Skip to content
Open to roles · United States, the EU and the UK

I turn regulation into systems people actually run.

Four years in privacy, risk and compliance across healthcare and regulated data environments, on a law and data protection foundation. The difference is that I build the intake, tracking and monitoring myself, so the programme runs instead of sitting in a folder.

What I do

Three things, and they only work together

Read the regulation and turn it into controls

Risk assessments, impact assessments, data inventories, vendor and third party reviews, policies. Written so they can be tested and evidenced later, not filed and forgotten.

Build the workflow that runs them

Intake, triage, routing, deadline tracking, escalation and evidence collection, built in n8n, Make and Zapier. Most compliance programmes run on spreadsheets and memory. They do not have to.

Get the people who have to use it to use it

Process documentation, training and adoption at the point of work. A control nobody follows is not a control, and that is usually where these programmes fail.

Selected work

What that has looked like in practice

The recordings, documents and working systems behind these are on the projects page.

Platform build

An eight module governance platform in n8n

Intake, routing, inventory, continuous monitoring and escalation, running as live modules rather than a diagram. It replaced spreadsheet tracking, which means control operation is evidenced as it happens instead of reconstructed at audit time.

Automation

Six end to end compliance workflows, human in the loop

Intake, routing, deadline tracking and escalation for regulated processes, including an AI triage workflow that classifies inbound requests, routes by urgency and drafts a first response. A person approves at every decision point.

Privacy operations

Records and data requests run against statutory deadlines

Records and data requests handled end to end, with structured review sets, redaction and an exemptions log. Data flows and system access mapped across six business processes to find where confidential records were reachable beyond the minimum necessary.

Risk and third party

Risk assessments and vendor review, tracked to closure

Risk assessments recorded in GRC tracking formats and reporting dashboards. Vendor agreements and data sharing agreements reviewed alongside Legal, Operations and IT, with remediation tracked across business units until it closed.

The research

The classroom that watches you

Schools are buying AI that reads children's faces, voices, keystrokes and behaviour. My thesis is about who is accountable when it gets one of them wrong.

Education is one of the areas the EU AI Act treats as high risk, and the amended COPPA Rule brought children's biometric identifiers into scope in the United States. Both landed on a sector with almost no capacity to answer for what its software does.

I assessed risk based governance of high risk AI processing children's biometric and behavioural data across three real education use cases, and designed a five stage lifecycle framework covering risk assessment, documentation, monitoring, escalation and remediation. It is written to be operated as a control set, not read as a policy.

MA Data Protection and Privacy (Law and Computing), Dublin City University. Thesis submitted, viva September 2026.

Listen instead

Two separate episodes, recorded at different times on different research. Pick the one you want, or play both.

23 min listen
COPPA, April 2026

COPPA changed. Now what?

What the rule change actually requires, and what it does not.

What the amended COPPA Rule actually requires as of April 2026, walked through one hypothetical EdTech company across four areas: biometric data, retention, third party sharing and security programmes, grounded in real FTC cases rather than a reading of the regulation.

21 min listen
AI in schools

The classroom that watches you

What these systems collect, and who answers for it.

AI, children, privacy and the machinery quietly installed in schools. What these systems actually collect, why consent does almost no work here, and where the accountability is supposed to sit.

Three regimes, one person

Most privacy hires cover one legal system. My degrees are spread across three, so a single person can hold a programme that has to answer to all of them at once.

United Kingdom

UK GDPR, Data Protection Act 2018, ICO guidance

LLB, Anglia Ruskin University

European Union

GDPR, EU AI Act, DPIAs and records of processing

MA Data Protection and Privacy, Dublin City University

United States

HIPAA and HITECH, CCPA and CPRA, FERPA and COPPA, NIST

LLM, Northeastern University School of Law

Where I have done it

Four years, named

Privacy & Compliance Consultant

Jan 2025 to present

PMOps AI · Self-employed · Remote

  • Design and test controls across IT, vendor and data processes, documented so they can be evidenced rather than asserted.
  • Built an eight module governance platform and six end to end workflows in n8n, including an AI triage step with a person approving every decision.
  • Translate HIPAA, GDPR, and CCPA and CPRA requirements into practical operational controls.

Privacy & Compliance Analyst

Jan 2023 to Dec 2024

Transition House · Health and social services · Hybrid

  • Mapped data flows and system access across six processes, finding where confidential records were reachable beyond the minimum necessary.
  • Ran fifteen plus records and data requests end to end against statutory deadlines, with structured review sets, redaction and an exemptions log.
  • Reviewed twelve vendor agreements and third party integrations with Legal, Operations and IT, tracking remediation to closure.
  • Trained thirty five plus staff across four departments, driving adoption at the point of work.

Risk & Regulatory Advisory Assistant

Jan 2022 to Dec 2022

Planned Parenthood · Healthcare provider

  • Conducted ten risk assessments and compiled findings into GRC tracking formats and reporting dashboards for governance review.
  • Reviewed twenty plus vendor contracts and data sharing agreements covering use and disclosure of confidential health information.

Background

Education and research

  • MA, Data Protection and Privacy (Law and Computing), Dublin City University
  • Thesis: Risk Based Governance of High Risk AI Systems Processing Children's Biometric and Behavioural Data in Educational Settings under EU Law
  • LLM, Master of Laws, Northeastern University School of Law
  • LLB, Law, Anglia Ruskin University

Frameworks

  • GDPR
  • HIPAA and HITECH
  • CCPA and CPRA
  • FERPA and COPPA
  • EU AI Act
  • NIST AI RMF
  • NIST CSF
  • ISO 42001

Tools

  • n8n
  • Make
  • Zapier
  • OneTrust
  • ServiceNow GRC
  • Vanta
  • Drata
  • Securiti.ai
  • Claude and ChatGPT

What I am looking for

Compliance operations, privacy operations, technology risk, GRC, AI governance and legal workflow roles.

Remote or hybrid across the United States, the EU and the UK. US citizen, no sponsorship required in the United States.