Data Privacy Regulations: Addressing Data Management and Cybersecurity – Alex Flanagan, Rollup.id
Alex Flanagan, co-founder of Rollup ID, explains why data privacy regulations will force organizations to address a wide range of data management and cybersecurity issues.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Alex Flanagan, who's a co-founder for Rollup.
I Dean. We're talking about the challenges the data privacy regulations are gonna have for developers and other folks because, well, the truth in the matter is we've gotten into a bad habit of collecting a lot of personal information and maybe not managing it as well as we should. Alex, welcome to the show.
Thanks for having me, Mike. Yeah, What's the fundamental problem from your perspective? I mean, we have all these data privacy regulations.
They seem to be lots of them, no shortage, but I'm not sure we really have the processes in place to kind of really adhere to them. And what do we gotta do and what do we gotta think about? Yeah, so startups are really just about going after their, the, the value that they've identified in the market.
And what happens is everyone ends up collecting data about customers, and it's all roughly the same data. And so there's this really large attack surface for people who are trying to collect that data, whether, you know, nefariously or otherwise. And, uh, yeah, as you mentioned, uh, governments are responding, uh, with increased regulation, and that puts this burden back on if back on large companies as well as startups to comply to this very, very, uh, kind of rich environment that's developing.
Do we need to change, therefore the application development processes themselves? Or is there some way to think about this as a data management issue? Who's supposed to step up and kind of help us address all this stuff?
Yeah, that's, um, that's what we do at roll up. So that's, we got into YC to build this globally distributed, uh, identity graph. That's the opportunity that our investors see is that each one of, yeah, every startup has to collect all of this data.
That means every startup needs a compliance team. Every enterprise needs a compliance team. Every startup needs a security solution.
All of the enterprises need a security solution. And you see the Fortune 500 spending something like $8 billion a year on G D P R compliance for the EU market alone. As you see G D P R in the EU and C C P A in California and all this other state level legislation, uh, uh, we think that there's a compliance treadmill developing and, and that really needs to be solved in a centralized way.
And that's what, that's what Rollup does. As we kind of work this whole process through, um, our workflow's a little too disjointed to deal with this. 'cause I feel like, you know, developers are doing one thing and the it people are doing another thing with the data, and everybody's not sure who's got what data when.
So do we really need to go in and kind of re-engineer those processes? That's the, the history of the company. We started it five years ago to solve problems exactly like what you're talking about in banking.
So if you think about a bank, uh, there's a bunch of data silos internally, and no one knows who has what data on whom. And there's, um, um, uh, you know, they've been trying to, uh, do the golden customer record for 10 years at some of these places. And yeah, we really do need a unified approach to digital identity, even within organizations, just so that companies know who they're talking to.
Um, and what we noticed was that we can blow that out and make that global and, uh, uh, build something that, that works for really big companies and really small companies too. It really shouldn't be, um, a development team task to manage privacy regulation, just as Stripe has solved sales taxes at the state level, so the developers and local level. So the developers don't need to have a big table somewhere of all of the different taxes and a, a set of business rules for how they apply.
Uh, roll up does the same thing for compliance. So we, uh, uh, compliance is a service stripe for compliance. It seems to me at least, or feels like that a lot of these regulations are trying to discourage people from collecting personal information.
Is that a feasible idea or is it just, you know, we need that information to drive the business, so we just have to figure out how to be more careful with it? Yeah, We, we do think that businesses over collect. Um, the, uh, uh, the issue there is that, uh, uh, the, the standard example here is a driver's license.
If you show a, a driver's license to get into a bar, what they need to know is that you're of age. They don't need to know your home address. So businesses typically, and very, in a very straightforward way, they just, you know, collect a bunch of data.
Uh, uh, but again, it comes back to this attack surface thing. The more that the business collects, the more they have to pay to maintain that, that data asset. And it's not really a differentiator.
And so what roll-up does is it allows you to collect data in a way that's compliant for the regime where your users are located. You can pin data, you can handle all your data sovereignty requirements, all of that. But it's, uh, uh, uh, it, it's really simple for developers to integrate.
We're not adding identity, uh, uh, authorization factors, uh, authentication factors. You can log in with Twitter, you can log in with email, you can log in with, you know, your Google account, crypto wallet, whatever. You wanna log in with your own, uh, uh, you know, you can set up s s o and use your own organization's login.
But, um, um, then you can just get back to working on what you're actually trying to do. Self cell phone plans or build a great e-commerce experience. Is there a lot of difference between all these data privacy regulations, or sometimes I feel like when I look at something, there's, you know, it's the same basic controls for all of them, so maybe I can centralize the management of it because they're not all that different.
Yeah. Um, that's a, um, that's a great observation. Uh, uh, what happens is these, these, you know, big markets like the eu, they passed G D P R and they were early out the gate, and they have, you know, a really, really strong, uh, uh, uh, sense of what, uh, people want in, in Europe about privacy.
California follows suit with C C P A, and then you see state legislatures, again, because those are big markets, uh, uh, um, pulling in those C C P A and G D P R requirements. Uh, Brazil, for example, uh, has one, I think it's the L L D G P. It's very, very close to the, uh, to G D P R.
The reason that all of these legislatures are making their own copies of these laws is so that they can add, uh, uh, variances for their own markets and their own populations. So sure, you can comply with, uh, you know, EU regs and hope you're good in California. But, you know, uh, we take a layered approach where there could be something at the local level, the state level, the federal level.
Again, why interrupt your developers in their nice little tight sprint loop, getting new user features out, say, hold on guys, we got to do a spike on, on regulations for Florida versus New York. You know, We used to make distinctions between what we call regulated industries and industries that are not heavily regulated. Is that all by the wayside now?
'cause it seems like if I have these privacy regulations, well, we're all regulated. We are all regulated. I think it's, uh, uh, the tech, I, I've been a, a developer for 20, 30 years.
I did 10 years in the games industry. I did a bunch of years as a consultant. And, um, I, I missed the old internet.
I missed the internet of the nineties. But the whole industry has grown up. It's, um, um, you know, we're, we're a large global industry and, and regulation is, is just kind of par for the course.
Um, now, uh, you know, how we influence that, how, how, uh, what people are asking for, how we comply, those are all areas of competition. But I, I, it's not really a, um, a question of regulation or no regulation. You can look at what happened in the crypto markets.
You need regulation. You cannot go down the street without somebody talking to you about their great new AI thing. So can AI be applied here and might AI save us from ourselves?
Uh, that's a really interesting question. Uh, so, you know, everyone's talking about generative. Um, uh, you see Sam Altman has world coin as well.
So he did this great tech thing of, he created the problem and now he's selling the solution. Uh, but, uh, by which I mean, you know, you have generative AI that's pretending to be people, and now you have a coin that, that, you know, attests to someone's validity as a person. Um, I think there are machine learning approaches that can help, uh, uh, connect identity factors.
We don't take those approaches. Uh, we want humans to remain in control of their own identity. So if we know that you have a Twitter account and you know, we know that you've created an email account, we don't automatically join those.
We ask you to join them. And this is really obvious, you know, I, I have separate accounts that I use for when I was a consultant. I didn't use my personal accounts for consulting work when I was a video game developer.
I didn't use my gaming accounts with my, you know, Microsoft Developer Center accounts. Uh, I, I maintained a, a split in my identity. And that's what rollup enables.
We actually don't want to fully pull together identities automatically. We want people, humans to be in control of their identity factors. One of the challenges of these various regulations is they all have some flavor of the right to be forgotten.
And once p i i data starts flowing through a system, it's everywhere. And it's very hard to capture all of that. So how will we kind of address that requirement?
Because, uh, frankly, stuff just sitting in spreadsheets, it winds up in production applications and winds up in application development initiatives. How do we kind of wrap our arms around it? Yeah, so the, uh, compliance teams in companies are a huge part of this.
E e exactly what you just mentioned. As soon as you, uh, uh, take something offline, you take it out of a production system and you put it in a spreadsheet that's data that needs to be managed. Uh, what rollup helps customers do, help helps developers do is, uh, we have a, we take a, um, a shredding approach, a data shredding approach, a burning approach.
So as we, we build this graph where you can connect in all these identity factors that I've been talking about, you know, and you, you make a, a graph and you connect all of these things to it. Uh, when you remove those connections or you delete those graph nodes, and all of this is just, you know, forget my identity, it's one click for, for the user's point of view. But for the developers in your audience, it's, it's, um, uh, uh, we do a cryptographic proof of what that, that identity is.
And as soon as we, uh, eliminate that proof, the data are lost, we delete them, the data are lost, they're unrecoverable. So within our system, these things are, are designed to shred very high standard, very high, um, um, level of compliance with best practices. Um, and actually that frees up your internal compliance teams because they have to handle those internal hacks.
Like, I'm just gonna copy all the data and put it in a spreadsheet really quickly and we'll delete it later. Compliance needs to track when later happens and actually do the deletion. Yeah, I think it's a dirty little secret in the land of it there.
We're not really good at managing data. We kind of give that illusion to folks out there, but the reality is, data's everywhere and we don't have a firm handle on who has it and using it for what. So we'll use regulations kind of force us to quote unquote clean up our act.
I think they will. Um, I think from a pragmatic approach, it'll cause something I'll call asymptotic compliance where, uh, uh, businesses over collect data, they're really concerned with going after customer needs, and governments are creating these, these, um, uh, regulations around how they have to serve those customer needs. And it'll take time for businesses to adjust and, and for best practices to, uh, uh, not just develop, but be codified into, uh, um, administrative, uh, implementation of the regs.
And we'll see businesses say, you know what? We don't really need someone's birthday. Or we can, we can, we can collect the fact that they are over the age of majority rather than their birthday.
We don't need to see their, their home address. We just need their shipping address. And we'll be able to, um, uh, what, what executives will typically see is that the mass of cost savings that come from the lack of a compliance threat and enforcement action.
Uh, you know, 80% of of large enterprises have seen data breaches. These are often per record fines. And if you're looking at thousands of records and thousands of dollars per record, you're getting into fines of the millions and tens of millions of dollars.
And that hits your compliance budget kind of conceptually, and, and you can get massive savings by simply collecting less. And I think that's, that's the, um, the carrot in the stick here is that, uh, you'll have to collect less, that'll reduce your compliance burdens, it'll reduce your security burdens. And if you don't do it, uh, you know, we have some fines to chase you with.
What's your best advice to folks to get started down this path? Because inertia is a powerful thing, and a lot of organizations just keep doing the same thing regardless of what regulations come out until somebody hits them with a fine. But, um, how do I get the security, the compliance, the developers, the IT operations people in a room together to kind of go address this whole thing?
Yeah. So, uh, uh, that, that is a great question. Generally speaking within an organization, you want to give people a really great tool and then adjust their incentives to make sure that they actually use the tool to accomplish the business goal.
And so that's the, the broad advice for executives is, as I used to say, as a consultant, uh, um, uh, changing organizational behavior is changing incentives. Hey, Alex, thanks for being on the show. Thanks very much, Mike.
All right. And back to you guys in the studio.