requests on your behalf this month. Look at the value I provided. You know, that’s an element of it as well.
Alex Cox 23:31
Right. And we’ll ignore the fact that the deletion requests were large data companies who you would never have interacted with. Right.
Jason Pufahl 23:36
That don’t matter at all.
Alex Cox 23:37
But like to your point, or I guess maybe like to the company’s point, like how do they know who you’ve interacted with? Do you really want to put the effort into listing all of that? What if you missed things? That’s the whole value prop to your point, right? Like they’re doing it, you’re not doing it.
Jason Pufahl 23:53
So. That’s all. There’s no effort, right? You get a report that tells you what you’re doing, right? I feel like it’s like those dark web ID scans that say, oh, your password’s out there in the wild. And you’re thinking, yeah.
Alex Cox 24:03
Sure it is. My social’s out there in the wild too. And same with every other American.
Jason Pufahl 24:08
Exactly.
Alex Cox 24:08
Since 2016.
Jason Pufahl 24:08
And honestly, that’s often where I struggle, which is you don’t want to be complacent and just say, well, I know it’s out there. I’m not going to worry about it. But at the same time, it’s very difficult to rein it in or have any amount of control. And I think, it feels very similar in this sort of marketing web tracking space that we’ve essentially now circled around for the last 25 minutes. You don’t have a lot of control ultimately. And so maybe some centralization of these privacy settings, maybe that’ll be a step in the right direction if it’s implemented more broadly.
Alex Cox 24:43
Yeah. I think it will be constructive. I don’t know how well it’s going to work in full. I mean, I guess it’s going to be moderated by how much browsers are still the primary way we interact with people versus other things.
Jason Pufahl 25:02
Yeah. And you’re seeing that too, right? I mean, the transition to AI and using that as your primary research mechanism, starting to make browsers less critical.
Alex Cox 25:12
Which is a little scary in a lot of ways, but we’ll see how that all goes. I mean, yeah. Yeah. And AI is, again, it’s funny, such a powerful tool, but so often just wildly misused. And it’s the way that many people think of it. And I mean, people in positions of decision-making power in large companies, they often, they’re being pushed by investors to do AI stuff.
Jason Pufahl 25:41
Yeah. For sure.
Alex Cox 25:42
And this includes our law firm.
Jason Pufahl 25:45
Yeah. Us too.
Alex Cox 25:45
We got like, what are you doing with AI? And I’m like, I’m doing what’s good with AI. I’m not doing what’s dumb with it.
Jason Pufahl 25:51
But is it a critical part of your business? Are you embracing it? All those questions.
Alex Cox 25:56
It’s Excel. It’s another tool. It’s good at some things and it’s dumb at other things. Use it for what it’s good at and don’t use it for what it’s not good at. I don’t know. But I mean, this is just, we’ll see how long this craze lasts until they sort of figure out. I mean, I’m very, just candidly, I don’t understand how the, yeah, I looked at the economics of how much a token costs and how many tokens get used for certain outputs. I don’t know if that version of AI where we’re all buying tokens from these data centers and cloud providers and running, I don’t know how long that’s going to work. But I mean, at least from a personal perspective, I mean, I run like a bird model on my home server to know the songs. There’s so many cool uses of these technologies that don’t require, if you have your own hardware, you can do so much cool stuff. I think that’s going to only get better and better.
I think these huge mega scale things, I mean, it all depends right on whether or not making another step change in quantity of connections really does change qualitatively the output and we’ll see. And yeah.
Jason Pufahl 27:12
And the whole token model, we run the risk of turning it into a whole other topic, but that whole token model, it’s so arbitrary. I mean, you’ll be happily working along and then all of a sudden you hit your threshold and it’s like, yo, come back in five hours and you can finish the work that you’re doing. And you’re like, well, how do I have any idea? A token isn’t a word. It’s not a character. It’s this arbitrary thing. And yeah, it’s a brutal, as a consumer, it’s a brutal model to have to try to adhere to because you have no idea what’s happening.
Alex Cox 27:43
It’s wildly opaque. I mean, how do you even know and how do you trust that they’re accurate? I mean, from a consumer perspective, I’m an attorney. Let’s say my firm is buying tokens from Claude, which I think we do that. Obviously I’m not spending my time thinking about the business side of that, but I don’t know how I would gauge whether we’re getting a fair value or how many tokens are Claude churning through for a given request versus OpenAI and what’s the relative pricing on… I don’t know how I would compare the products in that way.
Jason Pufahl 28:22
Yeah. Well, I think the answer today is you really can’t. You have to decide whether or not the value is there versus the amount of times that you should have cut off for some period of time. And that’s where you’re at.
Alex Cox 28:34
And that’s the only way you can really gauge anything, right? It’s like at the end of the day, like, okay, is this working or is this not?
Jason Pufahl 28:39
That’s all right. Well, I don’t even know how long this has gone because I have a full screen and no tracking time. But I think as per usual, it’s a pretty organic conversation. This isn’t exactly what we envisioned talking about, but at the same time, I think it shows a lot of the challenges that are out there for what I would describe as pretty commonly used basic technology, right? I mean, the question marks around consumer privacy and marketing and basically web cookies and tracking we just spent 30 minutes on. And frankly, I think you’ve made it clear there’s a few ways that you want to do your banner that probably are appropriate, but ultimately the way the data is handled state by state is pretty variable and there’s a lot of decision points to still to be made here.
Alex Cox 29:33
Yeah. And at the end of the day, differently than most of the privacy space, which is very like, we’re worried about the regulators, we’re worried about the guidance, it’s very private litigation driven. So it’s just a very different game.
Jason Pufahl 29:47
All right. Well, we’ve got a good agenda for another conversation. So maybe in another couple of months, if you’re interested, you can come back on and continue chatting.
Alex Cox 29:57
Yeah. That sounds great.
Jason Pufahl 29:58
Well, as always. I hope people listen to this, got some value out of it and feel like walking away. They’re like, Hey, I understand that Connecticut’s got an increased privacy about coming out. I know there’s some cookie things I have to worry about. Um, you know, we can always dive more deeply into it. So if anybody has any, any feedback or questions, let us know, you know, we can craft another podcast around it that gives a little bit more specificity, but I appreciate you joining.
Alex Cox 30:19
Yeah, no, it was great.
Jason Pufahl 30:20
Yeah. Good. All right. Thanks, everybody.
Alex Cox 30:21
Cheers.
Speaker 1 30:22
We’d love to hear your feedback. Feel free to get in touch at Vancord on LinkedIn, and remember, stay vigilant, stay resilient. This has been CyberSound.


































































































