Steffi Sesuraj Direct
“For every feature you want to build,” Steffi explained, “I want you to ask: ‘Would I feel good if this person knew exactly how their data was used?’ If the answer makes you hesitate, we redesign.”
She handed out cards with different user identities: “Anoushka, 16, shares art online.” “Mr. Davies, 72, uses your app to video-call his doctor.” “Lea, a journalist in a country with strict speech laws.”
Her most famous case, however, came when a major smart-home device company discovered a vulnerability that had been silently recording snippets of private conversations. The company’s legal team wanted to bury the report, issue a quiet patch, and hope no one noticed. Steffi Sesuraj
It was a radical shift. Suddenly, privacy wasn’t a legal shackle. It was a design challenge. The team started building “privacy by default” settings, simplified data download tools, and clear, cartoonish icons that told users exactly what data an app was using, in real time.
Steffi knew she had to change their minds. She didn’t march into the boardroom with legal threats. Instead, she brought a stack of index cards. “For every feature you want to build,” Steffi
Today, she runs her own non-profit that teaches children how to protect their digital shadows. And on her website, beneath her list of awards and patents, is the same quote from her mother that she’s kept since law school: “You don’t own the information. You merely borrow it for a while. Be a good borrower.”
The backlash, when it came, was brief. The public, exhausted by corporate cover-ups, was stunned by the honesty. News headlines read: “Company Messes Up, Then Does the Unthinkable: Tells the Truth.” The stock dipped for a day, then soared as the company was hailed as a new gold standard for digital ethics. It was a radical shift
After law school, while her peers flocked to corporate mergers and intellectual property battles, Steffi dove headfirst into the then-niche world of data privacy. She pored over the dense, 88-page text of the General Data Protection Regulation (GDPR) like it was a thriller novel. While others saw compliance checklists, she saw a framework for dignity.
Her big break came when a social media startup, reeling from a public breach of user location data, hired her as their first Data Protection Officer. The engineering team saw her as a “no” person—a roadblock. The CEO saw her as a necessary evil.
“Let’s play a game,” she announced to the skeptical engineers.
In the sprawling, humming campus of a leading tech giant in Silicon Valley, where jargon like “synergy” and “disruption” hung in the air as thick as the scent of cold brew coffee, Steffi Sesuraj was known for two things: her encyclopedic knowledge of data privacy law and her uncanny ability to explain it without putting anyone to sleep.