PRIVACY, DATA PROTECTION, AND AI GOVERNANCE
Practical privacy and AI governance, from blank page to boardroom.
I'm Matthew Ellis. For more than 25 years I've built and led privacy, data protection, and AI governance programs for category-defining consumer and technology brands. Compliance opens the door to opportunity. The real work is building strategies that fit what the business needs and what customers expect.
FRAMEWORKS I WORK IN
GDPR
CCPA / CPRA
US state privacy laws
EU AI Act
ISO 27701
NIST AI RMF
JUST A FEW OF THE MANY BRANDS I'VE WORKED WITH
eBay
McKesson
PayPal
Nike
Peloton
JetBlue
Microsoft
AmBev
Johnson & Johnson
HP
ABOUT
Matthew Ellis
Founder & Principal,
Matthew Ellis LLC
I believe privacy is a key part of advancing business strategy, not just an operational requirement. I've spent more than 25 years proving that's true.
I've built privacy functions from a blank page more times than I can count. I launched EY's first privacy practice, led Deloitte's privacy practice in the Eastern U.S., and built Microsoft's global privacy compliance program. Before its IPO, I wrote some of Google's original privacy policies, at a time when most companies didn't have one at all. I've also set up privacy functions for eBay, JetBlue, HP, Johnson & Johnson, and McKesson. Most recently at Peloton, I co-led the company-wide AI rollout, built privacy into AI-powered products like Strength+, and started a Privacy Champions program that got people outside Legal to care about data.
I create frameworks people actually use, vendor contracts that don't stall the deal, and AI governance that keeps pace with the product team instead of chasing it. I'd rather ship a practical control this quarter than a perfect policy nobody reads.
If you're building something with data at its core, or wondering what the latest AI law means for your roadmap, let's connect.
EXPERTISE
Where I focus
The work I've led across startups, growth-stage companies, and global enterprises.
Privacy assessments
Clear-eyed reviews of how organizations collect, store, and share data, with a prioritized view of what to fix now and what can wait.
Mergers, acquisitions, and divestitures
Privacy due diligence before the deal, integration after it, and clean separation when a business is sold or spun off. Examples range from PayPal's acquisition by eBay to Peloton's integration of Precor.
Privacy programs & operations
Policies, internal controls, data mapping, DPIAs, records of processing, data subject rights, and champions programs that make privacy part of how teams already work and stand up to regulator scrutiny.
Incident response
Breach response programs, executive tabletop exercises, and support for counsel through regulator inquiries.
Third-party risk and cross-border transfers
Vendor due diligence, DPA negotiation, sub-processor oversight, and international transfer risk, including for enterprise AI vendors.
Privacy leadership
Senior privacy judgment embedded with product, legal, and engineering teams, whether in-house or in a fractional role.
AI governance
Responsible-AI frameworks for training data and AI-enabled launches, aligned to the EU AI Act, NIST AI RMF, and ISO/IEC 42001.
OPERATIONS
Making privacy run
Policies are the easy part. What makes them hold up when the business changes shape is the strategic work done when no one is looking.
Operationalizing privacy
Turning policy into daily practice: data mapping and inventories, DPIAs, records of processing, data subject rights, and training and champions programs that make privacy part of how teams already work.
Mergers & acquisitions
Divestitures
Separating data, systems, and obligations cleanly when a business is sold or spun off, so both sides walk away compliant.
Third-party risk
Vendor due diligence, DPA negotiation, sub-processor oversight, and contract playbooks, including for enterprise AI vendors.
Incident response
Privacy due diligence before the deal and integration after it, from PayPal's acquisition by eBay to Peloton's integration of Precor.
Breach response programs, executive tabletop exercises, and support for counsel through regulator inquiries.
Data retention &
disposition
Keeping what the business needs and defensibly deleting the rest.
PRESS
In the conversation
Podcast · Compliance Chronicles with Liisa Thomas
Another amazing conversation with Liisa Thomas & Lauren Ervin - fantastic podcast!
CONNECT
Let’s Connect
Whether it's a role, a project, or a conversation about privacy and AI, I'd be glad to hear from you.