Skip to content

Commit e2d3fbe

Browse files
shrutibistamburi
andauthored
Update patterns/1-initial/transparent-catalog-privacy-controls-posture.md
Co-authored-by: Amburi Roy <amburi.roy@gmail.com>
1 parent 84353a1 commit e2d3fbe

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

patterns/1-initial/transparent-catalog-privacy-controls-posture.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ Separately, three teams in the same organization each independently build their
2323

2424
A privacy manager receives a customer security and privacy questionnaire ahead of a contract renewal. One section asks not just whether the product uses generative AI, but how: what it's used for, what data it touches, and what safeguards are in place. The privacy manager knows GenAI is used somewhere in the product, but not in what capacity, for which features, or on what data. What follows is several days of chasing the product manager and engineering team for answers before the questionnaire can be answered accurately. The customer is left waiting on a response that should have taken minutes, for information that already exists somewhere in the organization, just not anywhere the privacy manager could find it. This is the same visibility gap as the audit fire drill above, just triggered by an external customer question instead of an internal audit, and made worse because the missing information is about what's deployed at all, not only whether a known control is met.
2525

26-
# Context
26+
## Context
2727

2828
* The organization has many engineering teams building and operating services independently (a decentralized engineering model).
2929
* A central privacy (and/or legal, compliance) function exists and is accountable for defining regulatory and policy requirements, but is small relative to the number of engineering teams.

0 commit comments

Comments
 (0)