Last year I started working as a privacy engineer for a cybersecurity start up as it began building a privacy compliance product for the ad tech industry. I found myself navigating some complex ethical and legal tensions and trying to translate them into efficient business processing rules and control flows, with a compass that was constantly evolving. Our North Star has been that the further we stray from the consensus the less credibility we have as enforcers but where does that leave you when you’re building ahead of consensus or the consensus left out some major stakeholders? How do you protect consumer privacy while allowing your clients to keep operating effectively? How do you surface and attribute violations when there is no clear bad guy or your client may be the one at fault? And how do you distill laws and regulations into business processing rules and control flow logic?