Navigating Data Privacy and Compliance in the Digital Age with RecordPoint CEO Anthony Woodward
Transcript
Hey everyone, it's Alan Shimel, and we're back here at Techstrong tv. My next guest is Anthony Woodward. Anthony is the co-founder and CEO of Record Point, and I think this is his first time on Text Drunk TV with us.
Anthony, it's a pleasure to meet you. Thanks for coming on. A pleasure to be here and yes, it is my first time on Text, text Drunk tv, so thanks for having me.
Fantastic, Anthony. Um, I, you know, I, we were talking off camera. I founded a few co-founded and founded a few companies in my day as well.
You know, you gotta be a little crazy to found the company. You gotta be driven. You gotta really believe that what you are doing is important, right?
No one ever says, yeah, I started a company. We don't really do anything important. No one really cares.
You know, you, there's gotta be a belief that somehow you're making someone's life better. You're making the world better in some small way or big way. Talk to us about kind of your journey and where you found your passion.
Yeah, that's a great question. I've really spent my entire career, um, looking at two key things. I, I, I worked for a long time in the legal industry, had some training, um, in the legal industry, really thinking about regulation and data.
The early two thousands, uh, in fact worked on, um, a bunch of processes around data, 2000 Olympics in Sydney, um, and went on and took that career to working to all sorts of organizations, looking at how they're handling information, what they're doing with it, and what are the controls wrapped around it. And, um, you know, that really delivered me, um, a bunch of understanding and training to think about how, um, organizations should be more effective at, at data control. Absolutely.
And so then your co-founder kind of by definition means that you had someone else also as a co-founder with you, talk about how, how record point came to be then. Yeah, so Alon Astro, who is my, my co-founder, no longer operational in the business, but, um, we worked alongside each other in a, in a previous business doing a lot of consulting, uh, you know, in, in the data management arena, primarily in those days. In fact, with Microsoft, on the Microsoft SharePoint platform in the Asia Pacific, so in Singapore and in Australia and those places.
Um, so we had previous business, we actually sold that business to the Jacobs Group, um, who bought that, bought that out to build a consulting practice down in, in apac. Um, and in fact, while we were in that business, we were sort of thinking about there must be a better way to actually address, um, the problem of managing data, particularly records, and you can tell from the record point name, we, we came from storing, um, your data as records, um, and really applying machine learning and rule set. So this is going back to like 2009, 2010, um, to classify and then build better control so that you would, you know, be discovery ready, be able to hit particular pieces of regulation and, and deal with that challenge.
And that was really the inception. What what we saw was that most companies were pretty good at collecting their data and working on it, but they were really bad at storing it over the long term and making sure it was ready for stakeholders that needed to use it. And, um, that was really the mission initially.
Excellent. Um, timeframe, how long, how long have you been at record point? Uh, sadly, sadly, uh, uh, uh, you know, as I said, we start yeah, around that, um, 2010 timeframe, so it's coming on 15 years now.
So, uh, we've been, There's nothing to be sad about. That's, that's an accomplishment, right? Yeah.
You know, in, in a world where the average business venture, you know, doesn't last a year, being around 15 years means you're doing something right. Yeah. We like To think something, right?
Yeah. Yeah. Um, Anthony, for people want to get more information about record point, where, where, what's the kind of the best on ramp here?
Um, you know, traditionally my answer would be, you know, go hit the website, uh, record point do come and have a look at, but, um, I'm actually more recently and we are really leaning into large language models and those things just go and ask chat, GPT and, and, and Gemini. Um, they have some really good answers. I think these days around what we're doing and what we're focused on.
You know, we've evolved a lot since our early days, so the things that we focused on, you know, classifying information, building file plans, disposing of information, you know, which were our really early iterations of the product have now evolved considerably to, to reach into AI and other things I'm sure we'll touch on in a minute. Alright, with that out of the way, Anthony, let's turn to our topic of discussion today. And that, you know, is framed as the intersection of data, technology and compliance.
Mm-hmm. A lot to unpack there. Why don't you start off unpacking it with, for us?
Yeah. Look, uh, the reality is, and we see this I think in most disciplines, is, you know, technology is moving so fast that the, I think, you know, um, right now we're feeling that more than ever, um, that that pace of change, um, regulation and compliance does not move at the same speed. Um, so you have these two different disciplines that are, uh, you know, very much integrated and reflective of each other, but they don't actually move, um, in a, in a connected way.
Um, and so what is kind of occurring is you've got companies trying to exist with regulations that often can talk about paper processes, can talk about how you shift and stick things in envelopes and send it across, um, mail boundaries. And that was the thinking of how that regulation was written. Um, and we've gotta apply that to technology that doesn't even have any of those concepts.
So, um, really where we live is being able to take those regularly con regulatory controls, and that could be something as simple as, say, the Banking Security Act and, uh, what we need to do there around managing people's information to something more complex like CCPA, the Californian Privacy Act. Um, it's really looking at how do you bring regulations to data and to technology, and then apply that in a way that doesn't block an organization from getting value out of the technology and the data sets that are there. And it's really that intersection that we live out where you can codify regulation, um, to make sure systems are doing the things they need to, and that data is managed in a way that's going to evolve, uh, away from risk and away from, you know, any legal issue that might occur.
Excellent. Um, you know, you mentioned AI before Anthony, and it's obviously touching on and changing so many different things. How, how is, how is it affecting your world at record point and at this intersection that we're talking about?
Yeah, uh, look, um, there's already 167 pieces of regulation globally on ai. Um, the most familiar ones are the European, um, AI regulations, but, you know, you've got, um, various other permutations, which could be from, um, some of the OECD, uh, uh, sort of self-governed, um, processes through to what you're seeing occur in New Zealand and some of the other countries out there around how to, uh, manage ai. And really what we do is try to flip the problem on its head, um, and take the regulation down to the data itself.
So there's lots of products in the market that will help organizations, um, you know, build better models, curate, uh, how, um, what are the biases in ai, you know, deal with some of the things that are required from a regulatory control, but they're really done generally at a model level or, um, trying to silo data in, in turn in into different generative AI or other AI applications. What we've really focused on is no, no, no. What we actually need to do is focus at the data level, because if you don't focus at the data level, you haven't already, you haven't dealt with some of the baseline things before it gets into the model.
So that could be thinking about data privacy, which is a really big element. Are we ensuring that we're not putting data into models that, or, or even into open AI or, um, with Google that has levels of sensitivity. So how does an organization classify and flag and deal with the data lifecycle that's associated with sensitivity?
So, flagging out, you know, really simple things, children's information, uh, pri you know, private addresses, those sorts of elements, we make sure, wanna make sure that's out. We also do a pass and tagging and flagging, thinking about the combinations of things. So I might have a piece of information which talks about, you know, Alan, without mentioning your name, but in an LLM, maybe you can join that information.
So maybe I've got your know, your, um, United mileage plan number, uh, and somewhere else I've connected the mileage plan number to your name. Well, we, we also go to the next level of looking for, okay, what are the signals inside that data that might have the mileage plan number, might have other el elements of sensitivity that you might not think is sensitive. So it's, it's quite deep around how this technology is now applying that.
We also then go one more level before we package it up and, and push it off, um, to the, uh, generative AI or, or, or any other, um, AI element. We'll do a, um, cleanse of the data. So the other thing you want to do to make your models more accurate is pull out any redundant, obsolete, trivial data that is going to skew the models and doing that these days, you know, by hand, and that's what people used to do a lot of the day, scientists would pick that out effectively and find those signals is quite a intensive and expensive process.
So what we allow to do is we look for the patterns of what is redundant, obsolete, and trivial data. We look at minimizing that data set and sort removing, um, bad signals alongside the sensitive signals, and that allow you to work out what should come in and out of ai, what are we gonna use in, um, different types of ai, uh, and then drive that from the data side. But we go one more step in terms of regulatory compliance, and that is we observe the prompts going into ai.
So as you go and ask chatt PT and you've got, um, record points sitting there in the background, or as you go and ask, um, Gemini or any of the other flavors, um, we will monitor the prompt, we'll monitor the response to the prompt, and then we'll store that off so that in the future if you have, uh, a legal issue or the courts come past and ask, where did you get this information? What occurred? You've got what we describe as providence to prove what happened, what was the data that went in, what was the query that went in, what was the response from the generative ai and how do you then manage that?
Thanks a lot, Vince, Nicole does, you know, I'm reminded I, Anthony, I was in security myself for 25, 30 years and you know, unfortunately the bad guys, it's sometimes it's just out in front, right? And I remember back in the day, it probably was from an old Verizon data breach report or something that when you looked on the dark web, you know, if you just wanted someone's first and last name, yeah, it was cheap. You wanna match it to an email address, a little bit more money, but still cheap.
You want a phone number associated with it, well, of cost a little bit more money and it went down. You want to get social security number, well, there's a price for that too. Credit card numbers associated to that person zip code, you know, and, and, and in so doing, you could build up a dossier on a person, right?
An entire record that oftentimes they would use that not just to rip that person off, but to create a, a fake id, right? Go file a tax return under a false address and, and stuff like this. So, you know, the bad guys have been doing that sort of model for a long time now with ai, we have the capability of doing it a lot easier, but so do they, and I think that's something that we need to remember as well is, you know, the, the white hats, the good guys just don't have the monopoly on this.
Uh, no, no. Look, you brought up a really complex issue that I think we're all struggling with. Um, this technology's amazing, but as, as we're going forward, being able to identify what is, um, constructed or, or sifted data to then, um, effectively spike it so that it can be reused in different ways, um, is a really complex area.
And it's something, what, what we're really focused on is how do you make sure what goes into the models doesn't get accidentally mixed? And I think that does limit a little bit of your exposure, but the reality is, you know, um, what's happening with these models, and we're, we're already seeing a lot of cases of it out there in the wild, is people that really joining large, disparate pieces of data and constructing whole new identities or whole new, um, you know, ways that, uh, the data can be, can, can actually be reconstituted so that you can effectively create, you know, a whole new version of Alan that, um, exists out in the ecosystem. And, um, the reality is there, there is, I think this is an area where we're waiting for governments and regulators to kind of catch up so that there are some more controls in that space.
Yeah. I, my my, my fear is that the space, it's moving so quickly, right? I don't know if government ever catches up.
Yeah, I, look, I I mean we probably come from a slightly different perspective. You know, I think it's quite encouraging that, um, that, that you, you are seeing a lot of folk in government think about these issues. Yes.
Um, I would like them to probably take a little bit more of a step forward around thinking about what are the, the key things they wanna focus on. 'cause they're a little bit, um, distributed the thinking at the moment. But, you know, um, you, you do have, you know, some leg legislation, you know, here in the us but globally around things like deep fakes and manipulation and the identity theft.
The issue is that right now, the, um, onus onto, you know, Facebook and other people that have large amounts of data that go into these things haven't, hasn't really transferred. You know, they don't suffer if you end up having a reputational damage issue or any of those things. You know, Anthony, a a hundred years ago I was in law school, and I remember I, my constitutional law professor, he was a pretty good professor.
He, he said something that I never forgot, which is generally from the adoption of technology to society and then legislative regulation catching up to it, there's anywhere from a three to seven year gap now with the a, this is way before there was an internet and everything else with the advent of the internet and the internet time crunch, if you will, maybe it's not three to seven years, but it's not measured in months either, right? And so it's probably close, let's say two to five years, or two to four years. And I, I think that's probably what we're looking at here.
Yeah, look, I think that's fair, but I would point out that, um, when you look at, you know, CCPA, the California legislation around privacy or GDPR in, in Europe and, and there are various other, uh, US state-based legislation like that, um, some of this is already there. It's really more about enforcement, right? Um, CCPA has the right to be forgotten, has some, um, ability to manage data going into the complex AI models.
And, and so it's really on organizations and us as individuals, not just to wait for the regulators, but to look at these model approaches and enshrine them into our, into our organizations. Because I think we have a, a moral responsibility to do. Yeah, no, It's person a one personal, and it's a personal and organizational responsibility.
You can't wait for the government to come protect you here, right? That's, that's not a formula for success either. I don't think anyone's ever succeeded in that.
Anyway, Anthony, I promise you the 15 minutes of these things go long. We're already over time. com.
COM com. Yeah. Do com.
Yeah. Record point do com. Yeah, The old fashioned white old School.
But yeah. Hey Anthony, thank you for coming on Text Trunk tv. Pleasure to have you on here.
We're gonna take a break. We'll be back with more in just a moment.