Building Trust
How Privacy Engineering is Shaping the Age of AI
TRICIA MILLER KLAPHEKE
In an era when data privacy and artificial intelligence governance have become critical, alumni from CMU’s pioneering privacy engineering program are filling a critical gap in the industry by mastering the complex intersection of law, technology and ethical innovation.
Geetika Gopi (SCS 2023) found her dream job at a big tech company, allowing her to use her technical skills in service of a mission to protect user privacy.
Gopi leads the Workplace Artificial Intelligence and Language Model Assessments (WILMA) program at Amazon in Boston. After earning her master’s degree in privacy engineering, she became a senior
AI privacy specialist at Amazon and eventually rose to lead the team she started on.
“The program I lead provides scientific evaluation for all AI systems impacting Amazon’s employees, candidates and contingent workers,” she said. “What’s unique about our approach is we employ a multidisciplinary panel of legal counsel, AI experts and input/output psychology experts to evaluate each system. This ensures our systems meet the high bar for responsible AI and are compliant with global privacy and AI regulations before deployment.”
Gopi began her career in cybersecurity, specializing in digital forensics and defense operations. She soon discovered a passion for user privacy, particularly understanding how privacy can be treated as a technical and operational challenge rather than purely a legal and compliance problem. When she learned that Carnegie Mellon was the only institution in the world offering a formal education path
in privacy engineering, she knew that’s where she needed to be.
The need for privacy engineers has grown as privacy regulations continue to catch up with technology. The European Union enacted its General Data Protection Regulation (GDPR) in 2018, and the California Consumer Privacy Act (CCPA) took effect in 2022. Companies that operate across jurisdictions need to comply with the most stringent privacy and AI requirements in any of the jurisdictions where they do business, so global brands have to find ways to comply with the strictest regulations in the world. Now, as the regulations continue to develop, companies must decide whether and how to exceed those requirements as they anticipate new laws and how users’ expectations for privacy might become more sophisticated. That’s when SCS alumni can be most helpful.
“The program is way ahead of current industry standards,” Gopi said. “The breadth of the curriculum shapes us into ‘T-shaped’ professionals — deep in technical expertise but broad across the many dimensions of privacy. Courses like Computer Law and Technology, Differential Privacy, and Engineering Privacy by Design give us the ability to approach privacy challenges from legal, mathematical and systems-engineering perspectives. That kind of multidisciplinary foundation prepares you for almost anything in the field.”
To reflect the increasing responsibilities of privacy engineers, the full-time program has been renamed the Master’s in Privacy Engineering and AI Governance. The part-time program, which allows students to work full-time while taking classes, is now called the Master’s in Privacy Technology and AI Governance. Both programs are growing rapidly along with the demand for privacy engineers.
Jack Gardner (SCS 2022) followed a different path to the privacy engineering program. He studied economics and math at Gettysburg College and then worked as a research assistant in decision making and behavioral studies at the Consumer Financial Protection Bureau (CFPB). While there, he talked to a friend who was in the privacy engineering program and recommended it to him. The research methods he honed as an undergrad and at the CFPB gave him a foundation to pivot to privacy engineering while continuing to focus on user behavior and consumer protection.
As a full-time student in Pittsburgh, Gardner learned the broad legal and technical priorities of a privacy engineer through the Privacy Policy Law and Technology class. He still uses the technical skills he learned from his research project, called Privacy Label Wiz, which helped mobile application developers create accurate nutrition labels.
“Not coming from what I would consider a traditional avenue into the program from computer science, it was the first time I released a full-on software project,” Gardner recalled. “That was very rewarding. And it was nice to go deeper with my classmates as we worked on a project that was not only fun, but also helped us form a better relationship with our professors.”
Since October 2025, Gardner has worked at GM Financial as the company’s second privacy engineer. Gardner’s work centers on how advertising technology responds to consumer preferences.
“We need to be policy and legal analysts to fully understand what legal actions are being taken and which aspects of the CCPA are being actively enforced and monitored,” he said. “And then we must engage technically to monitor advertising technology and how it’s configured.”
Gardner joined GM Financial from CrowdStrike, a firm that protects businesses from cyberattacks. He started there as an intern at the end of his graduate program and was then hired as a data solution architect. He was the first engineer at CrowdStrike to focus on privacy as a significant percentage of his responsibilities, working closely with the legal team. In CrowdStrike’s business-to-business context, he learned where privacy protections are crucial to customer assurance, considering the sensitive data processed with security products.
Blazing the Trail
Norman Sadeh, professor of computer science in the Software and Societal Systems Department (S3D), has a history of starting trailblazing programs. Co-founding the privacy engineering program is no exception.
The first cohort of master’s students in privacy engineering began in 2013. Until then, SCS had been graduating a trickle of doctoral students who focused on privacy issues. As companies like Google and Microsoft asked him to recommend more potential hires with privacy experience, Sadeh realized they could fill those roles with people who held a privacy-focused master’s degree. Privacy is a subject typically taught by law schools, and the SCS program is still the only degree-granting program focused on privacy for computer scientists. Graduates of the program are well-versed in law and can bridge the gap between lawyers and software engineers, helping lawyers understand how policy can be implemented at their company.
“When lawyers talk to software developers, they’re typically talking past one another. They may think they’ve agreed, but in the end, they’ve each understood something very different,” Sadeh said. “A privacy engineer is not just someone who’s an expert in all these different areas, but really someone who helps orchestrate those conversations, ensuring that people are speaking the same language and understanding the considerations being brought by different roles within the organization.”
Sadeh has taught and conducted research at CMU since 1991. In the late 1990s he became interested in privacy policy while working for the European Commission when he helped establish the European Union’s research program in e-commerce and became its chief scientist. The program focused on e-commerce research, including all EU-wide cybersecurity and privacy research, and played a key role in informing related EU policy in these areas. When he returned to Pittsburgh, he knew that privacy would remain one of his priorities, and he pushed his department to hire new faculty accordingly.
In 2003, Sadeh recruited Lorrie Cranor, who was then a researcher at AT&T Labs. She was his top choice because of her unique background. While at AT&T, she led a working group for seven years on internet privacy for the World Wide Web Consortium, an international nonprofit that develops web standards.
Cranor had been at CMU for almost a decade, one of a few professors in S3D who taught classes with privacy themes, when Sadeh suggested a master’s degree program in privacy engineering. They pieced together classes they were offering already, filled in some gaps, and added a capstone project. Then they ran the program by industry partners to make sure the 12-month learning experience would meet their hiring needs.
“We had to invent the curriculum in 2012, and there still isn’t anything like it,” said Cranor. “We periodically go back to companies and ask, ‘Are we still teaching what you want?’ We reach out to our alumni who are now out in the job market and ask, ‘Did you learn what you needed to learn here? Are there other things we should have taught you?’”
Over time, the privacy engineering program has evolved and expanded. The full-time offering includes a 12-month program and a 16-month program with an internship. In addition to a course on Information Security, Privacy and Policy, Sadeh teaches a class on Responsible AI & AI Governance that began as an elective but is now required. Content in the rest of the core courses has evolved to reflect the increasingly prominent role played by AI — both in the form of the new threats it introduces, as well as the new tools that make it possible to help enterprises and users manage privacy.
Sadeh and Cranor are leaders in the field. Working professionals and alumni rely on their research and often come to them for advice. Sadeh has led two of the largest national research projects in privacy — an NSF Frontier project on usable privacy policies and a project on personalized privacy assistants.
Cranor served as chief technologist at the U.S. Federal Trade Commission in 2016 and was one of the founders of the Conference on Privacy Engineering Practice and Respect (PEPR), the main gathering for privacy engineers in the U.S. Hana Habib, privacy engineering faculty member and associate director of the program, co-chaired the PEPR conference in 2026, where Cranor and Sadeh also spoke.
Prioritizing Privacy from the Outset
David Zagardo (SCS 2022) came to CMU after working as an audio engineer. During the COVID-19 pandemic, he became more concerned about digital surveillance and wanted to learn more about privacy. Zargardo independently published his first research, Geometry-Aware Tabular Diffusion, a look at how incorporating privacy mechanisms from the beginning can make developing a new application faster and cheaper. That’s in contrast to what typically happens when developers add privacy mechanisms late in the process, forcing them to make decisions about spending more time and money on privacy accommodations.
“The barrier to adopt privacy-enhancing technologies generally boils down to two things,” Zagardo said. “One, there’s an inherent privacy versus utility trade-off. In order to achieve privacy, we often take a hit on utility by making our predictions less accurate or precise. Two, deploying privacy-enhancing technologies costs more money than non-private deployments. So when we think about behavior change, our good habits have a cost in the present, but they have benefit in the future, and our bad habits have cost in the future, but they feel great in the present.”
Zargardo presented his new paper at the International Conference on Machine Learning in Seoul, and he formed his own business, Morph Research, to help companies where privacy stakes are high build trust with their users by deploying technologies that protect data privacy, comply with regulations and safely use sensitive data that they are otherwise unable to work with. He hopes that his professional legacy will be helping to enable the adoption of privacy-enhancing technologies at scale.
“If we can make it so privacy-enhancing technologies are faster and cost less to deploy than non-private, it’s going to be easier for a machine learning practitioner or data scientist to justify reaching for the privacy-enhancing technologies,” he said.
Expanding the Program
As more companies recognize the need for privacy engineers on their teams, some engineers have taken on those responsibilities before having all the required skills. For professionals who wanted a program where they could learn the skills they need while still working at their full-time job, SCS began offering the part-time, remote program in 2021.
Jillian Fish, a current student in the part-time program, works as a corporate data privacy lead architect at Westfield Insurance in Ohio. Fish holds an undergraduate degree in environmental science and math, and a graduate degree in business. Her professional experience was in health data IT when she joined Westfield Insurance as a business analyst in 2018. Her foray into privacy engineering began in 2022, when a coworker asked her to help with a privacy project.
“I started to learn about all things privacy. I was really intrigued and took to it like a duck to water,” said Fish. “They opened up a position for a data privacy architect, so I applied. They had no privacy-specific resources in the legal department other than the corporate privacy officer.”
All along, Fish was doing privacy work while learning more about what it entailed. She joined the International Association of Privacy Professionals and pursued certifications, including one from CMU.
S3D has offered a remote certificate program for industry professionals since 2022. It takes place over five weekends and features a combination of mini-tutorials, class discussions and hands-on exercises to ensure that students develop practical knowledge of all key privacy engineering areas. This year, S3D added a module on AI governance to the program.
While Fish was learning more about privacy engineering, the corporate privacy officer at Westfield Insurance retired, and for eight months, Fish was the only person there working in privacy. The company also expanded internationally, acquiring an office in London, which meant she had to make sure they were complying with the European Union’s stricter regulations under GDPR.
Now, Fish handles AI governance as much as privacy, overseeing staff that cover both. With these expanding responsibilities, Fish wanted a broader education in privacy, so in 2025 she began the part-time Master’s Program in Privacy Technology and Policy. She takes one class and one seminar per semester and plans to finish in December of 2028. Learning from guest speakers who share things they’re working on has been immediately impactful in her job.
“The concept of ‘policy as code’ came up in a presentation,” she said. “Instead of having policies written out in a document, you implement them as part of your actual process. I think we’re seeing that, especially with our AI governance tool that we’re now implementing. If the policy says you can’t do that, the tool is checking to make sure that you didn’t.”
Lauren Siegel, now a software developer at 1Password, started the part-time program in 2024 when she was a software engineer working on Google’s Workspace infrastructure. Now she focuses on APIs, open authorization and identity. At 1Password, Siegel uses many of the concepts about privacy she’s learning in class.
She studied economics, public policy and computer science as an undergraduate at North Carolina State University, and her interests have always been at the intersection of those three fields. She was excited to take a public policy course during her first semester in the privacy engineering program.
“The privacy engineering program at Carnegie Mellon felt like a really nice fit because it is very interdisciplinary, and I feel like I’m getting to use a lot of what I learned in undergrad from my different majors,” Siegel said.
Siegel plans to finish her graduate degree at the end of 2027 and hopes to work in an even more privacy-focused role, eventually influencing public policy.
“I hope my career will be focused on protecting and empowering people,” she said. “So that may be from the technical side of things — right now I work on consumer security, empowering people’s online security — or from the policy side of things, working to make it so people’s privacy rights are protected.” ■
More from the Fall 2026 LINK Issue
Guarding the Future