Hosted by Data Privacy Board Member Costco
Agenda
Wednesday, September 2
11:30 AM
Registration Opens
12:00 PM
Lunch Discussions
Grab a seat and get to know all of the great privacy leaders at the Summit.
1:00 PM
Welcome & Introduction
1:15 PM
Case Study
Data Retention as a Business Strategy: Turning Compliance Frameworks into Measurable Value

Pruthvi Gurram, Privacy and Data Protection Manager at American Airlines
Privacy programs are often viewed as cost centers focused on regulatory obligations. This session explores how American Airlines is reframing data retention as a business strategy that delivers operational, financial, and governance benefits. Pruthvi Gurram, Privacy and Data Protection Manager, will share lessons learned from partnering with HR, technology teams, and application owners to reduce unnecessary data, improve accountability, support application retirement initiatives, and create sustainable governance practices. Attendees will gain practical insights into using retention frameworks to reduce cost, lower risk, and demonstrate business value beyond compliance.
1:45 PM
Break
1:55 PM
Case Study
PIA as Superpower: Perspectives From 25 Years of Privacy Assessments

Helen Goff, Global Privacy Counsel at Costco
Helen Goff, Global Privacy Counsel, will share the often-overlooked strategic value of privacy assessments beyond meeting legal requirements. This session will highlight how Costco leverages privacy impact assessments to deliver business value and help the company stay ahead of rapid changes in technology and privacy laws.
2:25 PM
Break
2:35 PM
Case Study
We Resisted AI…Now It’s the Newest Privacy Teammate

Andrew Bjerken, Chief Privacy Officer & Michelle Hess, VP Data Compliance and Risk Management at Marriott Vacations Worldwide
Drew Bjerken, Chief Privacy Officer, and Michelle Hess, VP Data Compliance and Risk Management, will share a candid case study on how MVW’s Privacy team evolved from an “AI not allowed” mindset to embracing AI as its newest teammate. Through the lens of an unexpected workplace relationship, they’ll explore the challenges, missteps, breakthroughs, and lessons learned while integrating AI into privacy operations, highlighting where automation excels and where human judgment remains irreplaceable.
3:05 PM
Networking Break
3:35 PM
Case Study
Herding the AdTech Cats: Turning Governance Theory into Practice

Michelle Kraynak, VP, Chief Counsel, Chief Privacy Officer at Voya
Michelle Kraynak, VP, Chief Counsel, Chief Privacy Officer, Voya, will share how fragmented platforms, tags, signals, vendors, and data flows create privacy, compliance, and operational risks across the AdTech ecosystem. Michelle will discuss why a practical governance model built on visibility, control, and accountability is necessary, regardless of how much AdTech an organization uses. She’ll also walk through Voya’s journey of evolving theoretical governance concepts into actionable practices while maintaining a privacy-centric approach without overkill.
4:05 PM
Break
4:15 PM
Case Study
Fair Patterns in Practice: Turning “Don’t Be Creepy” into Enforceable Criteria

Aaron Weller, Leader – Privacy Innovation and Assurance, HP
Aaron Weller, Leader – Privacy Innovation and Assurance, will discuss HP’s journey to improve the privacy experience delivered to customers across products, digital services, and AI-enabled interactions. Drawing on privacy UX research, customer journey assessments, fair experience evaluations, and design review initiatives, he will share how HP identified customer pain points, translated abstract concepts such as fairness, transparency, and trust into actionable criteria, and integrated those insights into design and governance processes. The session will highlight lessons learned from both large-scale user experience research and practical implementation efforts that help teams create experiences that are compliant, trustworthy, and genuinely customer-centric.
4:45 PM
Adjourn
5:00 PM
Data Privacy Board Members-Only Dinner
Following our afternoon of conversations and case studies, we’ll have a fantastic dinner just for our members. It’s a perfect opportunity to connect with your privacy peers before a big day of brainstorming, discussion, and collaboration. For our guest attendees, we’ll see you tomorrow!
Thursday, September 3
8:00 AM
Breakfast Discussions
The conversations over coffee and eggs at this event are often more lively than any other conference’s happy hour. You’ll want to be here bright and early (and on time).
8:40 AM
Welcome Back
8:50 AM
Break
9:00 AM
WorkshopAI in Employment Decisions: Trusting the Black Box?
As organizations increasingly leverage AI-enabled and automated technologies, privacy teams are being asked to navigate a rapidly evolving landscape of legal, operational, and reputational risk. Norman White, Managing Counsel for Global Privacy Compliance at Intel, will facilitate this confidential discussion as we compare how our organizations are assessing and governing the use of AI in employment-related decisions across hiring, employee monitoring, performance management, and workforce planning. |
WorkshopTelling the Privacy Risk Story: Building a Strategy that Resonates
Privacy teams collect risk signals from countless places—but how do you turn that information into a story that drives action? Jennifer Myers, Privacy Compliance Manager at ADM, will lead this confidential discussion on the different ways we’re gathering and representing privacy risk internally. We’ll look at how we’re reporting those insights for our business partners, and explore how to move beyond metrics to answer the most important question: “So what?” Join us as we share approaches for creating meaningful risk narratives and visuals that support better decision-making and elevate privacy as a strategic business function. |
|---|
9:30 AM
Break
9:45 AM
WorkshopPrivacy Event or Incident? Defining the Line
When does a potential privacy issue become an incident — and are we all drawing that line in the same place? Beth Decker, Senior Director of Privacy Compliance at Ally, will facilitate this discussion to benchmark how our organizations define and distinguish privacy events and confirmed incidents, who makes that determination, and how those definitions shape our response processes. We’ll put our approaches to the test through common scenarios — from misdirected and undelivered mail to returned communications — and discuss how we’re handling the gray areas that continue to spark internal debate. |
WorkshopFrom Activity to Impact: Reporting Privacy Program Maturity
How are you measuring your program’s maturity, distinguishing activity from impact, and communicating that progress in ways that resonate with leadership? Chris Horan, Senior Manager for Privacy and Data Compliance, will facilitate this conversation as we compare the metrics and frameworks we’re using to assess maturity, explore how we’re balancing operational measures with business outcomes, and discuss the realities of collecting reliable data across fragmented systems and tools. We’ll also examine what has been most effective when reporting to executives, where our approaches have fallen short, and the common gaps that still make it difficult to tell a compelling story. Come prepared to share what’s working, what isn’t, and the questions you’re still trying to answer. |
|---|
10:15 AM
Networking Break
10:35 AM
WorkshopPrivacy Champions in the AI Era: Rethinking the Model
As AI adoption accelerates and privacy risks become more complex, is the traditional Privacy Champion model still the best way to extend privacy’s reach across the business? Joan Zhang, Legal Director of Global Privacy at Lenovo, will lead this conversation on building and sustaining Champion networks, and how we’re measuring whether they’re actually making an impact. We’ll also explore how AI could reshape our models — from determining new risks for Champions to navigate to automating guidance and reviews — and consider what the next evolution could be for this role. |
WorkshopPlanning for the Unexpected: Emerging Privacy Risks
As privacy teams confront increasingly novel technologies, business models, and data uses, traditional risk frameworks are being put to the test. Stephanie Reines, Director of Global Privacy – PIAs at Marriott International, will lead this conversation to explore how we’re identifying and responding to emerging privacy threats. From evolving technologies and business practices to the unexpected “weird” scenarios that don’t fit neatly into existing governance models, join us as we examine how organizations are separating meaningful risks from distractions, adapting their review processes, and preparing for what’s coming next. |
|---|
11:05 AM
Break
11:20 AM
WorkshopBeyond Checklists: Preparing for CPRA Audits in Practice
As deadlines loom to get your program ready for California’s cybersecurity audit requirements, compare your progress with fellow privacy leads. Linda Trickey, IHG Head of Privacy Legal, will facilitate an open conversation on assessing readiness, the role of privacy in the process, best practices in engaging key stakeholders and relevant systems, auditor considerations, and leveraging mechanisms like attorney/client privilege. |
WorkshopPrivacy by Design: Breaking the Reactive Cycle
Annie Nagel, Principal Privacy Program Manager for Strategy and Operations at Alaska Air Group, will facilitate this discussion on how our organizations are proactively embedding privacy by design into key business, technology, and AI workstreams. Drawing from recent enforcement trends, evolving regulatory guidance, and real-world program experiences, we’ll examine where privacy teams are successfully integrating into decision-making processes, what questions actually drive better outcomes, and how to ensure stakeholder engagement and privacy requirements provide value added services for our organizations. |
|---|
11:50 AM
Lunch Discussions
12:50 PM
Break
1:00 PM
Peer Advisory Roundtables Round 1
EXAMPLE TOPICS:
- Beyond Data Privacy Day: How to increase awareness year-round
- Addressing employee privacy concerns
- Vendor review: OneTrust
- PIAs: Evaluating your process
1:30 PM
Peer Advisory Roundtables Round 2
EXAMPLE TOPICS:
- Taking on AI accountability
- Data mapping: Building for long-term privacy success
- Assessing and managing data privacy risk in China
- WhatsApp, WeChat, etc: Weighing risk and opportunity
2:00 PM
Break
2:15 PM
Peer Advisory Roundtables Round 3
EXAMPLE TOPICS:
- Data privacy and DEI initiatives: Balancing progress with compliance
- Loyalty programs: Balancing privacy compliance and growth
- Data minimization strategy for privacy compliance
- Records retention: Best practices for big companies
2:45 PM
Adjourn
Please note: This agenda is subject to change based on speaker availability and scheduling.