Privacy professionals today are navigating a more complex landscape than ever. Stricter enforcement, growing AI-related scrutiny, and the pressure to prove compliance to enterprise clients have raised the stakes for privacy programs at every level. In a recent TrustArc webinar, Chief Assurance Officer Noël Luke sat down with Jonas Kuhnle, Privacy Manager at DoubleVerify, to discuss how third-party certification helps organizations turn their internal privacy work into external proof of accountability.
The Pressures Facing Privacy Programs Today
The numbers tell a clear story: 72% of all GDPR fines issued in the regulation’s eight-year history came in the last three years alone. California’s CPPA has become an increasingly active enforcement body. And with 74% of data breaches traced back to third-party vendors, the stakes of supplier due diligence have never been higher.
For organizations that operate as both vendors and customers, which describes most companies, this creates pressure on two fronts. They must assess the compliance posture of the vendors they use while simultaneously proving their own to the clients and partners they serve.
“It’s usually those parts that are not public where the scrutiny may arise.”
Noël Luke, TrustArc Chief Assurance Officer
A strong privacy program requires rigorous internal processes, but those processes often can’t be shared directly. That’s where independent certification fills a critical gap.
AI Is Expanding the Scope of Privacy Work
Artificial intelligence has added a new dimension to this challenge. More than 300 AI-related regulations have been proposed globally, and 90% of organizations report that their privacy programs have expanded because of AI. Meanwhile, 60% of consumers say they’ve already lost trust in organizations over how those organizations use AI.
For privacy teams, AI is a double-edged development. On one hand, tools like large language models have made certain tasks faster and easier. On the other, they introduce new data processing activities, require new governance policies, and demand careful review of outputs before they’re relied upon.
DoubleVerify responded proactively. In April 2024, the company became the first organization to receive TrustArc’s Responsible AI Certification, a certification that required them to formalize internal AI governance policies and submit to external review. “We wanted to display to clients and potential clients that we actually use external accreditation for that,” Kuhnle explained. “Someone who reviews, someone who puts a seal to that promise.”
Certification as External Proof of What Can’t Be Shared
One of the core challenges privacy teams face is that much of their best work is invisible. Internal policies, data mapping documentation, and vendor review processes are all essential to a mature privacy program, but they can’t be handed over to a prospective client in a sales conversation.
Certification addresses this directly. When a third party like TrustArc reviews and validates a privacy program, the resulting certification seal becomes shareable evidence that the underlying work has been done and done well.
“Clients want to see some form of proof. A lot of internal processes you cannot share directly, and therefore verification comes into play.”
Jonas Kuhnle, DoubleVerify Privacy Manager
DoubleVerify now uses its certifications actively in the sales process. The company trains its sales teams on what each certification covers and what it signals to prospective clients. For a global ad verification company operating across markets in Europe, the US, and Asia, the portfolio of certifications (including APEC and Global CBPR for cross-border data transfers, CCPA validation, and the Data Privacy Framework Verification) gives sales teams region-specific credibility they can put in front of the right clients.
Building Executive Buy-In Through Demonstrated ROI
Getting leadership support for a certification program isn’t always automatic. Kuhnle’s approach at DoubleVerify has been straightforward: show the return on investment. When clients explicitly ask which certifications a vendor holds before moving forward, that’s concrete evidence that the spend pays off.
That executive buy-in, once established, creates its own momentum. “It also is super important when it comes to asking questions around the organization,” Kuhnle noted. When privacy requests carry visible C-suite backing, the rest of the business takes them seriously, which makes the annual audit process smoother and helps embed privacy thinking into product and technology decisions from the start.
Certifications Benefit the Whole Organization, Not Just the Privacy Team
The value of certification extends well beyond the privacy team itself. For legal and compliance, it helps create interoperable frameworks and reduce enforcement risk. For security and IT, it can surface gaps in existing controls. For marketing, it provides public-facing credibility that positions the company as a responsible data steward.
For DoubleVerify, the audit cadence also functions as a regular forcing function, a scheduled moment to review policies, check that data flows are documented accurately, and confirm that everything is current. “It always provides a moment in time when you review your processes,” Kuhnle said. “Of course, you review them regularly, but it’s another reminder.”
Staying Ahead in a Global, Always-Changing Landscape
For companies operating internationally, the challenge isn’t just the number of privacy laws, it’s the pace at which they evolve. US state privacy legislation continues to expand. The EU’s digital omnibus package and updates to the Data Act are adding new layers to an already complex European regulatory environment.
DoubleVerify manages this by combining strong team coverage, privacy expertise on both the European and US sides, with tools like TrustArc’s Nymity for regulatory tracking. Having a portfolio of certifications that spans frameworks and geographies means that when regulations shift, there’s already a documented baseline to work from.
“Only if you really know well what you’re doing, if you know your organization, if you know your structure, your data flows, you can adapt,” Kuhnle said. “The better you know your program, the better you can adapt to additional requirements.”
Whether you’re building a privacy program from the ground up or looking to demonstrate maturity to enterprise clients, TrustArc’s certification and assurance offerings give you independent validation that stands up to scrutiny in the sales cycle, with regulators, and across global markets.
Explore TrustArc Certifications