Leaders in Privacy · 2026

Show Your Work: Privacy's Shift to Continuous Assurance

Privacy teams are covering more ground with less authority. Drawing on a recent Vault JS conversation with PwC's Jake Meek, this is the case for observing the surfaces that carry the most risk, rather than documenting your way to confidence.

18 mo
How fast privacy influence has eroded inside many organizations
36
US laws now touching children's online safety, with varying thresholds
49%
Of nine-year-olds have their own smartphone, rising to ~70% by 13
~20
Things most organizations actually do with data, once rolled up

Something uncomfortable has happened to privacy teams over the past 18 months. The list of things privacy is expected to cover keeps growing, while the authority to actually shape those things has moved in the opposite direction. Teams that spent years building toward a seat at the table are finding the table has more chairs and less room.

The instinct is to respond with more process: another assessment template, another intake form, another inventory refresh. That approach has limits. The programs that will hold up over the next few years are the ones that stop trying to document their way to confidence and start observing the surfaces that carry the most risk.

Key takeaways

The short version

01

Privacy's remit is expanding while its authority shrinks, and ownership of upstream data governance is the fault line.

02

Programs built on personal heroics do not scale. Volume is the thing that breaks them.

03

Regulators are moving from "do the work" to "show your work," which favors continuous assurance over point-in-time artifacts.

04

Digital tracking is the surface an outsider can scan without your cooperation, which makes it the pragmatic place to start.

05

The hard part is the operating model: who takes the ticket. Judgment stays human.

The remit expands while the influence contracts

Privacy today touches competition law out of Europe, content moderation, youth online safety, recommender systems and predictive analytics, and AI governance, all on top of the classic work of consent, data subject rights, and sensitive data management. Ownership of most of those topics is still unsettled, and each new discipline has quietly taken a piece of what privacy used to hold.

Data governance is the clearest illustration.

From the conversation

"It doesn't really matter to me how sophisticated your data deletion or data retention policy is. If you can't demonstrate your upstream data governance capability, your downstream consents are sort of weakened by that."

Many privacy functions have no ownership of that upstream capability at all. They inherit whatever it produces and are held accountable for the result.

Programs built on heroics do not scale

Walk into most privacy functions and you will find talented people wearing four hats each. One person handles assessments, vendor reviews, a regulatory tracker, and whatever lands in the inbox that morning. It works, right up until it does not.

"We need to start developing programs that are based more on systems rather than on personal heroics. A lot of the professionals I work with are burnt out, and the volume just keeps coming in."

Volume is the operative word. It is the thing that breaks heroics. No amount of individual capability closes a gap that grows every week.

Point-in-time artifacts are running out of road

A PIA captures a moment. So does a RoPA, and so does a data inventory. They describe a system as it was understood on the day someone wrote it down.

Use case drift has always undermined that. A team adds a feature, a new third party, or a new connector, and the change never comes back for a checkpoint. Anyone who has run an assessment program has watched it happen. Agentic AI compresses the timeline. When an agent can write code, spin up connectors, and touch personal data inside your environment over the course of a week-long experiment, the distance between what your documentation says and what your systems do widens faster than any review cadence can track.

The useful response already exists in the market next door. Organizations are actively buying AI observability to watch their high-risk models for adoption, cost, and behavior. The same posture applies directly to privacy: watch for use case drift, data usage drift, and third-party drift, continuously, after launch.

Regulators are asking you to show your work

This shift is not only operational. It is becoming a compliance expectation. CalPrivacy's high-risk assessment submissions, South Carolina's audit requirements around minors, and the audit components embedded in the DSA and DMA all point the same direction.

"It's no longer enough to just do the work. You have to show your work after something has been launched and put into production, with the idea that someone at the executive level is going to sign off on the validity of those results."

The risk underneath

In nearly every privacy consent order, the most severe issue is misrepresentation. Filing a high-risk assessment is making a formal representation about how your systems behave, and inviting a regulator to compare it against what is actually running.

You cannot watch everything, so choose by exposure

Enterprise-wide visibility sounds appealing and stays out of reach for most organizations, particularly with budgets under pressure. The practical move is to choose deliberately. A useful filter is velocity against complexity.

Where to point the camera Velocity (vertical) against complexity (horizontal) High velocity · Low complexity Audience insights, ad campaigns POINT THE CAMERA HERE High velocity · High complexity Digital tracking, data clean rooms, AI activation Low velocity · Low complexity Routine, low-change processing Low velocity · High complexity Workforce software rollout, a traditional PIA fits Complexity → Velocity ↑
Most organizations do roughly 20 things with data. The high velocity, high complexity corner is where continuous visibility earns its keep.

Digital tracking sits squarely in the high velocity, high complexity corner, and it carries one property nothing else does. It is the surface an outsider can examine without your cooperation.

Why trackers first

"We put digital trackers and website governance up here, not because it's causing the most financial pain, but because it is the most easily scannable by an external party. We have regulators, we have plaintiff's attorneys who can just see noncompliance, or perceive a possibility of noncompliance, through scans."

A regulator does not need to subpoena anything to form a view of your website. Neither does a plaintiff's firm building a CIPA case. Getting that surface observed saves the work of explaining it later, after a letter arrives or litigation starts.

What continuous visibility looks like in practice

For most teams today, tracker governance runs like this: a scan produces a dashboard, someone reads the dashboard, and then the real work starts. Answering each finding means emails, Slack pings, and trips to legal, contracting, marketing, and site owners, repeated every time. The orchestrated version routes scan results into a workflow that already holds the rules of the road, and answers the repeatable questions before a human sees them.

1

Origin

Do we know where this tracker came from, and is it categorized correctly?

2

Contract

Does contract language define what this vendor can and cannot do with the data?

3

Onward transfer

Is data moving on to somewhere it should not, and is this essential or marketing?

4

Behavior

Is it behaving in a way that introduces risk, up to and including malware?

Findings get scored, packaged by site, owner, or severity, and routed as tickets. An analyst opens a queue, sees fifteen items for the quarter, and finds a drafted email already prepared for the site owner. In the most mature version, a violating tracker is disabled automatically while remediation runs, and the risk scoring reaches well past cookie categorization into questions like CIPA exposure.

The operating model is the hard part

Tooling is the easier half of this. The harder question is the one that kept coming up.

The real question

"Who is going to take those tickets? Who is actually going to work this ticket as it comes in, provided that there's still human judgment that needs to be applied?"

Every adjacent discipline has already answered it. Security has a security operations center. Know Your Customer teams monitor accounts after onboarding. AI risk teams watch dashboards and act on alerts. Privacy has largely skipped this step, which is why the tooling conversation stalls so often. Digital tracking is a sensible place to build that muscle, precisely because the volume is survivable. Monthly and quarterly scan cycles produce a manageable pile, unlike a data clean room generating thousands of operations a day.

It also changes what privacy professionals spend their day on. AI's most valuable contribution here is removing the layer of abstraction the profession has worked through for a decade. It takes the PIA, the RoPA, the data flow diagram, and lets a person interact with and observe the source object directly.

Judgment is still the job

Ask what privacy headline a year from now will surprise everyone and should not, and the answer is a warning rather than a prediction: some company will let AI be the risk professional. An agent will connect something it should not have, or an assessment will sail through with a human signature and no human thought behind it.

That headline would be bad for the organization involved and worse for the argument the profession is making. The case for continuous visibility rests on freeing people from drudgery so their judgment lands where it matters. Automating the judgment itself gives up the whole point.

The direction of travel

Documentation describes intent. Observation establishes fact. Regulators are starting to ask for the second one.

From documented to demonstrable

Vault JS gives privacy teams continuous visibility into what is actually running on their digital properties, so the story you tell regulators matches the systems they can already see.

Watch the full conversation on demand