Jason Edwards
Certified: The IAPP CIPT Audio Course
Certified: The IAPP CIPT Audio Course is an audio-first study and skills course built for privacy professionals who need a practical, modern understanding of privacy in technology. It’s designed for people who work near products, data, or security and want to speak confidently about how privacy actually gets implemented—product managers, engineers, architects, analysts, security practitioners, and privacy program staff. If you’re moving from policy into product, supporting a privacy team as a technologist, or preparing for the IAPP Certified Information Privacy Technologist credential, this co...
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Episode 39 — Find and Fix Privacy Bugs Before Release 22.02.2026 14:56
This episode treats privacy bugs as defects that can be discovered, triaged, and prevented, which is a critical CIPT mindset when exam questions ask how to reduce risk through engineering discipline. We define privacy bugs as failures where a system collects, uses, shares, retains, or exposes data in ways that violate requirements, user choices, or documented commitments, including problems caused...
Episode 38 — Choose Proven Pro-Privacy Design Patterns for UX 22.02.2026 13:00
This episode focuses on privacy-friendly user experience patterns that make compliance and trust easier to sustain, because CIPT scenarios often ask what a privacy engineer should recommend when designing interactions around data collection, preferences, and transparency. We define design patterns as reusable solutions to common problems, and we frame privacy patterns around outcomes such as infor...
Episode 37 — Eliminate Manipulative Dark Patterns by Design 22.02.2026 13:00
This episode explains dark patterns as a privacy and trust risk, because the CIPT exam increasingly expects candidates to recognize when user interfaces undermine meaningful choice even if a “consent” box exists. We define dark patterns as interface designs that steer, pressure, confuse, or obstruct users to achieve outcomes that benefit the organization at the user’s expense, especially around co...
Episode 36 — Defend Human Factors: Social Engineering and Deception 22.02.2026 14:33
This episode focuses on the human side of privacy failures, because CIPT scenarios frequently involve phishing, pretexting, and manipulation that bypass technical controls and lead to unauthorized disclosure. We define social engineering as techniques that exploit trust, urgency, authority, or helpfulness to trick people into revealing data or granting access, and we highlight that privacy risk of...
Episode 35 — Tame Advertising Ecosystems and Cross-Site Profiling Risk 22.02.2026 17:25
This episode explores how advertising technology creates privacy risk through tracking, identifiers, and data sharing, a topic that appears in CIPT contexts because it combines technical mechanics with consent, transparency, and third-party governance. We define common ad ecosystem components such as trackers, SDKs, cookies, mobile identifiers, data brokers, and real-time bidding, and we explain h...
Episode 34 — Harden IAM and Authentication for Privacy Outcomes 22.02.2026 16:39
This episode connects identity and access management to privacy outcomes, because CIPT questions often assume you understand that privacy protections fail quickly when identity controls are weak. We define IAM as the set of processes and technologies that manage identities, roles, permissions, and authentication, and we explain how it supports confidentiality, integrity, and accountability across...
Episode 33 — Counter Blackmail, Appropriation, and Identity Misuse 22.02.2026 17:37
This episode examines privacy harms that involve coercion, exploitation, and misuse of identity-linked data, which the CIPT exam may represent through scenarios involving sensitive attributes, reputational risk, and unintended exposure. We define blackmail risk as the use of personal information to threaten or coerce, appropriation as taking or using personal identity elements in ways that harm or...
Episode 32 — Prevent Distortion, Exposure, and Confidentiality Breaks 22.02.2026 14:51
This episode focuses on privacy harms that result from data distortion and exposure, because the CIPT exam often tests integrity and confidentiality outcomes, not just collection and consent. We define distortion as inaccurate, incomplete, or misleading data that drives incorrect decisions about an individual, and exposure as unauthorized visibility of data through security failures, misrouting, o...
Episode 31 — Control Disclosure and Access with Robust Guardrails 22.02.2026 15:50
This episode explains how to control disclosure and access so that personal data is only available to the right people and systems for the right reasons, which is a core CIPT competency in both governance and engineering scenarios. We define disclosure broadly as any release of data outside its intended boundary, including internal sharing across teams, external sharing with vendors, and exposure...
Episode 30 — Limit Secondary Uses, Targeting, and Profiling Responsibly 22.02.2026 13:33
This episode focuses on secondary use and profiling risks, which appear constantly in CIPT-style scenarios because organizations often repurpose data beyond the original user expectation. We define secondary use as applying data to a new purpose beyond the one that justified collection, and profiling as automated processing to evaluate, predict, or influence behavior, preferences, or outcomes. You...
Episode 29 — Use Differential Privacy Wisely in Analytics Pipelines 22.02.2026 12:40
This episode introduces differential privacy as a principled approach for limiting what can be learned about any individual from a dataset, which supports CIPT scenarios involving analytics, reporting, and large-scale measurement where confidentiality and utility must be balanced. We define differential privacy at a practical level: it adds carefully calibrated randomness so that results are stati...
Episode 28 — Implement Pseudonymization Controls That Actually Protect 22.02.2026 13:56
This episode explains pseudonymization in practical engineering terms, because the CIPT exam often asks candidates to choose between anonymization, pseudonymization, and other controls based on realistic constraints and risk. We define pseudonymization as replacing direct identifiers with substitutes while keeping a re-linking capability under controlled conditions, and we emphasize that it reduce...
Episode 27 — Apply Anonymization Techniques That Stand Up to Scrutiny 22.02.2026 11:53
This episode teaches anonymization as a risk-based practice rather than a magic label, because the CIPT exam often tests whether you understand re-identification risk, residual risk, and the conditions required for anonymization to be credible. We define anonymization as processing that makes it not reasonably likely to identify an individual, directly or indirectly, given the means likely to be u...
Episode 26 — Reduce Aggregation Risks in Data Lakes and Warehouses 22.02.2026 13:00
This episode focuses on aggregation risk, a key privacy concept where combining datasets creates new sensitivity and inference power even when each dataset seems harmless on its own. We define aggregation risk as the increased ability to identify individuals, infer traits, or reconstruct behavior when multiple sources are joined, and we explain why CIPT scenarios often revolve around data lakes, w...
Episode 25 — Segregate Processing Workloads to Contain Privacy Blast-Radius 22.02.2026 12:07
This episode teaches segregation as a privacy engineering control that limits exposure and reduces the consequences of mistakes, which is why it appears in CIPT-style thinking whenever multiple purposes, audiences, or sensitivity levels exist. We define segregation as separating data, processing, and access paths so that one failure does not automatically compromise everything, and we connect it t...
Episode 24 — Practice Ruthless Data Minimization Across the Lifecycle 22.02.2026 11:15
This episode makes data minimization practical by showing how to apply it at collection, processing, sharing, and storage, because the CIPT exam repeatedly tests whether you can reduce data exposure while still meeting functional requirements. We define minimization as limiting data to what is necessary for a specific purpose, then we explain how “necessary” is a decision that must be justified, d...
Episode 23 — Plan Data Retention and Destruction That Works 22.02.2026 12:18
This episode teaches retention and destruction as engineering and operational disciplines, not just policy statements, because CIPT scenarios often test whether you can make retention real across systems, backups, vendors, and workflows. We define retention as keeping data no longer than needed for defined purposes, and destruction as rendering data irrecoverable or effectively unavailable, and we...
Episode 22 — Extract Public Data Responsibly and Defensibly 22.02.2026 13:26
This episode focuses on public data collection and the privacy risks that still exist when information is “available,” because the CIPT exam often tests whether you understand context, expectations, and downstream harm rather than assuming public means safe. We define public data extraction as collecting information from sources accessible without special authorization, then we discuss the practic...
Episode 21 — Manage Automatic Data Collection Without Overreach 22.02.2026 14:53
This episode explains how automatic data collection happens in real systems and how to govern it so it stays proportional to purpose, which is a frequent CIPT exam theme when telemetry and analytics quietly expand beyond what users expect. We define automatic collection broadly, including device identifiers, cookies, SDK events, server logs, crash reports, and behavioral signals, and we emphasize...
Episode 20 — Craft Clear, Honest, and Actionable Privacy Notices 22.02.2026 18:54
This episode focuses on privacy notices as a core transparency control that must be accurate, comprehensible, and operationally connected to real processing, which is why the CIPT exam treats notice quality as more than copywriting. We define what a notice must accomplish: explain what data is collected, why it is used, who receives it, how long it is kept, what choices exist, and how individuals...
Episode 19 — Design Consent Journeys Users Understand and Choose 22.02.2026 18:19
This episode teaches consent as a user experience and system control problem, not just a checkbox, because the CIPT exam often tests whether you can design consent flows that are meaningful, informed, and enforceable. We define what makes consent valid in practical terms: clarity, specificity, real choice, and the ability to withdraw, then we connect that to the technical requirement to honor pref...
Episode 18 — Mitigate Bias in Automated Decisions and Analytics 22.02.2026 18:10
This episode focuses on bias risks in automated decision-making and analytics, a topic that shows up in CIPT-style thinking whenever data processing influences outcomes for individuals. We define bias in practical terms, including selection bias, measurement bias, historical bias, and proxy discrimination, and we explain how these issues can emerge even when sensitive attributes are not explicitly...
Episode 17 — Advise Ethical Technology Design that Scales Sustainably 22.02.2026 17:22
This episode builds the skills needed to advise product and engineering teams on ethical design decisions in a way that scales, because the CIPT exam often frames you as a professional who must influence design through principles, controls, and governance rather than personal preference. We define what it means for ethics to scale: clear decision criteria, repeatable review processes, documented r...
Episode 16 — Separate Legal Duties from Ethical Design Decisions 22.02.2026 18:57
This episode clarifies the boundary between legal compliance and ethical responsibility, because CIPT questions often reward candidates who can identify when “allowed” is not the same as “appropriate” in system design. We define legal duties as obligations rooted in statutes, regulations, contracts, and enforceable commitments, while ethical decisions address fairness, dignity, and harm reduction...
Episode 15 — Leverage MITRE PANOPTIC Modeling for Data Protection 22.02.2026 18:04
This episode introduces MITRE PANOPTIC modeling as a structured way to think about privacy and surveillance-related risks, which supports CIPT scenarios that involve tracking, observation, and the downstream misuse of collected data. We focus on what this modeling mindset helps you do: identify who is observing whom, what signals are being collected, how those signals are combined, and how that en...
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos