Refacto

Podcast episode

The Permission Layer: Who Told the Al It Could Do That? Richy Glassberg on Data Privacy, Consent, and Al Innovation

compliance data-brokers dsp privacy ssp

Richy Glassberg, co-founder and CEO of SafeGuard Privacy, joined Signal & Noise hosts Brett House and Rio Longacre to argue that AI needs no new privacy laws and that advertisers are already legally responsible for every vendor in their supply chain, five tiers down. The episode's real news is buried in his bio: SafeGuard Privacy is the engine behind the IAB Diligence Platform, the first industry-standard system for vendor privacy attestation (think SOC 2, but for ad-tech compliance).

Glassberg's workflow pitch is the most credible part. If a vendor answers one questionnaire and shares the attestation across every buyer, that kills a genuine pain. Operators will adopt it for that reason alone. The liability argument is softer. Glassberg flags himself as "directional, not a lawyer," and a $130,000 fine against one data broker is not existential risk for a holdco. The CPM premium he promises for clean compliance is, as of now, theoretical.

Adopt it for the efficiency and the insurance. Don't believe the revenue upside until a buyer actually pays for it.

Full analysis

Richy Glassberg, co-founder and CEO of SafeGuard Privacy, went on Signal & Noise with hosts Brett House and Rio Longacre to make one argument: AI needs no new privacy laws, and advertisers are already on the hook for every vendor in their chain. The real news underneath is that SafeGuard Privacy is the white-label engine behind the IAB Diligence Platform, the first industry-standard system for vendor privacy attestation. That's the thing to weigh.

What's being decided: whether ad-tech operators treat standardized vendor diligence as a real obligation now, or keep running spreadsheets until a fine lands. Easy to undo if you're a buyer testing the platform. Hard to undo if you're a DSP, SSP, or data broker who gets cut from media plans for refusing to attest. No hard deadline, but California enforcement is the clock: Glassberg cites a $130,000 broker fine and the CPPA's non-negotiable statutory penalties ramping in 2025.


The Market Analyst. Follow the position. Glassberg is CEO of the company that powers the IAB's diligence platform, and every claim he makes on this episode raises the value of that platform. Spreadsheets are "moronic," regulators are hiring technologists, advertisers are liable five tiers down. All true-ish, all bullish for SafeGuard. Read it accordingly. The IAB white-label matters because industry-standard usually means default: whoever owns the questionnaire everyone answers once owns a toll booth. For an operator, the question is whether this becomes the SOC 2 of ad-tech privacy, a box you must check to be on a media plan. In plain terms: a compliance form is becoming a gatekeeper, and one vendor built the form.

The Skeptic. "AI needs no new laws" is convenient for a man selling compliance under existing laws. It might even be right. But the harder claim is the liability chain: that a brand is legally responsible when a fifth-tier data broker ignores an opt-out. Glassberg flags himself as "directional, not a lawyer," which is the caveat that should make you call your actual lawyer. The enforcement math is also soft. A $130,000 fine against one broker is not existential risk for a holdco. The $1.4 billion Texas-Google settlement is real, but Google is not the median SSP. The urgency is real; the size of the stick, as presented here, is not yet.

The Operator. Tuesday morning, this is a workflow change, not a philosophy. If the IAB platform lets a vendor answer once and share the attestation many times, that kills a genuine pain: answering hundreds of bespoke questionnaires. That's a real efficiency and operators will adopt it for that reason alone, regulation aside. What breaks at 90 days is the tagging layer Glassberg describes: marking each vendor compliant or non-compliant per client, because a bank and a candy company have different rules for the same DSP. That's a matrix someone has to maintain and defend. In plain terms: the form is easy, keeping the answers current across every client is the job.

The Customer / End User. Two customers here. The consumer, whose consent is broken: opt out on ESPN, re-enter the same identity graph via another publisher, and the opt-out never followed you. Glassberg is right that cookie banners are performative. But nothing on this platform fixes that for the consumer; it protects the advertiser from liability for the broken system. The CTV viewer seeing the same Bookings.com ad 10 to 13 times is the sympathetic version, and it's a real frequency failure worth 25 to 30 percent unsold inventory by his estimate. In plain terms: this helps brands prove they tried, not consumers get left alone.

The CFO. The cost isn't the platform license. It's the operating overhead of maintaining per-client compliance status across a live vendor list, plus the cost of cutting non-compliant partners who might be your best-performing supply. Glassberg's upside pitch is that clean, attested compliance becomes "a signifier of higher quality" that commands higher CPMs. Untested. No advertiser today pays a premium for a privacy attestation the way they pay for viewability. Payback is defensive: you're buying insurance against a fine and a plaintiff-bar lawsuit, priced against a $130,000 enforcement action, not a $1.4 billion one. The math works if enforcement scales. It doesn't if California stays at six-figure fines against brokers.


Where the council splits. The Market Analyst sees a toll booth forming and thinks operators should get on the platform early. The Skeptic says the liability case rests on a self-interested read of law from a man who isn't a lawyer, and the enforcement stick is smaller than the pitch. The CFO lands in between: adopt it for the workflow savings and the insurance, but don't believe the CPM-premium story until a buyer actually pays one.

The second tension is who this protects. The Operator and Market Analyst frame it as risk management for advertisers. The Customer view is blunt: the consumer's broken consent is the selling point, and the fix on offer shields the brand while leaving the person who clicked "accept all" exactly where they started.

What it hinges on. Two things. One, does California enforcement scale from six-figure broker fines to penalties large enough that a mid-tier SSP or holdco changes behavior? Two, does industry-standard attestation become a gate to being on a media plan? If both, the IAB platform is infrastructure and SafeGuard sits on the toll booth. If enforcement stalls, this stays a nice efficiency tool competing with spreadsheets that still technically work. The council leans toward adoption for the workflow reason regardless, and toward skepticism on the "existential risk" and "premium CPM" framing.

Prediction: The IAB Diligence Platform will still be the only broadly-adopted standardized vendor-privacy attestation in US ad-tech, with no competing industry standard from a rival trade body or major SSP, when the IAB reports on it at its Annual Leadership Meeting in early 2027.

Confidence: Medium. Standards win by being first and blessed, but adoption is slow and quiet.

Why: Industry-standard compliance forms become defaults because nobody wants to answer two of them, and the IAB got there first by convening 80 members and 10 law firms in 2023, giving it the neutral-body blessing a single vendor could never claim alone. Once vendors have answered the IAB questionnaire once, the switching cost to a rival standard is answering everything again, which is exactly the pain the platform was built to kill, so a competitor would have to overcome the same inertia the IAB already beat. The opposite outcome, a rival standard emerging, is unlikely because no other trade body has the cross-buy-and-sell-side membership to bless one, and a single SSP launching its own would just be another bespoke questionnaire nobody wants. What stays genuinely uncertain is depth of adoption, not whether an alternative appears.

Revisit by 2027-03-31: We're right if, by the IAB Annual Leadership Meeting in early 2027, no competing industry-wide vendor-privacy attestation standard has launched from another trade body or major platform and the IAB platform remains the referenced default. We're wrong if a rival standardized attestation gains real traction, or the IAB platform is quietly shelved for lack of use.

Comments