Episode 13
Privacy, Proxies and Podcasts
with Alan Chapell of the Monopoly Report
Show Notes
Rob Leathern speaks to privacy attorney and host of The Monopoly Report Podcast, Alan Chapell, about residential proxies, privacy and podcasting. Hear how free smart TV apps might be sharing your home IP address with strangers, and see just how broken online consent forms really are.
Alan explains why current data broker laws miss these proxy networks entirely and how coming age verification rules could rewrite the open web.
In This Episode
- Free smart TV apps quietly bundle code that rents your home internet connection to strangers, creating vulnerabilities that look suspiciously like security exploits.
- Online consent breaks down with bandwidth sharing, when endless disclaimers mean nothing as consumers may have no easy way to turn the access off.
- State data broker laws miss the mark by hunting legacy data vendors while ignoring massive proxy networks, credit card companies, and telecom giants.
- AI companies pushing to scrape the entire web without limits could accidentally hand ad verification firms the ultimate legal shield against platform lawsuits.
- Strict age check laws could spark an arms race with clever teenagers that could end with governments requiring real ID just to browse the web.
Chapter Timestamps
- 00:00Introduction
- 5:32Residential Proxies: The 'Ethically Sourced IP' Question and the LG TV Case
- 9:48Legitimate Uses vs. Harmful Behaviors of Residential Proxy Networks
- 12:50Data Broker Laws, Enforcement Gaps, and KYC
- 14:40Consent Problems: Revocation, Age Verification, and the LG TV Example
- 16:56Adware Parallels: History, Opt-Outs, and Financial Incentives
- 23:31Age Verification: A Looming Internet-Wide Challenge
- 25:39Scraping, Antitrust, and AI Companies
- 29:40Podcast Strategy, Guest Selection, and Speaking Recklessly
- 41:53Regulators, Historical Knowledge Gaps, and Industry Dynamics
Transcript
There may be transcription errors: we apologize for those in advance.
Rob: Hi, welcome to Won't Fix. My guest today is Alan Chapell. Alan is a privacy and regulatory attorney who's been in digital media since 1997. He started at Jupiter Research, where I also worked, spent time at DoubleClick, and founded Chapell & Associates in 2003. Since then he's served as outside counsel and fractional chief privacy officer to well over a hundred adtech and martech companies, and guided a good number of them through exits. He's board chair of the Network Advertising Initiative and writes The Chapell Report. Alan hosts The Monopoly Report podcast, and I've been a longtime listener, so it's really great to be able to chat with him.
Here we go — Alan Chapell.
Rob: Alan, it's good to see you again, sir. How are you doing?
Alan: I'm doing great. Good to see you as well. It's been months since New York, right?
Rob: Yeah, since we were at the Marketecture show. I did some stuff there, and it's always great to talk to you. It was great to be on your podcast — I don't know whenever that was — and now I've started this one. Still early days. I aspire to be as interesting as some of the topics and speakers you've had on, so I really appreciate all your advice and thoughts as we've gone along.
Alan: Happy to do it, and I love what you're doing. It focuses on a really interesting set of issues that are rather distinct from a lot of what I typically address. Well done — you found a niche.
Rob: Thanks. You definitely have a great niche yourself. One of the things I wanted to talk about today was something we've discussed before, and something I talked about at the Marketecture conference as a panelist. I think it's a really interesting one that cuts across a bunch of the safety and AI topics I spend a lot of time looking at, and the regulatory topics. There are also a lot of consent and privacy-related issues in it.
So I thought we might talk about residential proxies and other kinds of "renting your bandwidth out for fun and profit" business models — if that's okay.
Alan: Absolutely. I think this will be fun.
Rob: For folks who aren't listeners — and I'd encourage everyone to listen to your podcast, we'll have links in the show notes — tell us a bit about what you're covering and how you got into it, by way of introduction.
Alan: Sure. The backstory is that about two and a half years ago, I'd been on Ari's pod, the main Marketecture one, the big stage, a couple of times. And I started getting in his ear that he really needed to create a Lawkatecture — I think that was the word I used. And that he needed to be focusing on these types of issues. I was even starting to put together a proposal for him.
Then one Saturday, Ari calls me up and says, "Hey dude, I need your help." Sure, whatever, man. He says, "I've got this Monopoly Report thing, and it's great, I've got a growing set of users, but I'm not the right person to run this. Do you want it?" I said, "Yeah, fantastic."
For folks who might not know, The Monopoly Report — which is the name of both the podcast and the biweekly newsletter — originally came out of the various Google antitrust trials, primarily the ad tech one. Ari was down there as the intrepid reporter for the entirety of the trial, it got a lot of press, and he built the whole newsletter on its back.
I started out with that as the focus, but then realized there are some other interesting things going on in the ad space that nobody's really talking about. So I've pivoted a bit. Antitrust and competition are still part of the focus, but the big focus now is: what are the major regulatory issues impacting the ad space?
By widening the orbit a little, I've been able to bring on folks like Patrick McGee, who just wrote *Apple in China*, or John Battelle, who's a fantastic guy to talk to on just about any subject. I've been able to have bigger thinkers involved, in addition to some of the regulatory nerds like myself.
Rob: I enjoyed the recent episode about the Google antitrust technical committee. There's a lot of inside baseball there, but I found it fascinating.
Alan: Thanks. Alyssa Cooper — I've known her for years — is really, really smart about this stuff, and wears both a privacy policy hat and a very well-earned technical hat.
What's fascinating is that these issues drive home the big seams between privacy and competition law. When Google says, "We can't turn over this data because of privacy," my knee-jerk reaction is that it's just Google gaslighting again. But the reality is they can point to the European Data Protection Board's position on anonymity and say, "See, it doesn't clear that bar" — and the statute, by the way, says it needs to be anonymous. So on one hand, I'm first in line to be critical of Google's positions as opportunistic. The reality is that they *are* grounded in law.
Rob: That's a good segue. In your opinion as a privacy lawyer — is there such a thing as an ethically sourced IP address? Or stated differently: do you think there's any disclosure that would be adequate for "we plan to rent out your home IP address to strangers, are you cool with that?" That's the consent issue with these residential proxy networks, and I'm curious what your hot take is.
Alan: That's just a marketing term. I think it was one of the large data brokers who started talking about "ethically sourced data" ten years ago — like a farm-to-table concept, as though the data broker was operating somewhere in Oregon where everything was on the up and up. It's a marketing term. At some point those terms become a little misleading. So "ethically sourced IP address" sounds dubious to me.
Rob: It does. With some of these there's typically a cash payment made to the user. Setting that aside, my understanding is that in many cases this kind of arrangement actually violates the terms of use of the ISP. And there's the "you can revoke your consent at any time, you can uninstall" claim.
The one that caught my attention — by way of context — was an article about CTV apps. In order to *not* get ads, ironically, in a game on your LG or Samsung TV, you could install an SDK that would then provide ongoing access to your home IP address, even when the TV was turned off. Brian Krebs wrote about this, and I reposted a photo I'd taken of my television where this offer was made. I thought the whole thing stank. Eventually someone at LG decided the same, and they force-updated the game software to disallow that use of their platform.
Did you see those articles? What did you think at the time?
Alan: Look, one person's borrowing of data is another person's security exploit. When I read it from Krebs, it really does look like a security exploit.
We all make trade-offs in this space, and we all make justifications — and we all live in a bit of a glass house here. But the thing I'd focus on is that this isn't people giving access to a little bit of data by, say, placing a cookie. That's a very different thing from giving access to your internet connection, which invites a whole bunch of things onto your computer that you probably don't want. While advocates sometimes characterize the cookie issue as a huge security exploit, it's really important to see these as very different things in terms of scope.
Rob: I'm reminded of the bargain with ads — we say we're fine with ads running on our machines and phones to pay for the internet so we don't have to pull out a credit card and subscribe to everything. I think that bargain makes a lot of sense. And we rely on those companies to make sure the ads don't contain malware or other nasty things. So there's a question of how good these companies need to be at that.
When you look at the residential proxy space, you have all kinds of applications. Some you might argue are benign — scraping websites to train AI models is obviously one of the use cases. But at its core it seems to me the model is fundamentally based on deception: I'm pretending to be an end user rather than telling you I'm coming from a data center.
So is this model even legitimate at all? Are there enough legitimate use cases? Maybe there are legal theories here like the Betamax cases. Curious if you have thoughts on legitimate uses versus what we all suspect the majority of use cases are.
Alan: There's an irony in play, because these use cases do solve a number of legitimate problems. A lot of attribution and a lot of fraud prevention activity — used by the Googles of the world, by the way — comes from these kinds of proxy networks.
At the same time, these proxy networks are engaged in some really bad behaviors. So there's a throwing-the-baby-out-with-the-bathwater problem. I'd be reluctant to do that, but I do think this is a place where there needs to be more regulation — and more definitions. Maybe that comes from self-reg, and I'm sure the advocates listening just spit out their water. But you need *something*, and it doesn't seem like this is going to be a priority for government. Hopefully we can at least get some baseline standards in place, because right now it's the Wild West.
Rob: I can confirm, having worked on this, that a lot of the big companies have to hold their nose and work with some of these providers — because the bad actors are using the same infrastructure, whether those providers or botnets, to defeat the detection systems.
Alan: There's one other component here, and this is a very broad statement, but I think it's been wildly accurate over the last 25 years.
There are different expectations in law — and even different consumer expectations — around different *uses* of data. You can pretty much do whatever you want, and nobody asks how valid your consent is, if you're using data for security or fraud prevention purposes. The recognition is that those are laudable goals. Fine.
But if you're using data for ad targeting, or even analytics, that tends to be under a different level of scrutiny. The challenge is that most of these proxy networks occupy *both* use cases. It's a little weird for me if you're getting in the door with a security use and then staying inside with an ad targeting use. That doesn't sit right.
Rob: Does this trip up data broker laws in different states, or federally? Mainly states, I guess.
Alan: The data broker thing is interesting, because I don't know what a data broker *is*. Palantir apparently isn't one — at least they're not registered anywhere. None of the big tech companies are. T-Mobile is registered; the other telcos are not. I don't know why. I don't know why Visa and Mastercard and maybe Amex are not data brokers — I guess they have a more direct relationship with users and fall outside the definition.
So my answer is that I don't think we've coalesced on a definition of "data broker" in a way that makes sense. These companies could very well meet it. I don't see them as a rife enforcement target at this point. It seems like Tom Kemp and his colleagues are happy to keep going after the traditional Acxiom-type data brokers and the ad techs. They don't seem to be expanding the tent. And there are 600 companies in that tent — I'd bet there are another six to eight hundred who look a lot like them and aren't in it. They'll focus on those long before they focus on residential proxy networks.
Rob: That's probably right. There are two problems: the low-hanging fruit problem — more visible actors, more of them — and, related, the brain damage problem. Understanding this stuff is tricky, so you go with the low-hanging fruit when it's a lot more work to understand how the rest of it operates.
Alan: And a lot of these companies are hanging their hat on "well, we get consent." That gets tricky too, because I don't think one can manifest consent for the seriousness of the level of access being provided — to the network and to their partners, and sometimes there's a very long list of partners. I'm uncomfortable with that being a true manifestation of consent.
But I've also been pretty critical of consent as a concept generally. Consent is one of those things privacy people use to make themselves feel better. I don't think it really does much good. There are some useful places for it, but Europe has demonstrated that it's just not helpful.
Rob: Especially when you start looking at the next layer — it has to be equally weighted, you have to explain, you need age-specific consents, bite-sized notices. Once you start overlapping all those requirements it becomes an n-by-n problem for anyone with meaningful scale.
Alan: And even simple downloadable software EULAs. This gets a little outside the privacy world, but there are really important things in there that I promise very few of your listeners have actually read. Maybe you've read one of them.
And by the way — just because bad stuff is happening somewhere else doesn't justify bad stuff happening here. But hanging your hat on consent here is a really problematic place to be.
Rob: One of my prior guests, Ben Edelman, talked a bunch about getting his start in the downloadable software and adware space. You've looked at this from the privacy and legal side too. Are there analogs — end user licensing agreement issues, that kind of thing — worth exploring in the comparison between proxies and adware?
Alan: Absolutely. And by the way, proxies were a component of the adware space.
The adware world was a lot of fun. I built my bones there when I opened up my practice — it was the first place I got real traction, working with adware companies. Then I started working with one of them, a company called Direct Revenue, and then got hired by TRUSTe — now TrustArc — which back then was a small nonprofit trying to create a self-reg program to rein in the adware guys.
I still think there's a debate to be had about whether that model for delivering advertising, coupled with certain types of content, is a valid business model. I think it can be. I was actually hopeful — and if Ben is listening, he's going to hate this — that when the Zango guys were about to announce a licensing deal with one of the big record companies, that might be a way to say: okay, you've got valuable content, and in exchange for it you're going to deal with a certain number of pop-ups. It would have removed a lot of the intellectual property issues around the adware space. I'm not even sure that deal ever really got off the books, and it ultimately didn't work out — partly because the value those companies were delivering to society was questionable at best.
So I think they're different from residential proxies, where I do think there's a societal benefit. As we discussed, it helps prevent fraud, it helps with measurement. And anywhere you're facilitating an independent third-party use of data to do the things big tech thinks it should be the only one able to do, I think that's a laudable goal.
But the flip side of the adware space is that you had a bunch of those companies literally shooting at each other on the desktop, ruining people's computers — creating problems for consumers, and then problems for the Geek Squad at Best Buy trying to figure out what in the world happened.
And then there was the whole opt-out issue: they never really created a persistent way to opt out. Which — I'm rambling a bit here — takes me to the point that the residential proxy guys also have an opt-out problem, as far as I can tell. I don't know how you stop it. I get that you can consent to it. I don't know how you *remove* your consent.
Rob: Right. And the thing I found really problematic on consent — going back to the LG TV example. To install the Pac-Man game, you need to create an LG TV account. To create the account, you have to state that you're 18, which you can just assert; there's no test of it. And have a valid email address. Once you do that, you've installed the software, because you don't want to see ads while you play. Then the TV is off. Maybe you never play the game again.
The problem is there's no way to see that this is going on. In the adware case, you'd get a pop-up with some branding — provided by Gator, whatever it was back in the day. At least there was a way to see it, a foothold from which you could un-consent.
I don't know if they're emailing the address that got created for the LG TV account. The problem is they're hoping you forget you consented.
Alan: I agree with all that, but I also don't think they've even provided a way to revoke consent. The adware guys mostly had an opt-out tool. It took forever to get there, it had a bunch of dark patterns to get through, and I'm not sure it always worked well — but at least they had one.
The problem I have with these proxy networks is that they're enabling a whole bunch of really important, and at times scary, functionality on these devices. And just because my six-year-old somehow figured out how to turn it on does not mean the household has consented to it. Since I have no idea it's even running in the background, I have no ability to turn it off. That's a problem.
Rob: I do worry, speaking as someone on the safety side, that there genuinely are legitimate security use cases for residential IPs being used. To the earlier point, it's an escalation: because it's being used, it has to continue to be used. And that creates a financial incentive.
I recall back in the adware days, in my first job buying online advertising, we had a pre-existing relationship with one of the providers. I won't mention which one — maybe you could guess. It was popping up on a lead gen form, and the charge for popping up on that form was a $450 CPM. But the company I worked for was making $700 in revenue for every thousand users. So it worked very well.
I worry about the financial incentives for these companies being so good. It seems like a time of real riches for the proxy companies right now.
Alan: They are, and they will continue to do so until somebody steps in. And I don't know who the sheriff is at this point. That's really the problem, isn't it?
Rob: Does it come back to having to KYC everyone? You have to KYB all the businesses using it, KYC all the users consenting to it, make sure it's an adult and not a child — actually do age verification instead of letting them create an LG TV account with a statement and an email address. Do you think this eventually takes us down the path of age verification and business verification for everything?
Alan: I like the idea of KYC. The age verification thing seems to be happening regardless of how this shakes out, and maybe that becomes a silver lining in what I think will otherwise be a horrible set of public policy outcomes as governments keep jumping into the age verification game.
They're going to start with very light verification, like what Australia's currently doing. Then they'll realize kids are circumventing it — perhaps a lot of kids — and they'll say, "We need to double down." As it becomes more and more restrictive, you're going to have an arms race. I don't know about you, but I don't want to get into an arms race with any 16-year-old, because I'm probably going to lose. They're creative and clever and have a lot more time on their hands than I do.
So we're veering into a world where you're going to need to show a government ID to surf the internet. That's not a great place to be, and there are smarter people than me who have opined on this consistently. I almost think that's beside the point, because governments seem completely dedicated to jumping in here.
You've got the European Union using a report that said very different things to justify their position. They commissioned a thoughtful report that mostly said, "This is really complicated, and we need to do a bunch of things that cost a lot of time and money." And Ursula von der Leyen and her colleagues are saying, "I think the report says we should do age verification." I'm not sure that's exactly what the report said. It sort of said, "If you have to do it, here are some ways you can."
Anyway, that's a side conversation — but the age verification thing is going to eat the internet in '27, '28.
Rob: There's a lot there that's problematic, and definitely more conversation to be had. But on the competition side — talking more generally about scraping, which is one of the main uses for these networks — do you think there's a fairness angle? These are called walled gardens because there's data stuck in them, so we need to be able to scrape them. Or maybe it's narrower: researchers should be able to scrape to hold these companies accountable. How do you think about the antitrust angle to scraping?
Alan: Where a lot of this is going is still TBD. hiQ lost against LinkedIn, but some other cases pushing for a broader ability to scrape have prevailed. And you've got Perplexity, who seem to be drawing the distinction that since the *user* is telling the browser to do something, it's okay for them to scrape Amazon. Amazon says no, that violates our terms of service. That case hasn't been fully adjudicated, but the initial leaning is that Amazon may not be able to use the Computer Fraud and Abuse Act to push back on this.
You're talking about fairness. What I look for is allies. In a perverse way, some of the AI companies — whose larger goal seems to be to scrape the entirety of the internet in an unfettered way — if they're able to get it done, that perhaps suggests DoubleVerify or IAS or one of those companies will also be able to. We'll see. Right now it's still very Wild West, and the big tech companies' initial approach of "we'll stop this via the CFAA" may not hold water over the long term.
Rob: It's also interesting when you have companies with consumer footprints as well as business footprints. They could make a case to their consumers — "this service will get better if you allow us to use your machine." There's definitely an aspect of that for AI companies that now have big install bases of users. They could do things they hadn't needed to do before. I wonder if that dynamic emerges over time.
Alan: It's going to be really interesting to follow. I thought the retailers had more of a leg to stand on, but it's starting to look like maybe they don't. For a regular publisher, what percentage of users are logged in? But with a retailer, a very high percentage of their customers are eventually logged in. And if you're logged in, you're subject to a certain set of terms — that seems to be on more solid footing.
Rob: Yeah, we will see. It also reminds me of early scraping ten-plus years ago. If you ever played any of those Java games that loaded in the browser, they were using your IP to scrape in the background. So — yay, Common Crawl. Anyway, it's a wild space.
Rob: One of the reasons I wanted to get you on the pod was that I've really appreciated the guests you've had. I've talked a lot to Ari about his podcast too. What I'm trying to do here is something that appeals to people who work in these areas, but that over time draws other people in as well. Tell me more about how you've found the experience — how it interacts with the other parts of your business and your day to day.
Alan: I've had so much fun, and I'm grateful Ari decided to turn over the keys.
My approach is to try to find a middle ground: policy people who understand how the business works, and really smart business people who at least have a general understanding of the regulatory environment. My theory is that a lot of people are making decisions in this space in ignorance of the regulatory rules. And I don't mean people scamming — I mean, for instance, that a good portion of the ad tech space has doubled down on some flavor of probabilistic IDs, and a large subcomponent has said, "We're going to do one better and attach it to identifiable data."
I think both of those approaches are rife with problems, some of which are privacy and legal. And some of which are: what happens when Google decides to do another about-face, and the thing you've gone all in on for two years effectively blows up?
That's a long-winded way of saying those are the issues I want to bring to the table. There are other privacy podcasts that get into the minutiae of what the Article 29 Working Party or the EDPB really meant by a given document. Those are fascinating discussions to have. I try to keep mine a little broader and a little less wonky, so I can appeal to the constituency with one foot in either camp.
Rob: I like the idea of getting the product people, the policy people, and the regulators talking to each other — or at least building some shared knowledge they can reference. I've had regulators send me messages saying, "Hey, I saw this thing you wrote," or "I saw this person you were talking to." I think that's really interesting.
These topics are so complex that you're not going to figure them out from one angle. You have to look at the technical side and the policy side. I've seen so many of these things take far longer than they needed to because people weren't open to perspectives they're not used to — or wouldn't know who to ask or where to start.
Alan: It's a fun niche. In terms of strategy, I try to find people who are well known enough that others want to hear what they have to say, but who can also speak effectively on the particular set of issues I want to raise to the community.
And one other component: I love people who are willing to speak recklessly. You don't always get that with a regulator — although I thought Jon Leibowitz, former FTC, did a fantastic job, and Commissioner Meador was great both at Marketecture and on the pod. But Megan Gray is a great example of somebody who is wicked smart on this stuff and just says what's on her mind. I think that's what an audience wants to hear — the unvarnished version, not the corporate speak.
If you look at the people I've brought on the pod, I've stayed away from clients — I don't think I've had one on, and I'm pretty sure I haven't. I tend not to have ad tech vendors. I had Bill Wise on, but I've known Bill for 25 years, he's hilarious and really smart, so he's a great guest. But I tend to turn down requests from the chief privacy officer at fill-in-the-blank ad tech, because they're just going to want to talk about how good and how compliant they are. That's not that interesting.
If instead I can bring in somebody and ask, "What was it like to build the IAB TCF? How did you balance all that?" — that's an interesting conversation.
Rob: Have you ever gotten pushback or blowback based on things your guests have said? Where someone says you're giving this person a platform to talk trash about Company X? I could imagine that happening — the guest says something that's seen as offside by some important corporate person.
Alan: No. I tend to directly annoy a lot of people in big tech just by what *I* say. Some of it's on the pod, some of it's in the writing, some of it's the monthly Chapell Regulatory Insider report I put out — although a bunch of big tech companies subscribe because they want the insights. Occasionally I get the call: "Dude, really? You had to say that?"
The closest direct answer to your question is this. I had Don Marti on — he's been on a couple of times, super smart, I really like him — talking about the attribution framework being created by the W3C. Don has a very direct opinion on that set of standards, and he refers to the people creating it as the attribution cartel. I thought it was a really good discussion.
Somebody reached out to me, a friend of the pod, and said, "I think it would be really interesting if you brought in somebody who was creating the spec, and got the W3C perspective." So I brought in somebody from Mozilla to speak to that. That kind of thing is really helpful. It wasn't that having Don on was bad — but it was probably telling a portion of the tale, and having the Mozilla folks on told the other side.
Rob: I heard those conversations. I thought they were great.
Having worked at Google and Meta myself — people sometimes assume there's one viewpoint the company has. There isn't. These are human beings, with lots of internal struggles and disagreements, things they're preserving optionality on, decisions they've made that maybe they regret. There's all kinds of interesting fodder for discussion.
Alan: And it's too bad that by company policy, none of those folks are coming on podcasts. It's not just my podcast. It's very rare you're going to get somebody who knows where the bodies are buried within one of those orgs. I think that's a shame, because a lot of them are really smart.
To the extent they do come on, it's Alex Cone talking about how wonderful the Privacy Sandbox is. That's not the conversation I want to have — and not just because I don't think it's so wonderful. If you're not going to really engage on the trade-offs in play with that kind of tool, there's no point having the discussion. And not to beat up on Alex; he's a nice guy and a good friend.
Rob: Alex is great. I like the way Nilay Patel frames his podcast — it's *The Verge* versus media training. Those of us who've been through several rounds of media training know what that means.
When I joined Google, a bunch of people asked me, "How did you get to be able to talk on behalf of the company on Twitter?" I said, "I don't know — just don't say dumb stuff." But you also have to be able to have substantive discussions, and you obviously have to get the license from the company to do it.
I did notice a lot of Google folks were posting a lot on LinkedIn. It felt like people were nervous about getting into a Twitter discussion — or X now — but LinkedIn was different. I'm curious to see how this engagement of employees pans out. Maybe they're not going on podcasts, but I think you can learn a lot from what people post, and what they like from their company, on social media.
Alan: A lot of the time it's really insightful but has nothing to do with their business model. That's fine. I'd rather get that than nothing.
Rob: I was talking to someone about this recently. One of the things that's happened with media — because a lot of publications are ad-based, they've historically not covered ads very well, or very much, in my opinion. The big publications like the *New York Times* don't write much about ad tech. I sense part of that is shying away from the subject.
You and I both worked at Jupiter Research many years ago. As an analyst I'd talk to the media a lot, but often the journalists knew as much, if not more, about the subject than I did. It's just that at the time, you wanted an analyst from Forrester or Jupiter or Gartner to talk about this internet thing.
So — are media people good podcast guests? In many cases they've talked to a lot of folks and have very good perspectives. How do you think about that guest profile?
Alan: I think journalists are fantastic guests, because they tend to be interesting people with varied life experience. I had Marty Swant on, and a couple of other journalists — mostly trade journalists.
The challenge is that I've tried to get Mike Isaac on; someday he'll come on. But his domain is tech, and the perception of me is that I'm ads — which is the redheaded stepchild at best of tech. So there's a bit of "do I really want to talk about that?" He may not.
I've had a bunch of advocates on too, partly because I think it's really helpful for my audience to hear from people even if you disagree with them, but also because people should understand the history. I had Cindy Cohn on. The reason the internet works is largely a direct result of the efforts of people like Cindy.
Rob: There are some very interesting folks. Again, just starting this thing out, I'm thinking about the audience and what their expectations are as you build it. Are they learning about things? What's actually going to be useful in their daily jobs? Or is it interesting history that everyone should know — part of the internet canon?
Alan: It's a really good question. I don't think you can spend too much time on the history. I'll tell you this: in my private practice I'm working with product people who have no idea what I'm talking about when I say DoubleClick/Abacus. That was a foundational principle. It might still be — it's certainly less so than it was.
There's a whole bunch of nuance around this rule of "thou shalt not touch PII in an ad serving context." And all they know is, "Well, look at LiveRamp. Why the heck can't we do whatever we want?" That's a valid question — absent some of the history.
Rob: I did a speaking engagement in the last year or two where I asked people about a certain privacy-related thing I would have expected everyone in the room to know about. Two people out of about 40 knew about it, and one of them had actually worked on the feature at that company. And that was only seven years prior — not ancient history.
But I agree, there's a bunch of this that's important to level-set with people.
Rob: Coming back to regulators — in some cases they may have an impossible job, right? The resourcing they have. It's asymmetric warfare with tech companies who can hire all these attorneys and outside counsel, and have product people, engineers, policy people. How do you think about where regulators should spend their time, or how they get up to speed?
Alan: My interactions with most regulators have been very positive, in that they actually do understand the space. But to your point — what you *know* and what you can demonstrate in court as part of an enforcement action are often very different things.
I had Tobias Judin on and we had a long debate around consent. He's sort of moved past consent; he thinks behavioral targeting should be prohibited. I said, "Great, let's do that in one specific market and see what happens." Because to be honest, do I know exactly what would happen and how it would play out? I don't. I think that would be an interesting experiment. I'd like to see much more experimentation.
I've also had Tom Kemp on. Tom is in a very different place than Tobias. Tobias is at the EDPB, he's very prominent, but his ability to make internet-wide change is different from Tom Kemp's ability at the California Privacy Protection Agency.
Those guys have figured out that there are very few headwinds opposing what they're doing. So they're in an empire-building phase. They've found a thing, a political area — horrible data brokers — and they've been able to say, "We're going to build an entire governmental apparatus around addressing this."
I've been whispering in Tom's ear for the last six months: "Okay, but is this the *only* privacy issue?" He's happy to talk. I'm not sure he's so happy to listen — partly because they want to build what they want to build, and right now they have a blank check to do it. To stop and do something else might not be the best path for the empire they're trying to build.
I don't know if that gives you any insights.
Rob: That's really helpful. This is the level of detail that gives you insight into what's going on. Similarly with the big tech companies — there's probably a level of detail people who'd recently left could talk about: the internal dynamics of how teams are structured, and what the internal incentives are around privacy and safety and AI. I do think eventually we learn a lot more if we have some of these people, as you put it, speaking recklessly.
Alan: I've built my career over the last twenty-something years on speaking recklessly. I see seams out there and I poke at them. Sometimes that ticks people off.
But what I hope is that it forces more constructive discussions — and that's really what we need. Over the last ten years particularly, there's been this weird narrative where everybody takes as gospel what the large tech company, usually Google, is telling them. Of course there's a backstory. Of course there's a bit of sleight of hand. They're businesses, they're trying to make money. But it's almost as if the ads industry thinks big brother would never steer us wrong. I think that's a problem, and I've built my career on pointing out exactly those things.
Rob: Well, I listen to your podcast, and everyone else should as well. Really appreciate you taking the time to chat with us, Alan. As always, it's fun to catch up — whether at a conference or on video, as it turns out.
Alan: Great seeing you, Rob. Hopefully I'll see you in real life soon.
Rob: Me too. Hope we will.