PRIVACY, DATA PROTECTION, AND AI GOVERNANCE

Practical privacy and AI governance, from blank page to boardroom.

I'm Matthew Ellis. For more than 25 years I've built and led privacy, data protection, and AI governance programs for category-defining consumer and technology brands. Compliance opens the door to opportunity. The real work is building strategies that fit what the business needs and what customers expect.

FRAMEWORKS I WORK IN

GDPR

CCPA / CPRA

US state privacy laws

EU AI Act

ISO 27701

NIST AI RMF

ABOUT

Matthew Ellis

Founder & Principal,
Matthew Ellis LLC

I believe privacy is a key part of advancing business strategy, not just an operational requirement. I've spent more than 25 years proving that's true.

I've built privacy functions from a blank page more times than I can count. I launched EY's first privacy practice, led Deloitte's privacy practice in the Eastern U.S., and built Microsoft's global privacy compliance program. Before its IPO, I wrote some of Google's original privacy policies, at a time when most companies didn't have one at all. I've also set up privacy functions for eBay, JetBlue, HP, Johnson & Johnson, and McKesson. Most recently at Peloton, I co-led the company-wide AI rollout, built privacy into AI-powered products like Strength+, and started a Privacy Champions program that got people outside Legal to care about data.

I create frameworks people actually use, vendor contracts that don't stall the deal, and AI governance that keeps pace with the product team instead of chasing it. I'd rather ship a practical control this quarter than a perfect policy nobody reads.

If you're building something with data at its core, or wondering what the latest AI law means for your roadmap, let's connect.

EXPERTISE

Where I focus

The work I've led across startups, growth-stage companies, and global enterprises.

Privacy assessments

Clear-eyed reviews of how organizations collect, store, and share data, with a prioritized view of what to fix now and what can wait.

Mergers, acquisitions, and divestitures

Privacy due diligence before the deal, integration after it, and clean separation when a business is sold or spun off. Examples range from PayPal's acquisition by eBay to Peloton's integration of Precor.

Privacy programs & operations

Policies, internal controls, data mapping, DPIAs, records of processing, data subject rights, and champions programs that make privacy part of how teams already work and stand up to regulator scrutiny.

Incident response

Breach response programs, executive tabletop exercises, and support for counsel through regulator inquiries.

Third-party risk and cross-border transfers

Vendor due diligence, DPA negotiation, sub-processor oversight, and international transfer risk, including for enterprise AI vendors.

Privacy leadership

Senior privacy judgment embedded with product, legal, and engineering teams, whether in-house or in a fractional role.

AI governance

Responsible-AI frameworks for training data and AI-enabled launches, aligned to the EU AI Act, NIST AI RMF, and ISO/IEC 42001.

OPERATIONS

Making privacy run

Policies are the easy part. What makes them hold up when the business changes shape is the strategic work done when no one is looking.


Operationalizing privacy

Turning policy into daily practice: data mapping and inventories, DPIAs, records of processing, data subject rights, and training and champions programs that make privacy part of how teams already work.


Mergers & acquisitions


Divestitures

Separating data, systems, and obligations cleanly when a business is sold or spun off, so both sides walk away compliant.


Third-party risk

Vendor due diligence, DPA negotiation, sub-processor oversight, and contract playbooks, including for enterprise AI vendors.


Incident response

Privacy due diligence before the deal and integration after it, from PayPal's acquisition by eBay to Peloton's integration of Precor.

Breach response programs, executive tabletop exercises, and support for counsel through regulator inquiries.


Data retention &
disposition

Keeping what the business needs and defensibly deleting the rest.


PRESS

In the conversation

Podcast · Compliance Chronicles with Liisa Thomas

Another amazing conversation with Liisa Thomas & Lauren Ervin - fantastic podcast!

Listen to the episode →

CONNECT

Let’s Connect

Whether it's a role, a project, or a conversation about privacy and AI, I'd be glad to hear from you.