I think the point we disagree on is the idea that accountability by a singular department is an indication that it's sufficient for vendor to avoid regulatory action. in terms of privacy protections, the strategy should be defense in depth. I think about the audits that happen in health tech for eg on the software side, both at the request of regulatory agencies and their clients
any platform that enables people to be stalked, harassed, tracked, and so on should face the same level of scrutiny in the form of auditing and open access to internal policies around data sharing