Building a Privacy Program in the Age of GenAI

Building a Privacy Program in the Age of GenAI

1h 14mBeginner2025-02-14

Authors

Nishant Bhajaria

Nishant Bhajaria

Privacy and Security Leader and Digital Product Architect

Course details

Dive into the world of privacy and data governance as Nishant Bhajaria—a privacy and security leader—guides you through essential topics such as data classification, inventory, and the importance of timely data deletion. Discover how to implement robust third-party risk management processes, ensuring that your company's external partnerships contribute to a secure data ecosystem. Understand the risks of data exfiltration, poisoning, and bias in AI systems, and explore best practices for mitigating these threats. Learn how to enhance transparency with users and maintain regulatory compliance through privacy impact assessments and robust review processes. Find out how technical privacy reviews can preemptively improve product design and prevent bad code deployment. When you complete this course, you'll be equipped to transform privacy from a compliance requirement into a strategic advantage for your organization.

Skills covered

PrivacyData PrivacyGovernance, Risk, and ComplianceCybersecurityData ScienceOne-Off

Concepts

Introduction

  • What privacy means in the age of GenAI
  • Who this course is for

Introduction to Privacy

  • The real meaning of big data
  • Privacy and security
  • Regulations and standards
  • Privacy and internal stakeholders
  • Building data governance into organizational operations

Privacy and Key Governance Milestones

  • Code governance
  • Data classification
  • Data inventory
  • Third-party risk assessment

Adapting Privacy to the GenAI Era

  • Understanding privacy risks posed by GenAI
  • Managing security risks posed by GenAI
  • Data minimization, consent, and deletion
  • Bias and fairness
  • Transparency
  • Robustness and safety
  • Building a truly modern privacy review process

Building Privacy Tooling, Processes, Hierarchies, and Consolidations

  • Data deletion
  • Data sharing
  • Build vs. buy
  • Decentralized vs. centralized
  • Privacy leadership and the chief privacy officer
  • Data Subject Access Requests (DSARs) and rights management

Conclusion

  • Next steps
40,000 Toman