I turn regulation into
systems people actually run.
Four years in privacy, risk and compliance across healthcare and regulated data environments, on a law and data protection foundation. The difference is that I build the intake, tracking and monitoring myself, so the programme runs instead of sitting in a folder.
What I do
Three things, and they only work together
Read the regulation and turn it into controls
Risk assessments, impact assessments, data inventories, vendor and third party reviews, policies. Written so they can be tested and evidenced later, not filed and forgotten.
Build the workflow that runs them
Intake, triage, routing, deadline tracking, escalation and evidence collection, built in n8n, Make and Zapier. Most compliance programmes run on spreadsheets and memory. They do not have to.
Get the people who have to use it to use it
Process documentation, training and adoption at the point of work. A control nobody follows is not a control, and that is usually where these programmes fail.
Selected work
What that has looked like in practice
The recordings, documents and working systems behind these are on the projects page.
Platform build
An eight module governance platform in n8n
Intake, routing, inventory, continuous monitoring and escalation, running as live modules rather than a diagram. It replaced spreadsheet tracking, which means control operation is evidenced as it happens instead of reconstructed at audit time.
Automation
Six end to end compliance workflows, human in the loop
Intake, routing, deadline tracking and escalation for regulated processes, including an AI triage workflow that classifies inbound requests, routes by urgency and drafts a first response. A person approves at every decision point.
Privacy operations
Records and data requests run against statutory deadlines
Records and data requests handled end to end, with structured review sets, redaction and an exemptions log. Data flows and system access mapped across six business processes to find where confidential records were reachable beyond the minimum necessary.
Risk and third party
Risk assessments and vendor review, tracked to closure
Risk assessments recorded in GRC tracking formats and reporting dashboards. Vendor agreements and data sharing agreements reviewed alongside Legal, Operations and IT, with remediation tracked across business units until it closed.
The research
The classroom that watches you
Schools are buying AI that reads children's faces, voices, keystrokes and behaviour. My thesis is about who is accountable when it gets one of them wrong.
Education is one of the areas the EU AI Act treats as high risk, and the amended COPPA Rule brought children's biometric identifiers into scope in the United States. Both landed on a sector with almost no capacity to answer for what its software does.
I assessed risk based governance of high risk AI processing children's biometric and behavioural data across three real education use cases, and designed a five stage lifecycle framework covering risk assessment, documentation, monitoring, escalation and remediation. It is written to be operated as a control set, not read as a policy.
MA Data Protection and Privacy (Law and Computing), Dublin City University. Thesis submitted, viva September 2026.
Listen instead
Two separate episodes, recorded at different times on different research. Pick the one you want, or play both.
COPPA changed. Now what?
What the rule change actually requires, and what it does not.
What the amended COPPA Rule actually requires as of April 2026, walked through one hypothetical EdTech company across four areas: biometric data, retention, third party sharing and security programmes, grounded in real FTC cases rather than a reading of the regulation.
The classroom that watches you
What these systems collect, and who answers for it.
AI, children, privacy and the machinery quietly installed in schools. What these systems actually collect, why consent does almost no work here, and where the accountability is supposed to sit.
Three regimes, one person
Most privacy hires cover one legal system. My degrees are spread across three, so a single person can hold a programme that has to answer to all of them at once.
United Kingdom
UK GDPR, Data Protection Act 2018, ICO guidance
LLB, Anglia Ruskin University
European Union
GDPR, EU AI Act, DPIAs and records of processing
MA Data Protection and Privacy, Dublin City University
United States
HIPAA and HITECH, CCPA and CPRA, FERPA and COPPA, NIST
LLM, Northeastern University School of Law
Where I have done it
Four years, named
Privacy & Compliance Consultant
Jan 2025 to present
PMOps AI · Self-employed · Remote
- Design and test controls across IT, vendor and data processes, documented so they can be evidenced rather than asserted.
- Built an eight module governance platform and six end to end workflows in n8n, including an AI triage step with a person approving every decision.
- Translate HIPAA, GDPR, and CCPA and CPRA requirements into practical operational controls.
Privacy & Compliance Analyst
Jan 2023 to Dec 2024
Transition House · Health and social services · Hybrid
- Mapped data flows and system access across six processes, finding where confidential records were reachable beyond the minimum necessary.
- Ran fifteen plus records and data requests end to end against statutory deadlines, with structured review sets, redaction and an exemptions log.
- Reviewed twelve vendor agreements and third party integrations with Legal, Operations and IT, tracking remediation to closure.
- Trained thirty five plus staff across four departments, driving adoption at the point of work.
Risk & Regulatory Advisory Assistant
Jan 2022 to Dec 2022
Planned Parenthood · Healthcare provider
- Conducted ten risk assessments and compiled findings into GRC tracking formats and reporting dashboards for governance review.
- Reviewed twenty plus vendor contracts and data sharing agreements covering use and disclosure of confidential health information.
Background
Education and research
- MA, Data Protection and Privacy (Law and Computing), Dublin City University
- Thesis: Risk Based Governance of High Risk AI Systems Processing Children's Biometric and Behavioural Data in Educational Settings under EU Law
- LLM, Master of Laws, Northeastern University School of Law
- LLB, Law, Anglia Ruskin University
Frameworks
- GDPR
- HIPAA and HITECH
- CCPA and CPRA
- FERPA and COPPA
- EU AI Act
- NIST AI RMF
- NIST CSF
- ISO 42001
Tools
- n8n
- Make
- Zapier
- OneTrust
- ServiceNow GRC
- Vanta
- Drata
- Securiti.ai
- Claude and ChatGPT
What I am looking for
Compliance operations, privacy operations, technology risk, GRC, AI governance and legal workflow roles.
Remote or hybrid across the United States, the EU and the UK. US citizen, no sponsorship required in the United States.