Webinar Description
Key Takeaways
- Focuses on data subject request automation and deletion workflows for privacy compliance
- Addresses operational challenges of the DELETE Act (DROP) and broader state privacy regulations
- Relevant for privacy, compliance and engineering professionals managing consumer data infrastructure
- Features practitioners from ZoomInfo, Upwork and Transcend discussing scalable compliance architecture
Building Infrastructure for an Expanding Privacy Landscape
This live panel discussion examines the operational realities of managing data subject requests at scale, with particular attention to California’s Delete Request Options and Protections (DROP) regulation. The session is designed for privacy professionals, compliance teams and engineers responsible for building systems that can handle consumer data deletion and opt-out requests across complex data environments. As state-level privacy laws continue to proliferate across the United States, organisations face mounting pressure to move beyond policy documentation toward genuinely automated compliance infrastructure.
About This Event
Moderated by Adrian Fine, Head of Product Marketing at Transcend, the panel brings together practitioners with direct experience implementing privacy compliance systems. Taylor Dronen, Senior Manager of Privacy and Compliance Technology at ZoomInfo, joins Lindsey Steward, Director of Government and Regulatory Affairs at ZoomInfo, alongside Sloane Kirstyn, Associate Privacy Counsel at Upwork. The combination of technical, regulatory and legal perspectives offers a comprehensive view of how organisations are approaching these challenges in practice.
The Operational Challenge of Data Subject Requests
Each new state privacy regulation creates a familiar engineering problem: consumer requests arrive, and data pipelines must locate, delete or suppress information across every system where it resides. The difficulty lies not in understanding the legal requirement but in executing it reliably across fragmented data architectures. Modern organisations typically store consumer data across dozens of systems, from marketing platforms and customer relationship management tools to analytics databases and third-party integrations. Tracing a single individual’s data through this landscape and ensuring complete deletion requires sophisticated identity resolution capabilities.
The panel addresses why genuine automation, rather than documented policies, determines whether organisations can handle these requests at scale. Manual processes that suffice for occasional requests quickly become unsustainable when regulations like DROP generate concentrated volumes of deletion demands.
DROP as a Regulatory Preview
California’s DROP regulation represents more than a single compliance deadline. It signals the direction of consumer data protection across jurisdictions. Organisations that build robust deletion and opt-out infrastructure now position themselves to handle subsequent regulations without rebuilding their systems for each new law. The session explores how investment in scalable compliance architecture creates compounding returns as the regulatory environment continues to evolve.
Who Should Attend
This discussion is particularly relevant for privacy and compliance professionals responsible for data subject request programmes, engineers building or maintaining data deletion pipelines, and legal counsel advising on privacy regulation implementation. Organisations processing significant volumes of consumer data, especially those operating across multiple US states, will find practical insights into operationalising compliance requirements that extend well beyond any single regulation.

