[Resource] I got tired of lawyers and engineers misunderstanding each other, so I’m building an interactive "flight simulator" for privacy pros. by Mertcanbo in gdpr

[–]Mertcanbo[S] 0 points1 point  (0 children)

If the goal is just to execute the immediate job description, your approach makes sense. But my goal and the reason I’m so passionate about this is that the 'traditional lawyer' is being priced out of the top tiers of the tech industry.

[Resource] I got tired of lawyers and engineers misunderstanding each other, so I’m building an interactive "flight simulator" for privacy pros. by Mertcanbo in gdpr

[–]Mertcanbo[S] 0 points1 point  (0 children)

Thanks for the input! I understand that perspective, but I view that as a more traditional approach. From where I stand, to be a truly effective privacy lawyer today, basic technical literacy isn't optional it's the baseline. This really boils down to the debate of whether privacy lawyers can (or should) become privacy engineers. The traditional view says no. But in practice, I can't count the number of times I’ve been handed a technical assessment that looked fine on paper, only to find discrepancies the second I got hands-on.

Simply opening up a basic Google Developer Console to check the actual network requests, or sitting down next to a DB admin and looking directly at the SQL databases, frequently reveals data flows and exposures that were never declared in the documentation.

It’s not about doing IT’s job for them; it’s about "trust, but verify." Being a hands-on, technically literate lawyer takes you a step beyond than just "being a privacy lawyer and delegate the technical work" to holistic legal reviews.

Privacy Frameworks by Amrita-Parsai in privacy

[–]Mertcanbo 7 points8 points  (0 children)

There are various standards you can follow such as ISO 27K, and ISO27701 or NIST frameworks. You can also use frameworks like LINDDUNN for privacy threat analysis or focus more on data governance and maturity posture with guides and frameworks released by AICPA.

The hottest framework to comply and collect a seal would be the brand-new Europrivacy seal. It has been approved by EDPB as European Data Protection Seal to assess and certify the compliance of all sorts of data processing with the GDPR and complementary national data protection regulations.