Get Started
How Ancestry Scaled Privacy Reviews from Hours to Minutes
Privacy·

December 2, 2024

How Ancestry Scaled Privacy Reviews From Hours to Minutes

Share

When you're managing 10,000 terabytes of sensitive customer data across 30+ countries, privacy can't be an afterthought. Just ask Steve Stalder, senior privacy operations manager at Ancestry, who faced the challenge of scaling privacy reviews while maintaining the trust of over 3 million subscribers.

"Trust is actually one of our top pillars here at Ancestry," Stalder told TerraTrue. "Without that, we're not going to have many customers relying on us for their service."

The Privacy Scale Problem

For Ancestry's five-person privacy team, keeping pace with product development while protecting sensitive data – including births, marriages, deaths, and DNA records – was becoming increasingly challenging. The team needed a way to automate privacy reviews without sacrificing thoroughness.

"In the past, I honestly didn't even have a window into that world because they worked on their own stuff, and they never really got us involved in a full vision, holistic approach," Stalder added.

Enter TerraTrue: Bridging Privacy and Engineering

The solution came in the form of TerraTrue's privacy-by-design platform, which integrated directly with Ancestry's existing engineering workflows through Rally (their issue-tracking system).

"That was huge. That was kind of our selling point, to have that automation," Stalder noted. The integration meant engineers could stay in their familiar tools while giving privacy teams the visibility they needed.

But the real game-changer? A simple "stop-or-go" gating process that automatically triages reviews based on risk.

"We realize that some features are just cosmetic," Stalder said. "Maybe they're just changing the color of a button. So we've got a gating question that specifically asks them, 'Does this deal with personal information?'"

The Results: Faster Reviews, Better Collaboration

Today, Ancestry's privacy program looks very different:

  • Automated risk-scoring and routing eliminates unnecessary reviews
  • Engineers can request privacy input without leaving their tools
  • All communications are centralized, replacing scattered emails and Slack messages
  • Privacy teams have complete visibility into product development

"The engineers can stay in Rally, within their own tool. It's not something they have to search for," says Stalder. "That was another selling feature, just to have that ability to keep the conversation going and make it more collaborative rather than very siloed."

Read the full case study

Loading GTM...