Skip to content
AppSec PodcastThe Application Security Podcast — home
22 min

Elena Elkina -- Privacy and Data Protection

With Elena Elkina

Privacy and Compliance

Protecting data from attackers does not answer every question about privacy. Elena Elkina joins Chris and Robert to explain the relationship between privacy, security, and customer data protection, drawing on her legal background and personal experience growing up under surveillance.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 10 chapters
  1. 00:00Privacy and data protection with Elena ElkinaAudio
  2. 01:57Elena’s path into privacyAudio
  3. 03:48How personal experience shaped her perspectiveAudio
  4. 05:53What privacy means to different peopleAudio
  5. 07:26Business use of data and transparencyAudio

About this episode

Protecting data from attackers does not answer every question about privacy. Elena Elkina joins Chris and Robert to explain the relationship between privacy, security, and customer data protection, drawing on her legal background and personal experience growing up under surveillance. She describes how different people and organizations understand privacy and why transparency about data use matters alongside technical safeguards. Robert brings a developer’s perspective, and Elena turns the conversation toward the influence engineers have on privacy through product design and requirements. They explore the communication gap between precise technical decisions and the contextual answers privacy teams often give. Elena’s closing advice is straightforward: build relationships with privacy and security colleagues so that protecting people’s information becomes a shared design responsibility.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Elena Elkina:
Elena Elkina on LinkedIn
Women in Security and Privacy

Resources
Women in Security and Privacy
Leading Women in Technology
23andMe

Actionable

From this conversation

  1. Explain data use transparently

    For example, very often, privacy law allows you to do many different things, but companies get in trouble how they describe to the customers or to the end users what they do with data.

    7:53
  2. Build privacy into development

    Developers play an instrumental role in this process because very often privacy and security controls to protect personal information required for a particular process or application or product are ignored or left to the end of the product development cycle.

    15:45
  3. Partner developers with privacy professionals

    Unfortunately for privacy professionals, very often we hear it depends and developers get frustrated and I understand why.

    18:54
Transcript · 22 min conversation

0:05Chris RomeoThe Application Security Podcast. Here we go. Hi folks, Chris here. Welcome to the first of many, many interviews on the AppSec Podcast. In this episode, Robert and I interview Elena Elkina on the subject of privacy. We cover the foundations of privacy, data protection, and customer data protection. This is a quick chat at around 20 minutes or so. In the future, we'll do a deeper dive on the crossroads of security and privacy. A bit about Elena. Elena is a senior global privacy and data protection management executive. She's worked with financial and healthcare institutions, software and internet companies, major law firms, and the government sector on both international and domestic levels. She is the co-founder of Women in Security and Privacy, a nonprofit organization that focuses on advancing women in security and privacy. She's also a board member for Leading Women in Technology, nonprofit organization dedicated to unlocking the potential of female professionals who advise technology businesses. We hope you enjoy this conversation with Elena about privacy and data protection. So today on the Application Security Podcast, we're going to tackle the topic of privacy, and we're also joined today by, by Alana, and we'll let her introduce herself She's an expert in the field of both security and privacy. And first of all, Alana, welcome to the podcast.

1:53Elena ElkinaThank you. Thank you very much, Robert and Chris. I'm excited to be here.

1:57Chris RomeoYeah. And so we always start out with one particular question for all of our guests because we must know, what is your security/privacy superhero origin story? And put another way, how did you get into this field? this crazy field that we think of as security and privacy?

2:15Elena ElkinaSure, sure. Well, I've started doing privacy work before it became what it is right now, a very sexy and hot topic. I started my career as a lawyer doing corporate IP work and mergers and acquisitions. It was about 20 years ago. And 7 years into my practice, I realized that my passion for law is outmatched by my desire to build and innovate. And I move slowly. from practicing law into business compliance, working with different tech companies. And, uh, later on, my deeper dive into privacy began when I joined financial industry and later healthcare. And in the US, as you know, privacy is an industry-based, and we don't have a single law, like for example in the European Union, that regulates privacy across the nation. Instead, we have different laws regulating industries and healthcare and privacy and financial industries to industries that are heavily regulated and have the strictest privacy law. And this is where me as a privacy expert was born. And in addition to that, I see privacy as a tool for my expression, kind of a means to follow what I love, because having my legal experience and my legal background definitely helps me a lot, but I am an engineer in my heart, and I find that privacy and data protection fields allow me to follow my passion and build and create new technologies.

3:48Chris RomeoYeah. Yeah. So, is there one certain event that really drove you into the privacy realm and the security realm, or was it more of a combination of just everything that you were seeing in in all of the things you were exposed to?

4:02Elena ElkinaIt's, it's a, it's an interesting because it would— I would say it was both. I grew up in Soviet Union, so I'm a Soviet baby. And, uh, when I was growing up, my parents are software engineers, and they were sent during Soviet time to work, uh, in a secret city where a nuclear plant was built and the nuclear bomb was developed. So by nature of family circumstances, I spent my childhood behind fence. And I was, uh, of course, the, the Soviet monitoring and surveillance was a big part of our lives, and specifically for my family because we were in a secret city. So from my personal perspective, I was always passionate about privacy as my individual freedom and as my human right. And later on, being a lawyer, that, that passion and that right was slowly transitioned, becoming into, into like a business differentiator for businesses to make sure that you protect privacy of users, but at the same time you use data to, to maintain and create new business, new technology, etc. So I would say it was a combination of both.

5:19Chris RomeoYeah, that's a, that's a powerful story to, to be influenced by the culture that you were in. And to have a desire to want to be focused on privacy because of maybe how yours was being abused in the way you grew up. It makes me wonder if some of the current generation now are going to be influenced in that same way here in the United States based on what they've gone through and the disclosures from Snowden and, and all that we know about the US-based, you know, monitoring and you could say abuse of privacy privilege.

5:53Elena ElkinaOh, absolutely. You know what, privacy means so many different things to different people. It depends who you're talking to, if it's an individual like you and I, or it's a business, or maybe it's the same business or individual in European Union versus in Asia or Russia. There are so many different laws and regulations that have absolutely, well, similar but at the same time very different approach to privacy. To people, I feel like especially in the EU, it's an individual— it's a fundamental right. It's the right to be let alone, and it's freedom from interference or surveillance or any type of intrusion, not only by the government but by other people as well. Um, you know, in the US, uh, US lawyers often talk about privacy from the Fourth Amendment, right? And, uh, it's basically prohibition against unreasonable search and seizures. as protecting private spaces. But me, I work with companies and different companies from large corporations to small startups. And when we think about privacy, it's more about authorized use and disclosure of personal information and how companies do it and how they incorporate transparency, mindfulness, and security into that. And I feel like a lot of what's happening, it's not only driven by laws and regulations, it's driven by culture, it's driven by mentality, it's driven by history. And it's very important to think about it when we think about privacy.

7:26Chris RomeoSo you've got government, you've got the need to protect the information from the government actors, but then it sounds like you're saying that the tech companies and I guess other companies that are serving up any type of data on the internet, seems like they're more focused on the data protection side and thinking about how do I segment the data between individual customers. Is that what you see as you look across the industry?

7:53Elena ElkinaWell, I see quite a few different things, including that. There are a lot of different things that companies worry about. First of all, of course, they want to make sure The big data boom, it's something that big companies want to take advantage of, and not only big companies, smaller companies as well. How can I use data to create, generate business? And data is money, and we all know about this. But at the same time, new regulations require companies to think very carefully how they use information and what they do with this information and how they tell people what they do with that. For example, very often, privacy law allows you to do many different things, but companies get in trouble how they describe to the customers or to the end users what they do with data. Also, one of the things that I want to highlight is that very often, it's not about what you're doing, it's about why you're doing that. I'll use myself as a personal example. Healthcare. This is a very tricky subject because it's very often you, you know, you don't have the same level of knowledge as doctors do. And when you come to see a doctor, very often they ask good questions, but very often, depending on the information you provide, there is the outcome. It can create, it can create difference in the outcome and advice you might receive from a doctor. A couple of times I requested my medical records and I was shocked to see how much data was in my file, data that I don't think was necessary for my doctor to determine my diagnosis or for my doctor to talk to me about particular needs. I was very concerned about medical records. And right now, when I go and talk to the doctor, I provide minimum necessary information, in my opinion. And of course, it can affect the advice I receive from a doctor, but I'm very I don't trust insurance company and how they use information. It's not about the doctor, but the insurance companies and laws and regulations around are still very unclear and remain challenging. At the same time, I can— I released my genetic code to 23andMe. It's a company, I think it's the only one and one of the first companies that use genetic— provide genetic services to consumers. They basically analyze your DNA and they tell you what kind of health risks you might have or might be exposed in the future. So, this is very sensitive information, but because I trust the company and what they do and why they do certain things and why they collect information, and I am more willing to share information with— and to make sure that— because I understand the benefits.

10:46Chris RomeoYeah.

10:46Elena ElkinaAnd I understand what the company does. So, there are a lot of things around privacy that are more not about regulations, but it's more about how the company using the information and how much it discloses to me as a consumer, what it does with that.

11:00Chris RomeoYeah.

11:01Robert HurlbutSo is—

11:02Chris Romeoso let me ask you this then. Is privacy and customer data protection the same thing or are they something different?

11:08Elena ElkinaPrivacy and customer data protection, I would say they are relevant. It's— I would say privacy, it's about— it's private matter. It's what I do with my data, what you do with my data, how you protect, how much control I have over my data. And the second part, data protection, it's kind of like the second side of the coin. It's more like security and privacy, right? These are different things, but they cannot exist without each other. I always use an example of a house. Let's say, envision a house and the walls are windows. And when you close the windows, when you lock it, you can see everything what's going on in the house, but you cannot get in. That's to me security. But when I close the curtain and open the door, basically there is no protection. Everyone can get in, but no one can see what's going on. But when both are closed, it's more like it's privacy and protection. The data is private and I am private. My— whatever is going on in the house is private and at the same time it's protected.

12:16Chris RomeoYeah, that's a great— that's a great example. example too. I just, I'm gonna borrow that again in the future and I'll quote you.

12:22Elena ElkinaIt's a very good way to talk, the way I talk to my engineers and developers, kind of trying to differentiate between privacy and security, as well as to people, because it's important for everyone to understand the difference because people still think that it's the same thing. Privacy and security and protection of data are different things, but they are closely related and cannot exist without each other.

12:45Chris RomeoYeah, so I understand that now. So what I want to transition into right now is I want to talk about how privacy impacts developers, but I want to do this a little bit differently. So Robert, I would like if you could, first of all, before Ilana talks about anything having to do with privacy developers, give us your take on what the average developer, how the average developer is gonna— is thinking about privacy. And remember, by average, I mean not a security-focused developer, but how are they thinking about privacy? And then after we get your take on that, Robert, then Ilana, I'd love for you to explain to Robert, who's playing the role of this average developer, explain from the developer's mindset, because I know you've had experience with that in the past. So Robert, first of all, when, as an average developer, What do you think of when you hear privacy?

13:39Robert HurlbutWell, sure. Actually, this is an interesting question because even when I do some of my threat modeling sessions with developers, that's always one of the questions I ask about. How are you dealing with privacy? So then I get their take on it. So it's kind of an interesting question. And generally what I'm hearing is they do think about, you know, the things that they do with data, but not so much you know, the data protection and not understanding the difference between that data protection and privacy. And so generally what I'm hearing is, I'm just trying to protect or trying to hide certain data or not save it, for example, in log files. I'm not tracking certain bits of information perhaps. So it varies across the board about what developers are thinking. In terms of trying to implement that, You know, for example, they say, well, I'm not going to save the password, but that's data protection into a log file, for example. That's more data protection. How are you verifying when a user does something in your system that you may not necessarily want to track, or something you do want to track, some things you don't want to track? How are you doing that? And right now I still get kind of blank stares. I don't know. I'm not doing anything, or I'm not thinking about that. So I think it's still, you know, it really is a key area to talk about and to help developers understand the difference and how can they distinguish data protection and then the privacy of that data or the things that they're doing with their data.

15:12Chris RomeoYeah, and I think that should hopefully help Ilana here to know where your mindset is. So now, Ilana, the challenge I'm going to put before you is let's pretend you only had 5 minutes Total time to influence this developer who's just given you the answer to what he thinks about from a privacy perspective. So you got 5 minutes to really explain to this developer what are the most important things that they need to understand. And this will help our audience because a lot of the audience are developers that are new to privacy. So with that, I'll let you take it away.

15:45Elena ElkinaSure. You know what? This is such an amazing question to me and a critical question. Because I've been thinking about it a lot. And it's interesting how you phrase it. It's how privacy can affect developers. But I wanna put it, I wanna reverse it. I wanna see how developers can influence privacy. Being a developer and understanding privacy principles can be so instrumental to the privacy risk and translating or incorporating privacy into product design and requirements. I call developers my best friends because they play a critical role in the business. It doesn't matter if I'm developing a product, hardware, software, mobile app, it doesn't matter what I do. They are my champions because how a product is built often determines what we build, how it works, how customers use it, how well it protects customer data, employee data, business data. And the risk it may pose to our business or future markets. And developers play an instrumental role in this process because very often privacy and security controls to protect personal information required for a particular process or application or product are ignored or left to the end of the product development cycle. And we all know that the first thing the business is pressuring us, we need to build something, we need to create, and privacy becomes an afterthought. And when it happens, it usually results not only in potential violations of laws and regulations, but also in poor user experience. And also, developers may end up with unnecessary work to fix certain things later. And as a result, there is customer dissatisfaction. So, I don't wanna be dramatic, but And I don't wanna say that developers, they are the ones who are gonna fix everything, but I wanna say that it can cost us a business if there is no collaboration between developers and privacy and there is no conversation happening as early as possible in the product development process. It can cost the business because either product becomes malfunctioning And regulators will come and ruin your brand reputation, or just customers don't wanna buy it. And privacy is a business differentiator. Very often, customers, we wanna purchase a product because it's privacy proactive and privacy is built into design. And without developers, unfortunately, it cannot be possible.

18:27Chris RomeoYeah, that's, you know, I'm gonna go back to the first thing you said there about flipping that question around and saying it's not as important how privacy impacts developers, but it's how developers impact privacy. And I think that's what you just summarized there is that each individual developer has the ability to influence privacy by implementing the requirements and understanding the concepts that you were discussing.

18:54Elena ElkinaAbsolutely. And it's a very challenging task and it's no way developers can solve it alone. I think it's, you know what, we all speak the same language, but it doesn't seem the same in practice. You know, developers have very precise black and white conversations. Either works or it doesn't. That's the nature of their work. And unfortunately for privacy professionals, very often we hear it depends and developers get frustrated and I understand why. And from the legal standpoint or compliance standpoint on privacy, Privacy people think that developers don't care, and it's not true. It's just about having the same, using the same terminology, using kind of the same concept to bring the bridge between developers and privacy to make sure that we have the same common language that we use around privacy and product development, making sure that the product is functioning, it meets the demand of consumer, business, and regulators. And it's a challenging task.

19:58Chris RomeoYeah. So just to wrap up this conversation, what would be— if you could only give Robert a— as playing the role of the average developer, if you could give him a one-sentence call to action, what would you recommend that he do coming out of this conversation?

20:16Elena ElkinaBecome friends with your privacy and security team.

20:22Robert HurlbutYeah.

20:22Elena ElkinaSo become friends. That's all. It's communication is the key. That's everything it takes. It's the big— it's the smallest and the biggest task that needs to happen. Yep.

20:33Chris RomeoThat's awesome. So, Alana, thank you for your time here introducing this foundational idea of privacy and security and how these things all fit into the world of application security. And we look forward to having you back in the future for a deeper dive into some of these topics. And we'll let the listeners help us by providing some feedback via Twitter and letting us know what are the areas about security and privacy that we want to dive deeper into. So, Alana, Robert, thank you very much for your time today.

21:02Elena ElkinaThank you, Robert and Chris.

21:04Robert HurlbutThank you.

21:05Elena ElkinaThanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Boring and TJ, and the outro is Southern Delight by Stefan You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. Thank you.

3,368 words · transcript by assemblyai

More on Privacy and Compliance

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.