Serious Privacy
The PICCASO award winning Podcast, for those who are interested in the hottest field of human rights and laws on the digital frontier. Whether you are a professional who wants to learn more about privacy and privacy laws, data protection, GDPR or cyber law or someone who just finds this fascinating, we have topics for you from data management to cybersecurity, from social justice to data ethics and AI and digital identity protection. In-depth information on serious privacy topics including interviews with privacy leadership, privacy culture, serious discussions, and more.
This podcast, hosted by Dr. K Royal, Paul Breitbarth and Ralph O'Brien, features open, unscripted discussions with global privacy professionals (those kitchen table or back porch conversations) where you hear the opinions and thoughts of those who are on the front lines working on the newest issues in handling personal data. Real information on your schedule - because the world needs serious privacy.
Follow us on BlueSky (@seriousprivacy.eu) or LinkedIn
Serious Privacy
Week in Privacy - Information is Beautiful
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal cover a week in privacy, enforcement actions, breaches, settlements (dud you see the one with Meta?), and more. Check out this website for visualizations of data breaches
https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!
Subscribe today HERE
Back the Board Game!
https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-game
Powered by TrustArc
From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.
You're listening to the award-winning Serious Privacy Podcast sponsored by TrustArc. Please welcome your hosts, Paul Breitbart, Ralph O'Brien, and Dr. K Royal.
PaulWe must be coming to the end of the summer because data protection has started to explode again. We see fine upon fine. We informed you last week in an emergency section in our regular episode of Meta's 18 billion dollar settlement in the minor protection case. But we've also seen fines in recent weeks, 400 million to TikTok, 825 million euro to Uber, and more things happening in privacy and data protection around the world. Break is over, and we just continue as usual. And as usual, my name is Pal Breitbart. My name is Ralph O'Brien.
KAnd I'm K Royal, and welcome to Serious Privacy. So I know we've got a lot to get into this week. It's going to be more quality than quantity. There's a lot happening, but still the quality of what's happening is what we're going to focus on. So with that, let's see. What are we going to go with the unexpected question? Let's do this one. What is the most boring thing about you?
RalphWhere to be Well, what to begin? The fact I can't even think of a response to that question probably tells you the depth of mundanity that there is in my life. No, yeah, what's the most boring thing? Do you know what? It's it's a principle of mine to never be boring, never be average, never be grey. If somebody called me boring or average, I think that would be the worst insults they could, you know, uh send my way. But I guess I do have some pretty bad habits, which is often for just sitting and watching endless shows on television as a way to de-stress at the end of the day. Boring sofa surfer, perhaps. It's not all gym and board games and outdancing and out at exciting clubs at the weekends, sadly.
KPaul, what you got? What's the most boring thing about you?
PaulMy relationship status and my dating life.
KWell, I was actually gonna say the most boring thing about me is that I'm married.
RalphThat could be very exciting, huh?
KIt could be. Tim makes it fantastic. There's no doubt about that, but it's a pretty boring fact, right? If you go sharing your bio and what you do, throw in there, and she's married. I have three cats that own me, that's pretty boring.
RalphThat own you, that's about right.
KThat own me, exactly. I just finished a puzzle, that's pretty boring.
PaulOh, I don't mind a puzzle.
KI don't know.
PaulBut you prefer a board game, I think.
RalphI do prefer a board game. Great, nice into it, Paul. I should perhaps note to all of our listeners that the Kickstarter page for registering your interest is open now, although the Kickstarter won't officially launch to October. If you did want to go to Kickstarter and find Serious Privacy the Data game, I would be more than happy for you to register to the notification upon its launch. Thank you. And we'll put a link in the show notes.
KAnd it is the data game, not the dating game.
PaulOh, oh, then I'm slightly less interested.
RalphSorry, Ralph. Serious Privacy the Dating Game. I think that's another one to add after the cookbook.
KFunny enough, one of the first presentations I ever did with Phil Lee back in San Jose, we presented it as international transfers. You could do standard contractual clauses, you could do binding corporate rules, or you could do the whatever was in place for the U.S. at the time, and Phil Lee was interviewing someone as in the dating game. Which of these would you choose? What are your questions to do these three bachelors?
PaulDo you want to have binding corporate rules with me instead of a prenup?
KI love it. Okay, should we actually get to some breaking news? I know it's not breaking news now because we added an update to the section that went live this week that we're recording it, but in the few hours before we started it, the meta settlement came out with the 16.8 billion, am I remembering that right? 16.8, 16.9 billion for child safety and a lot of rules that they have to put in place for children online. And of course, our outrage that it's limited to the US, right?
PaulYeah. But we actually saw something similar happen in Brazil earlier in August, because the Brazilian Data Protection Authority signed TikTok 153.7 million reiches, which is about 29.7 million US dollars, 25.5 million euros, and 21.9 British pounds. So also quite a significant amount. And that also includes a compliance plan committed to by ByteTance, the owner of TikTok, to correct irregularities and improve data processing. So the ANPD found that TikTok violated the Brazilian data protection laws. In any case, processing personal data of children and adolescents without the existence of a valid legal hypothesis by allowing access to the TikTok feed also without registration, failure to adopt measures to present the processing of personal data of children without registration and with registration, also processing of miners' data without a valid legal basis, no effective measures to prevent miners from registering on the platform, and also a failure to demonstrate effective measures capable of proving compliance with data protection standards. So on top of the fine, it dense has committed to implement certain safeguards, very similar to what we've seen in the Meta case. In this case, for the unregistered users, the experience needs to be limited to 12 hours maximum. I don't see in what time frame, but I would assume overall, users may not create content, comment, send direct messages or interact socially without registering, no possibility to follow other users or to be followed, no posting or watching of live streams, very limited customization, total suspension of advertisement in Brazil, and access only to age-appropriate content, so content that is appropriate for all ages. For registered account, the social network must automatically apply the most restrictive privacy settings to accounts of those under 16, which can only be changed with the authorization of parents or guardians, and they need to reinforce their parental control systems to allow parents to supervise, and it should implement stricts or content filters. Quite a significant compliance order on top of already a significant fine.
KYeah, and we're starting to see this become more and more common. As y'all know, I think the first one to kick it off was Japan, unless you count the US states. I think Utah may have kicked off right before Japan did. But protections for children is the theme this year, right? That's what we're going for. We've been screaming for it for years, but finally starting to see that materialize. And I'm not surprised. It takes a while for the government to move to recognize that people aren't just screaming woof, the dam's not about to blow, and but they have to do their research, have to gather their metrics, or something horrible usually has to happen that prompts the the regulators to look at something. So not surprised that we're getting there eventually.
PaulAnd TikTok is paying even more because they also agreed to finally pay the $400 million settlement in the US to end a lawsuit on the violation of children's privacy under COPA. This is a deal that was already created in 2024 by the Biden Department of Justice. And at the time they alleged that ByteDence had collected vast amounts of data on millions of users under the age of 13 in violation of COPA. Not a good week, I would say, for TikTok.
KWho's going to pull up the numbers and say how long it takes them to make that amount of money?
PaulAnd they are valued at 55.5 billion US.
RalphYeah, it's interesting. I I often look at all these numbers of fines and penalties, and of course that's not the only enforcement action people can take. I'm more sometimes interested in the commitments towards change that they're going to do afterwards. But I sometimes wonder about the rates of how much of this is actually paid and when it's paid. I think Ireland last year put out some interesting statements of how little they'd actually managed to draw back of the fines it actually issued. It'd be really interesting to look at the numbers of fines and penalties compared to how much and when they get paid.
KBut that does remind me of something that we gave for the update for the one that's about to be published last week. We said why a settlement, why not a lawsuit? A lawsuit would be stronger because then they would be found guilty of doing something. A settlement is the only one that's going to put in the behavioral changes. You're not going to get that with winning a lawsuit. The settlement, however, is going to be able to impose the rules under which they act, and they'll be under federal oversight for 10 or 20 years, usually 20 years, to go with it. You're not going to get that with a lawsuit. So there are some pros to having it a settlement.
PaulYeah, but you would get it with regulatory action. We've seen it in FTC, in FTC compliance orders. We've seen it in just now in the compliance order from the Brazilian Data Protection Authority. We've seen it in others in Europe, whether we're processing bans or compliance orders attached to an investigation inclusion.
KAnd that's what this is. This is an investigation closure and a settlement. But those are the pros and cons of lawsuit versus settlement agreement. If you come to a settlement agreement, the FTC is able to impose a lot of behavioral changes and requirements that they wouldn't be able to do with a lawsuit. They would be able to do with a separate action, no doubt about that. But for that, there's pros and cons, is all I'm saying. So we like the behavioral changes being put in place. So one thing I want to bring up is not only in addition to the enforcement actions that are happening, we're also seeing a lot of breaches come back into the news. And before we go into the breaches, I know it's been a while since we mentioned this online. There's a wonderful website online from information is beautiful dot net. We can put the the link in the show notes. We don't tend to do that because we've heard most of y'all, you don't go to the show notes. But we'll put this link in there that way you can look for it. But it's information is beautiful dot net slash visualizations plural slash worlds dash biggest dash data dash breaches dash hacks. And in there you're able to look at how many breaches there have been by year. You can scroll down and you get a visualization of the sizes of what they are. So it looks like they go down till about 2004. But for right now, you can sort them on the number of sizes, the type of industry, the type of data, scroll over. And one of the biggest ones that's popping up right now is national public data, over a billion records lost, 2.7 billion of U.S. citizens for background checks, leaked on a hacking forum with name, social security numbers, physical addresses. One of the only ones that's that size is the Indonesian SIM cards with over a billion records lost, 1.3 billion SIM registrations revealing national identity numbers, phone numbers, and more. And so you can scroll in and see what the breaches are. The huge one from Marriott International is barely even size the size of the ones you're looking now. So just a really cool thing to go to if you're interested in what kind of, and this is around the world. If you scroll down, you can see them by types of data. It comes out with email addresses. The biggest ones there are LinkedIn and Facebook, personal details and passwords, the biggest one there is national public data, credit cards and banking, the biggest one is Indonesian SIM cards, health and personal records, the biggest one there is Cinniverse that happened in 2021. And then full sensitive details is Shanghai Police back in 2022. But it's just really interesting, especially those of you that also teach or prepare training materials for your company. Really interesting statistics to go to.
RalphEnough, that's how I use it. I'm really pleased you brought it up because I actually use that web page in nearly every training I do just to show people. Start off at the bottom of the page in 2005 and scroll up and say to people, say to my trainees, what do you notice? And of course they notice two things.
KAnd a lot of these you don't even hear about.
RalphAnd the second is the size increases. So it's a really good visual representation. I know Paul has got a big one to announce, but I'll just jump in very with some couple of very quick ones from the UK because we've been quite quiet at the end of the summer. The biggest one actually that just popped up across my feed today is Nigel Farage, the leader of the reform party here in the UK. It's actually worth mentioning that he did actually win. He is an MP again after beating out Count Binface in Clacton. He got about 40,000 votes, I think, and Count Binface got something like 10,000 votes or something. 10,000 people would rather vote for a bin. I think that's quite amusing. And essentially all of the main parties declined to stand. So that was quite an interesting little electoral thing. But the day after he stood, all of the investigations into his financial situation re-kicked off now that he's an MP again. But he's taken to the stage today to say that the GDPR is terrible for British business and it's an unnecessary burden. And ten years after leaving the EU, we shouldn't still have EU legislation in our law. So, you know, the GDPR is bad, bad, bad for British business, bad for innovation, bad for using data. And if reform got into power, we'd get rid of that horrible EU red tape. Now, I think we've seen all these arguments before. Horrible EU red tape, horrible, bad for business. My personal view here is, of course, that I quite like my fundamental rights and freedoms.
PaulThere is also this small little thing called the Council of Europe Convention on Fundamental Rights, on human rights, that the UK is also still a party to.
RalphYep. And I also still want to be adequate with the EU, of course. I think the Data Use and Access Act, in my mind, actually went too far to put in exemptions away from the GDPR already. We have made post-European adjustments to make life easier for British business. Though I think proportionality is and appropriateness and necessity is baked in all the way through the law anyway. So I don't think I'll give him any more column inches than he deserves. And the only other thing I want to say before we move on to the big one is the ChatGPT Apple plugin. People might have seen that OpenAI has released a plugin for Apple messages that allows the AI ChatGPT tool to read, search, draft, send, and delete iMessage, SMS, and RCS text directly within the Apple native messages app. So that's really interesting, because on Macs and on phones, of course, users can ask ChatGPT to summarise their conversations, suggest replies, analyze messages, send messages. Apparently, it requires user approval before it will send the message. I think my concerns are more about surveillance here and the capability of handing over all your messages to this third-party organization. Apple, for years, have said, we're going to be private, we're going to be very private. We governments will have will fight the government for you if they want access to your messages. However, it seems like they're allowing a third-party plug-in complete access. And if OpenAI have access to all the messages, then that's that sort of back door for governmental access and that other kind of stuff. I won't be doing it. I'll put it that way.
PaulOkay, then on to the Netherlands, where on the 21st of August, the Dutch Data Protection Authority fined Uber. Again, this is the fourth find for Uber by the Dutch CPA. This time it's almost 825 million euros for automated decision making and insufficient transparency. So you may recall that a couple of years ago, the French Ligue des droits de l'homme, uh LDH, represented 171 French Uber drivers in filing a complaint. So LDH lost lodged a complaint with the French Data Protection Authority, the KNIL, on behalf of the drivers. So this is one of the first representative actions on behalf of others at a large scale. I think this is a bigger scale than we than what we would usually see from Neub. Obviously, Uber is headquartered for its European establishment in Amsterdam, so in the Netherlands. So the KNEL had to forward the case to the Dutch GPA under the one-stop shock mechanism, but remained involved in the investigation. So the Dutch DPA has investigated. They came to the conclusion that indeed Uber used certain software to track drivers, both their behavior, also their customer reviews. And if the software detected a suspicion of fraud, or if customer reviews were too low, the accounts of drivers would be automatically deactivated. That could be a temporary suspension, but in case of persistent low customer reviews, it could also be a permanent deactivation. There was no human review in this whole process, so it was fully automated decision making. And the Dutch GPA comes to the conclusion that this is automated decision making with a legal effect or otherwise similar significant effect. If it immediately touches upon your daily income, then you can argue indeed that this is a significant effect on the individual. The Dutch GPA also found that Uber did not sufficiently inform drivers about the way that this automated decision making would be taking place. That is about the summary that I can give, because unfortunately so far, and contrary to what is custom, the Dutch EPA has not released the finding decision yet, or the investigatory report, or any more detail than the press release that they have put on their website. I can imagine that is because Uber has appealed, but in the past that has not prevented the DPA from releasing an edited version or a redacted version, I should say, of the finding report. But so far, no further details have been published. And I think that's it is important for others to be able to see also the legal argument here. Because obviously you can argue that this is automated decision making. I think everybody would agree that this is automated decision making. They would also agree that this is a significant effect because it touches upon somebody's income. But what is the underlying regal reasoning to come to those conclusions? I think that is very relevant for a lot of organizations out there to know, especially when they are dealing with fraud prevention, and which is fairly common. That you would have an argument about yes or no for customer reviews. I think that is a debate also to be had in court. But there are tons of companies out there who do fraud prevention with automated means. We've seen before in decisions from also published by the EVPB that in any case they would allow legitimate interest as a legal basis for automated decision making for fraud prevention. But there now seems to be some sort of limit of what you can do as an organization to counter fraud in an automated way. So I'm very curious to see what detail there would be available here.
RalphYeah, that is interesting. There's a couple of other little bits from it. It is, what's it, it's roughly 1.85 of the company's 2025 turnover. As you said, they are appealing based on the fact that there was 126 driver accounts deactivated for Mo ratings in 21. They're saying it's disproportionate as a fine. That's interesting. So it could be that the fine is fine, but the amount of fine might change, who knows? But it does really turn upon two questions for me. Number one, did a person look at the file before they turned it off? So was there meaningful human intervention, which they now say they have, but at the time they didn't? And secondly, the sort of the quieter finding from the Dutch regulator here is that Uber didn't adequately inform the drivers that the machine was involved, that the machine was making the call, which meant they had no ability to contest a decision they didn't know existed. That's kind of another thing. So this kind of comes in with the whole EU AI Act thing, which is about transparency, explainability, telling people what you're doing and what your processes are, as well as having meaningful human offer outs, meaningful human escape routes, huge fine. And I think the fourth of the Dutch of Uber?
PaulIt's the fourth. The first one was back in twenty eighteen, six hundred thousand euros. That was for the data breach that Uber failed to disclose, the hacker who they paid a hundred thousand. To just get away, good to go away and hand back the data. And then in 2023, there was a fine of 10 million euros in 2024 of 290 million euros. So you also see that there is a slowly but surely increase in their fines. The 10 million fine related to a failure to disclose the full details of retention periods. Uber has appealed internally to the DARF CPA. This was declared unfounded, the appeal. So that court, that case is now before the courts. The 290 million euro, that's the one I was most critical of, is the transfer of driver's data to the United States. Also, there, Uber has appealed. Apart from the 600,000 euro for the data breach that was not disclosed, all of these cases will end up before the Dutch courts.
KYep.
PaulOkay, what do you make of this? Of the Uber and Of this automated decision making. Would you assume that it would be a similar problem in the US?
KI absolutely I agree. That's automated decision making, and that's automated decision making that has a negative repercussion on people or a significant impact because it's their livelihood. Do I believe that Uber has now implemented meaningful human oversight? No. I don't. I'm sorry. I don't trust U.S. companies when something is that widespread. And yes, I know it's the European counterpart, but U.S. parent company, does that mean that everyone that's going to be kicked off of UGR or their account discontinued automatically? Do I believe that list is printed and given to a person every day? Probably. Do I really think that person's looking at it and making any decisions that are otherwise? No. I don't. So I don't see this as getting better.
PaulDo you think it's meaningful in terms of oversight?
KNo, no, it's not meaningful whatsoever. Most of us can't even keep up with the normal email that comes to our email boxes, much less something that would be a daily report of here's everybody, you kicked off being an Uber driver. No, I don't believe that's going to be meaningful. Even if a human opens it, it can't be meaningful. How many are they losing per day? Per week? We don't have those numbers, right?
PaulNo. No, that is something that I would expect to be included maybe in redacted form, but in the in the finding decision.
KYeah. How big of an issue is this, right?
PaulIf we find more, we will update in a future episode. But for now, this is what we can share about the Uber find.
KAnd if you're an Uber driver in the US, pay attention. For all we know, it's happening here too. And it wouldn't make the news.
RalphYeah. I was about to follow up with that in the U.S. Isn't there something in the C CPA that's yet to come in, like January or something, about automated decision making technology as well in California?
KYep. It took effect already. But the the cross checks and the certifications and the audits and everything start next year. And then the first audit you have to turn in from a cyber perspective, which is what people think we're talking about. It's not. That's chapter nine. We're talking chapter 10 with the automated decision making. Yeah, that the the law itself has already gone into action, but meaningful enforcement is next year. I hope. Maybe I'm lying out the my eye teeth, and for some reason I'm thinking 2027 because of the cyber audits. I should probably know this stuff, right?
RalphYeah. There's so much to keep track of these days. I was looking at California's SV7 the other day, which is, I believe, on the table about what they call it, no robobosses, which is about the use of automated decision making in your HR recruitment and HR sort of performance monitoring situation. There's nothing like having your interview, your performance interview with your AI chatbot every year.
KOh my goodness, right? And I will say I just double-checked myself, I was correct. Good to know. Rattling things off the top of your head, right? But no, I do think it's interesting with the automated decision making, as you say, the video interviews that people are undergoing for jobs. I have a lot of privacy friends looking for jobs right now. And as y'all know, I watch the job market because that's how you find out what's happening on for pay raises and remote versus hybrid. It's really interesting to watch. But I had a friend that called me the other day and said she was just asked, would she be willing to go through the initial video hiring process? And she's can I refuse that? I'm like, you should be able to refuse it. It's not that it's being recorded her interviewing with a human, it's an actual one person, you answer prompts and whatever. And I'm now looking for someone in Canada at a basic level, entry-level analyst role for my team. Hey, share that out. And I was asked if I would be willing for our position to do the video. And I'm like, we offer that? Since when?
PaulWhen was this reviewed by legal? When was this approved by legal?
KFirst of all, no, I don't want my person redoing. I said, but on the other hand, maybe that's a good test for my person is they need to refuse to do the video. But yeah, I have to dig into that now.
PaulThat's how you create your own work.
KRight?
RalphI have I have looked around myself at the job market and I have seen it increasingly in play. This idea that you would do a first interview with Yeah. You basically say, hey, click this button for which role you're applying to, then I will go to the internet and get appropriate questions to ask you. And it's and I'm like, with the amount of rubbish that's out there about data protection, I wouldn't be confident.
PaulRight. No, but it's it already starts a phase before that, before because even to get to the interview, you already need to stand the test of AI, picking your CV out of the stack of CVs that are submitted, which already is a big issue in my view. It's horrendous. Most companies are not even transparent about the fact that they're doing this. But as soon as your CV is somewhat non-standard, then already you know that an AI selection process.
KYeah, so don't go for pretty resumes, people. Just go plain, blank, probably a human's not looking at it anyway. Don't won't worry about it looking good. Just yeah.
RalphActually, that's what my cousin does for a living. Oh, big shout out to my cousin who's recently moved to Katie, Texas, by the way. Welcome to Texas. Welcome to Texas indeed, with his fiance. And and that's his job. His job is to help people write their CVs so that AI recruitment selection tools will choose it. And how does this company do that? By using AI tools.
KSo using AI tools.
RalphSo now you've got people writing their CVs with AI so that other AI tools will select them.
KYes.
PaulSo that you can be interviewed by AI for a role that wouldn't exist, will not exist in a couple of years because of AI.
KRight. And you're supposed to disclaim if you're using AI for your job search and your resume and everything, which is crazy. Absolutely crazy. One of the reasons why I'm taking my master's in AI and my next semester starts, but I'm gonna moan a little bit here because as Ralph said, there's always a good time for a little moan. I had a perfect 100% score in my class for compliance on AI until the group project at the end, which gave me 21 out of 25 points and didn't even give any comments as to why I broke my perfect score.
RalphIt wasn't you, it was the group.
KMy group was fantastic, I'll say that. The group was fantastic. But yeah. And my daughter's like, Really? You're moaning about a less than perfect score? Absolutely I am. But this semester I'll be taking AI innovation and ethics in AI. So if I learn anything earth-shattering, I'll be sure to share this to the class. But before we get off for today, did y'all have any other stories to share?
PaulI have one more. One more. And that one brings us to Ireland in the 17th century. Well. Oh, sweet. Thanks to Politico. Credit where credit is due. But there is some discussion in Europe about class actions. And the European Union introduced a class action law a couple of years ago that member states are required to implement. Also, GDPR has provisions for class actions and group actions against data controllers or data processors that allegedly violate GDPR. We've just seen the representative action from the Ligue de Dois de l'homme against Uber in the Dutch GPA investigation. We also see class actions happening, many in the Netherlands, because Netherlands has a class action law that predates already the European directive, also for data protection violations. But for big tech, that actually is more difficult because most of big tech is located in Ireland. And Ireland does allow collective legal action against companies. But the one thing that they do not allow is for legal proceedings to be financed by an outside party. And that means that for most of the class actions, the financing mechanisms, because these things are costly because they drag on years and years, cannot be fundraised. Because outside parties that that are not involved, that are not a party in the case are not allowed to pay for it. So only if you can bootstrap your own class action, you are able and allowed to do so in Ireland. But otherwise, as some would say, you're cooked. Like an undercooked potato.
KAn undercooked potato. Before we left, I wanted to make sure that we gave a big shout out because this has hit the world that Dolly Parton passed away. We're recording this on the 26th, so she passed away yesterday, almost 18 months from the time she lost her husband, and they were very close. Her family's released information, but it has smacked the world upside the head to lose Dolly Parton. She is quite the icon on so many different levels. So many different levels. And then also Ralph brought up this morning that Tim Curry also died earlier today. So I know this will be a week later when y'all hear this from us, but just know that we too will take a moment of silence to honor the legacy of Dolly Parton.
PaulYeah, and maybe on top of that, I saw a tribute from Jo Jones of the IPP actually calling her even a champion of privacy.
KYeah.
PaulBecause her mama taught her to keep something back for you. You can give what you've got to give, but don't give it all away. Always keep something for you, and that's what she did.
KYeah. Her marriage life with Carl was very private. Most people had no idea who her husband's name was, no idea. I lived in Severeville, Tennessee, for a little while when I first moved out of the South, almost 30 years old. And so I was very familiar with what she did to the local community and the books to every kid and the scholarships to every kid that graduated high school. She was an unstoppable force. I also lost my kid at Dollywood. So there you go.
RalphOh, you've been to Dollywood. That's so cool. I would love to guard. She also donated a lot of money to help the Moderna vaccine during the time of COVID, of course.
PaulAnd she gave away books. Books to libraries, to school libraries, which is I think the best thing anybody can do.
KEvery kid from the time they started school, even in kindergarten, would get a free book a year from her.
RalphThat's amazing. So perhaps we should finish with a couple of dolly quotes. And no, I'm not going to use it costs a lot of money to look this cheap. But the one for the two I really like, the way I see it, if you want the rainbow, you've got to put up with the rain. But the one I really like of hers is don't get so busy making a living that you forget to make a life.
KYep.
PaulAnd on that note, we'll wrap up this week's episode. Thank you for listening. Until next week, goodbye.
KBye, y'all.
TimNow that was serious privacy. Please subscribe on your favorite podcast app and leave us a review. You can find us on LinkedIn, Instagram, and Blue Sky at Sirious Privacy. Feel free to drop us a question or a comment. We'd love to hear from you.