Apple •Spotify• Pocket Casts •Youtube •Overcast •RSS

What’s up everyone, today we have the pleasure of sitting down with Cara Caruso, CEO and co-founder of Sentinel Insights, and Dustin Taylor, counsel at Troutman Pepper Locke.
Summary: A privacy-software CEO and a litigation defense attorney scare every marketer in the room, in the most useful way possible. Cara Caruso has scanned over 10,000 websites and found nearly 90% of them non-compliant, while Dustin Taylor has defended more than 100 companies against the exact lawsuits that follow. Together they trace how a forgotten tag from 3 years ago becomes a seven-figure settlement, why your own privacy policy is the document most likely to get you in trouble, and why clean, consented data actually performs better. Stick around for the part where your email open rates might be illegal and the FTC makes companies delete 4 years of data.
In this Episode…
- Why Your Website Is Running More Tracking Tools Than You Know
- How Privacy Lawsuits Start With a Website Scan
- How Privacy Policy Mistakes Trigger ECPA Lawsuits
- What Consent Drift Actually Looks Like
- Who Actually Owns Privacy Compliance
- How Consented Data Improves Marketing Performance
- What Marketing Ops Can Do About Privacy This Week
- Why Email Marketing Is the Next Privacy Lawsuit
- Why AI Models Built on Bad Data Get Deleted
- Why Small Companies Get Privacy Lawsuits Too
Recommended Martech Tools and Agencies 🛠️
We only partner with products and agencies that are chosen and vetted by us. If you’re interested in partnering, reach out here.
📧 MoEngage: Customer engagement platform that executes cross-channel campaigns and automates personalized experiences based on behavior.
🎨 Knak: Go from idea to on-brand email and landing pages in minutes, using AI where it actually matters.
🔄 GrowthLoop: The agentic, composable CDP that drives compound growth by uniting your cloud data + AI into one marketing engine.
🦣 Mammoth Growth: Customer data agency that turns fragmented data into a unified foundation, unlocking sharper marketing insights and action.
About Cara and Dustin

Cara Caruso is the CEO and co-founder of Sentinel Insights, where she leads a platform that monitors websites in real time for consent violations and privacy exposure. Before starting the company she spent more than 25 years in data and martech, building and scaling teams across technology and financial services in both B2B and B2C. She pairs strategic planning with hands-on execution, and she’s also a certified yoga instructor who has been known to bring a workshop into the office.
Dustin Taylor is counsel at Troutman Pepper Locke, where he defends companies at the intersection of privacy law and marketing technology. He’s defended more than 100 companies in ad-tech privacy cases involving cookies, pixels, session replay, and website chat, secured dismissals at the pleading stage in federal court, and argued in California, New York, Florida, Texas, and New Jersey. He started out with an advertising degree before law school, which makes him fluent in the martech stack in a way most litigators never are. He also publishes monthly privacy litigation reports and tracks ECPA filings with AI.
Why Your Website Is Running More Tracking Tools Than You Know

Most marketing teams believe they have a clean inventory of what runs on their website. There’s a tag manager, a cookie banner, a vendor list in a spreadsheet somewhere, and a general sense that someone signed off on all of it. Then someone actually scans the site, and the number comes back 2, 3, sometimes 4 times higher than anyone expected.
Cara has watched this play out thousands of times. Sentinel Insights has scanned over 10,000 websites in the past year, and the pattern barely changes from one company to the next. Nearly 90% of those sites are not compliant. Every new customer gets the same uncomfortable conversation on day one.
“We haven’t had a new customer come on board yet where we’re not like, ‘Hey, we found some extra stuff on your site that you weren’t prepared for.'”
The gap between what a team thinks is running and what’s actually firing comes from 2 places. The first is history. Somebody 3 years ago added a tag for a campaign that ended, then left the company, and nobody ever took it down. The team you have today inherited a stack built by people they never met, and most of those decisions were never written down anywhere. Cara calls it the ghost of marketers past, and it’s sitting on almost every site she scans.
The second is piggybacking. You buy one tool, drop in one script, and that single tag quietly loads 4 more. Each of those can load more on top. An agency hard-codes a pixel straight into a landing page because they didn’t have access to the tag manager, and now your customer data flows to companies nobody on your team could name. None of it shows up in the tidy spreadsheet. All of it shows up in a scan.
This is the part most marketers underestimate. The real exposure comes from the tools nobody chose on purpose, the dozen scripts running quietly in the background, each one sending customer data somewhere you’ve never audited. They pile up while everyone assumes the banner has it covered. No marketing team actually knows what’s on its website until a scan proves otherwise, and “we reviewed it last year” is closer to a guess than a control.
Why Forgetting a Tag Still Makes You Liable
The instinct, once you find those orphaned tags, is to assume they don’t count against you. You didn’t install them. You didn’t even know they were there. Dustin spends a lot of his time correcting that assumption. These privacy laws do have a knowledge component, but courts read knowledge very differently than a normal person would. As long as the person who installed the tag 3 years ago knew they were installing something, the legal requirement is met. The fact that today’s marketing team forgot it existed changes nothing.
“Somebody along that chain knew. You didn’t accidentally install something altogether. You just kinda forgot about it, and that’s not gonna get you out of the problem.”
There’s a second trap hiding inside the same problem. What marketing knew, what IT knew, and what legal knew are rarely the same thing, and that fragmentation is its own risk. Each group assumes another group is watching the stack. The court doesn’t care which department dropped the ball. It only cares that someone, at some point, hit install.
Key takeaway: Run a full scan of your live website this month and compare the results against your documented vendor list. Flag every tag you can’t immediately explain, especially anything loading third-party scripts you never installed directly. The tools you can’t account for are the ones quietly building your legal exposure, and forgetting they exist won’t protect you.
Back to the top ⬆️
How Privacy Lawsuits Start With a Website Scan

Here’s the mental model most marketing teams carry around: we’re compliant until someone complains. You picture a single annoyed customer who takes the time to file something against your little startup, and you quietly decide the odds are low. Who’s really going to sue over one text message or one tracking cookie? That assumption is the most expensive thing on your website, because litigation in this space doesn’t start with a complaint. It starts with a scan of your site that you never see.
Plaintiffs’ law firms run continuous automated audits of company websites, and they’re looking for far more than a typo in your privacy policy. Dustin walked through exactly what their scanners check:
- What loads automatically the moment someone lands on the page, before any consent is given
- Whether there’s a banner at all, and what it actually does
- What keeps firing after a visitor opts out
- Whether anything is miscategorized, like a marketing cookie quietly labeled “essential” so it can’t be turned off
“Marketing is essential to our business, therefore it’s an essential cookie and you can’t get rid of it. That logic makes sense, and it did then. But then you’re getting a demand letter saying you owe tens of thousands of dollars.”
Once a firm finds the exposure, they find a plaintiff. The demand letter arrives, and the dollar amounts climb fast. Cara breaks the pressure into 3 forces bearing down on marketing teams at once:
- Trophy-hunting plaintiff attorneys who come after you for small amounts individually, then scale it into a class action
- Brand and reputational damage that lingers long after a settlement clears
- State enforcement at the attorney general level, where Gartner pegged fines at 3.5 billion dollars last year and expects the trend to keep climbing
And those public numbers only show the surface. Dustin describes the settlements as an iceberg. The class actions you read about are the seven-figure tip, the ones that start at a million or 2 or 5. Underneath sit the private settlements nobody reports, tens of thousands of dollars at a time, sometimes climbing into 6 figures, often triggered by nothing more than a letter that never becomes a lawsuit.
The companies getting hit aren’t reckless. Kaiser Permanente paid 46 million dollars over a tracking pixel. Duke Health paid 3.7 million. These are sophisticated organizations running the same tools your marketing ops team runs right now. Dustin’s defended count went from 45 companies to more than 100 in the time he and Cara have been talking, and his first words to almost every new client are the same: you’ve done nothing wrong. They were focused on complying with rules like the CCPA, which doesn’t even require opt-in consent, and then a letter shows up accusing them of violating someone’s privacy. The first job on every call is untangling that confusion. The second is the audit, correct, and track loop Dustin builds every engagement around, and step one is always the same question Cara opens with: what’s actually on your website?
Websites aren’t set it and forget it. Cara’s marketing ops customers push site updates every 2 weeks, and every push is a chance for something to slip. Layer on the legal patchwork Dustin navigates, 20 states with privacy laws today and 22 soon, plus federal rules like the VPPA for video, HIPAA for health data, and separate regimes for children’s data, and the picture gets worse fast. Add children’s data to a small violation and the fines multiply. No wonder marketing ops teams struggle to feel safe when the same site can break the law in a dozen different ways.
Key takeaway: Open your own website in an incognito window, reject all cookies, and watch what still fires in your browser’s network tab. That’s the exact view a plaintiff’s scanner gets before they ever contact you. Anything tracking after a rejection is the gap that turns into a demand letter.
Back to the top ⬆️
How Privacy Policy Mistakes Trigger ECPA Lawsuits

There’s a new category of lawsuit aimed squarely at the gap between what your privacy policy promises and what your website actually does, and it’s growing at a rate that should worry anyone who owns a martech stack. Dustin and his team read nearly 200 of these complaints and sorted them by the specific thing each one claimed a company did wrong. The results map almost perfectly onto things a marketing team would never flag as a problem.
From September 2025 through March 2026, plaintiffs filed 197 lawsuits alleging violations of the Electronic Communications Privacy Act, the federal wiretapping statute. Depending on the month, that’s 2 to 4 times the volume of the same period a year earlier. The reason the ECPA matters so much is the math attached to it.
“Say your banner wasn’t working properly for just one month. How many people interacted with it? Multiply that by 10,000, and suddenly these seven-figure settlements start to make a little more sense.”
That 10,000 dollars is statutory damages per class member, which is what gives these cases their teeth. Now look at how the 197 lawsuits break down. 112 of them alleged the website misrepresented something to consumers. Of those, 80 claimed the privacy policy itself stated something false, and the example Dustin gives is one almost every company is exposed to: the policy promises you “only share aggregate data,” while a pixel on the same site quietly sends identifiable information to a third party. Another 41 said the consent mechanism was broken, so a visitor who opted out kept getting tracked anyway.
If you add 80 and 41, you get more than 112, and Dustin is the first to point out the math doesn’t balance. Plenty of these lawsuits allege both problems at once, then use the misrepresentation to unlock the federal ECPA claim and its statutory damages. That’s the engine. A false sentence in your policy plus a tracking tool that contradicts it equals a federal case, and the per-person multiplier turns one month of a broken banner into a settlement that ends careers.
The uncomfortable truth for marketers is that the document doing the damage is one most of them have never read closely. Legal wrote the privacy policy years ago. Marketing built the tracking. The 2 have been drifting apart ever since, and plaintiffs are paid to find the daylight between them.
Key takeaway: Read your privacy policy line by line against what your site actually does this week. Hunt for any sentence that promises you “only share aggregate data” or “don’t collect identifiable information” while a pixel does exactly the opposite. One false sentence paired with one contradicting tag is the entire case against you.
Back to the top ⬆️
What Consent Drift Actually Looks Like

A site can be fully compliant in January and quietly illegal by June without a single person doing anything wrong. That slow slide has a name. Cara calls it consent drift, and it’s the part of this whole conversation that hits marketing ops hardest, because the damage comes from ordinary systems doing exactly what they were built to do.
The drift usually starts with a false sense of completion. A team installs a consent management platform, the cookie banner pops up on the homepage, and everyone moves on. They believe the job is finished. Then the demand letter arrives. Cara is careful to say this isn’t a knock on the platforms themselves, because there are plenty of good ones. The problem is how they get implemented and then ignored. A consent platform has to be managed and maintained like any other piece of enterprise software, and instead it gets treated like a light switch.
“That consent drift, it really happens so quickly. It can happen in a matter of one website change, or one sprint, or one tag.”
At a minimum, Cara wants teams running monthly data governance reviews: looking at what’s actually firing on the site, vetting every new vendor before it goes live, and reading the contracts that come with them. Her platform sits in the middle of that loop, flagging the pixels still firing for people who already opted out. And she adds a line that should stop any marketer cold. Even with consent, you should never be sharing PII or PHI, the birthday and medical details a visitor pre-fills before booking a doctor’s appointment. Consent to be marketed to is not consent to leak someone’s health history.
This is also the exact seam where the org chart fails. Legal knows it’s an issue. IT might know it’s an issue. But the person who actually controls the website and every tool on it is marketing, which means the fix almost always lands back on the team that didn’t realize anything broke.
The Failures That Surprise Marketers Most
When Cara sits down with a marketing team and shows them what’s really happening, the same 3 discoveries land hardest every time:
- Tags on the site they never expected to be there, with no record of who added them or why
- Piggyback tags, where one tool loaded another, which loaded another, sending their data to companies they can’t even name
- Outside agencies throwing up landing pages that ignore the brand’s own rules, leaving the in-house team to clean up errors they didn’t know were happening
The thread running through all 3 is silence. None of it announces itself. The data just starts going places it shouldn’t, and the first signal often arrives in the form of a letter from someone you’ve never heard of.
Key takeaway: Put a monthly data governance review on the calendar and treat your consent platform like production software, not a one-time install. Re-scan after every site change or sprint, confirm no pixels fire for users who opted out, and verify you’re never passing PII or PHI even to consented tools.
Back to the top ⬆️
Who Actually Owns Privacy Compliance

Ask 3 departments who owns website privacy and you’ll get 3 confident answers that all point at someone else. Marketing assumes it’s a legal problem because of all the jargon. Legal assumes IT handles the technical side. IT assumes marketing owns the tools it installed. The issue lands in the gap between them, and the gap is exactly where the lawsuits grow.
Dustin can’t tell you who owns it in theory, but he knows precisely whose desk it hits in practice.
“I can tell you whose desk it lands on by the time it comes to us, and that answer is legal.”
By then it’s already a lawsuit. Dustin wonders aloud how many companies get these letters and simply ignore them, or get sued because they had no legal team and no outside counsel to call. The deeper split he sees is this: a lot of companies know how they use their own data, but not what that data is sending to others or how those others use it. Compliance teams focus on the first half. Litigation lives in the second.
Cara’s read matches his. The problem ends up on legal’s desk or a privacy officer’s, and those people pull IT and marketing into a room for what she calls an attempt at kumbaya. What follows is finger-pointing and alphabet soup, with every function using different language for the same things. You almost need an interpreter. Her point is that the rare people who can actually translate are worth everything. Dustin is a litigator who came up with an advertising degree, which makes him fluent in martech in a way most lawyers never are, and Cara has spent nearly 30 years in data and martech. The conversation only works because both of them learned to speak the other side’s language.
Phil’s seen the in-house version of this translation work, and it’s tedious but it functions. Build a spreadsheet with a column for every tool, a column explaining to legal and IT why marketing needs it and what it does, and a column for what the business would lose if IT cut it tomorrow. The reason teams skip this work is that it doesn’t drive revenue on paper, so it loses every prioritization fight until a demand letter reorders the list. The fix is a two-way street. Marketers need to learn the compliance side, and legal teams need to understand how fast these martech tools actually change.
Key takeaway: Build one shared inventory that lists every tool, why marketing uses it, what data it sends out, and what breaks if it’s removed. Give a single named person accountability for keeping it current, because a committee with shared ownership is how these issues fall through the cracks in the first place.
Back to the top ⬆️
How Consented Data Improves Marketing Performance

Every argument so far has run on fear, and fear only carries a project so far before someone in the room asks what the company actually gains. That’s the more interesting case, and it’s the one that gets marketing to stop treating consent like a tax. The moment a consent banner gets proposed, the reflex is panic about lost revenue. Dustin hears it on nearly every engagement, and it’s the exact point where he hands the conversation to Cara.
“She can tell you the difference between improving the quality of your leads even if the quantity goes down.”
Cara reframes the whole thing around clean and consented data. The goal is to collect the right data fast and make sure it’s usable. She tells the story every marketing ops person feels in their gut. You launch a 3 million dollar product campaign, and 2 weeks in the CMO asks where the numbers are. But you forgot to tag the key pages, your UTM parameters are missing, and your honest answer is “I don’t know, we’ll try to attribute some of it after the fact.” That data is gone, and that loss was completely preventable. Those missing tags are what actually cost you the attribution, while a handful of people declining cookies barely moves the number.
So the work becomes a trade. You accept that maybe 20% of users in privacy-aware states will decline tracking, and you offset it by capturing far cleaner data everywhere else. Suddenly the conversation shifts to things marketers genuinely want. Your commerce and analytics numbers finally match. You stop double-counting page views and realize you’ve been overspending on Facebook when LinkedIn was the better bet all along. Fix enough of that, and consent stops feeling like a cost.
The numbers back the felt experience. Cara points to a Cisco privacy benchmark study from early 2026 that surveyed thousands of people worldwide:
- 99% of companies report measurable benefits from privacy investments
- 96% say strong data controls make them more agile and innovative
- 95% see increased trust and loyalty as a result of their privacy programs
Cara’s favorite payoff is speed. Nothing makes a marketer happier than shipping a campaign, and a real privacy program means you clear legal in days instead of stalling for 6 to 8 weeks in review. Dustin adds the part that the data only gestures at. Companies want to do right by their customers, and treating people’s privacy with respect resonates with almost everyone he works with, long before anyone runs the ROI.
Key takeaway: Reframe consent internally as a data-quality program instead of a compliance tax. Measure lead quality and attribution accuracy before and after you clean up your tags, then bring those numbers to the CMO to show that consented data performs even when raw volume dips.
Back to the top ⬆️
What Marketing Ops Can Do About Privacy This Week

All of this only matters if you can do something with it on Monday. Not a six-month program, not a steering committee, just the first real move. Cara’s answer starts with people, then gets technical fast.
- Stand up a cross-functional data governance council so ownership and accountability live somewhere specific, then open it with a simple prompt: here’s what we’re hearing, here are the multi-million dollar settlements competitors are eating, what’s happening around us?
- Take a hard look at your live website. Run one of the free scanners that plenty of companies offer, hers included, and check whether you’re even honoring consent at a basic level.
- Run a few manual scenarios with your own browser controls. Click reject, then watch whether the site actually does what the banner promised.
Cara’s reasoning for starting at the website is blunt. Regulators and state attorneys general told her directly at conferences that the website is the door opener. If they land on your site and find a privacy policy 3 years out of date, cookies that aren’t enforced, and basics that go unhonored, that’s their invitation to look at everything behind it, every vendor contract included. A small front-door problem becomes a full investigation, and the bill grows accordingly.
Dustin’s first step is shorter: call Cara. Then comes the audit, the A in his audit, correct, and track program. Figure out what’s actually running, what marketing knows, what legal knows, what IT knows, what the vendor contracts say, and when the privacy policy was last touched. He’s quick to puncture one defense marketers love to lean on, the idea that everyone in the industry does it this way.
“They were doing it too is not a defense. Now you’re both in trouble.”
Industry standard practice carries real weight in a boardroom, where executives genuinely weigh how competitors obtain consent and set their own risk appetite against it. In a courtroom it counts for nothing. Dustin frames his actual job with a driving analogy. He can’t tell you to avoid lawsuits by deleting your website and selling nothing, the same way he can’t tell you to avoid car accidents by never leaving the house. Both work and neither is realistic. What he can do is help you spot the riskier roads and stay off them, like not driving at 2 a.m. when the bars empty out, while the rest of the business keeps moving.
And if none of that moves the priority list, Cara points to a force that will: your own insurance company. Large corporations carry cyber insurance, and those carriers now run scans on their customers’ sites. When they find issues, the ultimatum is fast and specific.
“You have 60 days to remediate, or if you get a lawsuit, we’re excluding this from your policy.”
That single sentence rewrites a CISO’s math overnight. The executive who shrugged off privacy because they had 5 or 10 million in coverage suddenly has none, and the marketing ops team gets the call to fix it in 60 days or less. It’s a wild west, and the deadlines are now coming from places nobody was watching.
Key takeaway: Schedule a 30-minute cross-functional kickoff this week and run a free consent scanner on your homepage before it. Walk in with the one question that starts everything: when a visitor clicks reject all, does anything keep firing? If the answer is yes or unknown, you’ve found your first project.
Back to the top ⬆️
Why Email Marketing Is the Next Privacy Lawsuit

Email marketers have spent years thinking compliance meant CAN-SPAM, an unsubscribe link, and a working preference center. That floor just moved. Washington’s Commercial Electronic Mail Act puts statutory damages at 500 dollars per email, and it turns your subject lines into a class action trigger. Most email teams have no idea this exists, and it’s already spreading to California.
What makes this a marketing problem rather than a legal footnote is how the claim gets proven. These cases ask 2 questions: was the email deceptive, and did you send it to someone you knew lived in that state? Your own martech answers the second one for the plaintiff.
“You knew this was somebody in Washington, you knew this was somebody in California because your tools told you that. Now all we have to do is prove it was deceptive.”
The tracking you built to personalize and segment is the same tracking that establishes you knew exactly where the recipient lived. Plaintiffs use your stack to satisfy half their legal test before they even open the email. A subject line that says “sale ends tonight” followed by an “EXTENDED” send is the kind of thing that now carries a price tag.
Cara adds a second front that should rattle anyone who lives by open and click rates. France’s data authority, CNIL, issued guidance that tracking email opens or click-throughs now requires prior consent. So you blast a webinar invite, celebrate a 46% open rate and a 35% click-through rate, and that engagement data may have been gathered illegally. The fundamentals email marketers grew up on are under real pressure, and there’s a live chance this guidance spreads across Europe.
Dustin explains why watching Europe matters even from a US seat. Defense counsel tracks what the European regulators do, which means plaintiffs’ counsel does too, because being first to a new theory is everything in this game. The first firm to land a novel claim gets the big litigation before insurance carriers react and before a dozen copycat firms pile in. That’s why these emerging trends are worth fixing now, while they’re still a quiet signal and not yet the thing everyone is suddenly dealing with.
Key takeaway: Audit your email program for 2 risks now. First, flag deceptive-looking subject lines, the “ends tonight” then “EXTENDED” pattern, especially for recipients in Washington and California. Second, map which tools record geographic and engagement data, then review your open and click tracking on EU contacts against consent.
Back to the top ⬆️
Why AI Models Built on Bad Data Get Deleted

Every marketing team is racing to point AI at their customer data, and most of them have never asked whether they’re allowed to. Cara’s first move is to strip the hype off the word. What we now call AI personalization is the same concept the industry called personalization tools years ago, just with newer language wrapped around it. The mechanics changed less than the marketing did. What’s genuinely new is the size of the downside.
“If you’re building an AI model on data that is not clean and consented, you could absolutely be told you have to throw away the model and throw away your data.”
That’s the part that turns a compliance abstraction into a panic. As part of these settlements, you don’t just pay a fine. One of the FTC’s favorite remedies is to make you delete everything. Cara points to Vizio, which got caught tracking what everyone watched on their TVs and was ordered to destroy years of collected data. You misused it, you weren’t allowed to gather it, so you don’t get to keep it. Imagine a regulator telling your team to delete 4 years of marketing data built on the wrong foundation. Cara doesn’t pretend to be cool about it. It makes her heart palpitate, and she jokes she’d be the one crying in the corner with a blanket.
The defense against that nightmare is unglamorous data hygiene. Trace every pipeline back to where the data entered. Do you have consent from the website, consent to email them, and consent for what happens once they become a customer? You need that proof across every channel before you pour it into a customer data platform and start training models on top of it. The model is only as clean as the consent underneath it.
Dustin closes the loop with the piece non-lawyers tend to miss. Enforcement isn’t only retroactive. With an FTC consent judgment, you throw away the past 4 years of data and then report to the agency for the next 5. That forward-looking leash is what separates enforcement from ordinary litigation, where the outcome is usually money and a few minor promises to change. State attorneys general operate the same way. Once one of these enforcement bodies has you, you’re showing them everything for 2 to 5 years.
Key takeaway: Before you train any model or feed a CDP, trace each data source back to a consent record across web, email, and customer channels. Any data you can’t prove consent for is a liability a regulator can make you delete, the trained model included, plus years of mandatory reporting after.
Back to the top ⬆️
Why Small Companies Get Privacy Lawsuits Too

There’s a comforting story small companies tell themselves: this is an enterprise problem. At a big company you get a full IT team, in-house legal, and compliance that people take seriously. At a 200-person shop you get outsourced counsel, maybe one IT person, and a marketing ops team juggling 700 things while privacy floats around unowned. So the SMB marketer hears all this, glances at their three-year-old banner, and decides they’re too small to matter. Cara and Dustin spend this stretch of the conversation dismantling that.
The first crack is the threshold math. Every state sets its own revenue bar for whether its privacy law applies, and several of those bars sit lower than people expect. Some rules ignore size entirely. HIPAA applies across all 50 states no matter how small you are. And revenue is only one test. California also looks at whether you buy, sell, or share the personal data of 100,000 or more residents, so the company that proudly says “we don’t clear 26 million in revenue” still has to answer the second question.
“I have companies come in below six figures who’ve gotten one of these letters. They want $15,000, and we make $20,000 of revenue a month.”
That’s the part Dustin finds genuinely heartbreaking. We’re not talking about 200-employee companies here. We’re talking mom-and-pop shops, the couple doing camper van conversions out of a garage. The reason they get hit is supply. There are now so many plaintiff attorneys working this space that they’ve stopped reserving their letters for big targets and started sending them out by the truckload. Getting ahead of consent stops being an enterprise luxury and becomes survival for a small business that can’t absorb a 15,000 dollar demand.
Cara’s answer for lean teams is to stop trying to staff it internally. You can outsource the whole thing as a managed service, where a partner runs the monthly governance cadence, handles the legal input, uses the tools, and does the remediation each month. Her company is a software platform rather than a services shop, but it works with partners who put hands on keyboards so a small team doesn’t have to. The one thing she won’t let anyone off the hook for is the excuse itself. Saying “I didn’t know” still isn’t good enough.
Key takeaway: Don’t assume a revenue floor protects you. Check the specific thresholds in every state where your customers live, confirm whether HIPAA or other federal rules apply regardless of your size, and if you’re running lean, outsource consent monitoring as a monthly managed service instead of leaving it unowned.
Back to the top ⬆️
How to Decide What Deserves Your Energy

The question we put to every guest is how they decide what deserves their energy, and whether they have a system for staying close to what actually makes them happy. Cara runs a company, teaches yoga on the side, and shows up as the fun aunt, so she’s had to get honest about it. For her it all comes down to time, the one resource she can’t make more of. So she thinks hard about where it goes, and whatever she’s doing, she’s all in. When work excites her, she throws herself at it. When it’s time to take her nieces and nephews to the pool, she’s the one jumping in the water.
The story she tells to make it land is about her brother. He was running his first company, raising a one-year-old, and still mowing his own lawn every Saturday, stressed out by the weeds and the pool and the whole list. She asked him a question that reframed it. You’re running a company and doing well, so why not hire a landscaper? What matters more on a Saturday morning, making your kid pancakes and throwing a ball around, or rushing out the door to cut the grass? The point isn’t the lawn. The point is noticing which hours you’re spending on autopilot and reclaiming the ones that count.
Dustin lands in nearly the same place by a different route. He describes himself as a deeply segmented person. When he’s at work, he’s at work, down to the six-minute increments attorneys famously bill in, where every tenth of an hour matters. When he’s home, he’s on the floor playing with his kid or on a road trip with his wife and the dog in the back. He refuses to blur the 2.
“I don’t want my kid to remember me being on my phone reading work emails when I’m supposed to be playing with him.”
He keeps himself honest with a Brick, an NFC device you physically tap to unlock your phone. His family parked it in the most annoying spot in the house, up high on something with a magnet, so getting to Reddit during work hours means actually walking over and tapping it. The friction is the feature. It’s a small physical wall that protects the boundary his willpower alone wouldn’t.
Key takeaway: Pick the one chore on your weekend list that steals time from what actually matters and outsource it this month. Then protect your focus with a hard boundary between work and home, even something as simple as a device that keeps your phone physically out of reach during the hours you want to be present.
Back to the top ⬆️
Books Worth Reading
We always close by asking what people are reading, and this pairing produced a fun split between escape and craft. Dustin owns the fiction side without apology. He won’t pretend he’s deep in Tolstoy, because his actual nonfiction read is the IAPP CIPP US certification book, which is exactly as thrilling as it sounds for a privacy lawyer.
“Reading is my escape. I read every single day.”
In the past year he’s gone through Brandon Sanderson’s entire Cosmere, somewhere north of 20 books, and he’s now rereading the Red Rising series. His pitch to the nerdier martech crowd is that both are worth your time. If your brain runs hot all day on litigation and consent law, a sprawling fantasy universe is a pretty good place to put it down.
Cara takes the nonfiction lane and brings the one with staying power. Years ago a longtime collaborator named Ben Rabner, who she met back at Adobe over a decade ago, handed her Orbiting the Giant Hairball: A Corporate Fool’s Guide to Surviving with Grace. The premise stuck with her. Inside any big company, the gravity of mundane everyday tasks pulls you toward the center of the hairball, where creativity goes to die. The skill is learning to orbit it, staying close enough to do your job but far enough out to keep doing the work that actually matters. She passes the book around to the leaders she mentors, which is about the highest recommendation a book can get.
Key takeaway: Add Orbiting the Giant Hairball to your list if corporate busywork is dulling your creative edge, and keep a real fiction habit for the mental reset, whether that’s the Red Rising series or Sanderson’s Cosmere. Reading every day is the cheap, repeatable way both of them stay sharp.
Back to the top ⬆️
Episode Recap

Cara Caruso and Dustin Taylor make one central argument across this episode: website privacy has become a marketing ops problem, and most teams are dangerously behind on it. The lawsuits driving this don’t start with an angry customer. They start with an automated scan run by a plaintiff’s firm, looking for the gap between what your privacy policy promises and what your tags actually do. Close that gap and most of the risk goes away. Ignore it, and a forgotten pixel becomes a federal case with 10,000 dollars in statutory damages per person.
The tactical thread holding the conversation together is Dustin’s audit, correct, and track loop, and Cara’s insistence that a consent platform is production software that needs monthly governance. Find everything running on your site, fix the contradictions between your policy and your stack, then watch the site continuously because a single sprint or a single agency landing page can break compliance overnight. The work isn’t glamorous and it rarely shows up as revenue on a roadmap, which is exactly why it loses every prioritization fight until a demand letter or an insurance ultimatum reorders the list.
The bigger picture is that the blast radius is expanding in every direction at once. Email subject lines are becoming class action triggers under laws like Washington’s CEMA, France’s CNIL is treating email open tracking as something that needs prior consent, and the FTC can force a company to delete years of data and the AI models trained on it. None of this is limited to enterprises. Revenue thresholds are lower than most founders assume, some rules like HIPAA apply at any size, and there are now enough plaintiff attorneys mailing demand letters that mom-and-pop shops are getting caught too.
The honest tension both guests sit with is ownership. Nobody clearly owns this problem inside most companies, which is precisely why it festers, and “everyone else in our industry does it this way” carries weight in a boardroom but means nothing in court. Dustin’s parting move is the cheapest fix in the whole episode. His firm recently emailed clients to delete the line in their privacy policy that says “we respect your privacy,” because plaintiffs are using that warm language as evidence. Small corrections, made now, are worth far more than a perfect plan you never start.
Follow Cara Caruso and Sentinel Insights for real-time consent monitoring, and find Dustin Taylor on LinkedIn, where he publishes his monthly privacy litigation reports tracking the ECPA filing wave.
Full episode ⬇️ or Back to the top ⬆️

✌️
—
Intro music by Wowa via Unminus
Cover art created with Midjourney (check out how)
Apple •Spotify• Pocket Casts •Youtube •Overcast •RSS
Related tags
<< Previous episode
Next episode >>
All categories
- AI (105)
- career (65)
- customer data (65)
- email (64)
- guest episode (178)
- operations (127)
- people skills (34)
- productivity (10)
- seo (6)
See all episodes
Future-proofing the humans behind the tech
Apple •Pocket Casts•Google •Overcast •Spotify •Breaker •Castro •RSS