Turning Privacy Into a Business Success Factor with Matthew Ellis (Ep. 16)
Key Takeaways
- Embedding privacy into product development and R&D from the beginning turns it from a late-stage compliance obstacle into a strategic business success factor.
- Non-lawyers can successfully navigate privacy and compliance by bridging the gap between legal requirements and product ambitions through effective communication.
- Privacy professionals are frequently asked to own emerging fields like AI and M&A diligence because of their strong problem-solving skills and ability to adapt quickly.
- Saying yes to stretch opportunities and being open to continuous learning are critical drivers for a long-term, successful career in privacy and compliance.
- Maintaining a focus on ethics, morals, and customer data protection remains fundamental as privacy complexities grow exponentially over time.
In this episode of Compliance Chronicles, Liisa Thomas talks with Matthew Ellis, an “opportunity creator and problem solver” who has spent nearly 25 years building and leading privacy programs across startups, Big Four firms, global technology companies, and consumer brands. Matthew shares how he fell into privacy at an email marketing startup, went on to start EY’s first Bay Area privacy practice, led privacy at Microsoft and Peloton, and now advises small–to–mid‑tier companies on turning privacy into a true success factor.
He explains why privacy is most powerful when it’s operationalized—embedded in product and R&D from the beginning—and why privacy professionals often end up owning AI, M&A diligence, and complex data questions. Throughout the conversation, Matthew highlights the importance of bridging legal and product, saying yes to stretch opportunities, and treating privacy as a long‑game career path.
This episode covers:
- Why early collaboration with product and R&D turns privacy from a late-stage obstacle into a strategic success factor
- How privacy professionals can bridge the gap between legal requirements and product ambitions by “speaking both languages”
- Lessons from large acquisitions and M&A work, including why “signing authority to assume risk” is a critical governance question
- Why privacy teams are often asked to take on AI, and what it means to “do something with nothing” when it comes to data and emerging tech
- How building teams of passionate learners and saying yes to stretch roles can accelerate a privacy career
- Why privacy is likely to remain a strong, growing career path over the next 20+ years—and how to prepare for that future
- Practical advice on leadership, vulnerability, and knowing when to raise your hand for more responsibility
If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.
Frequently Asked Questions
How do you turn privacy into a business success factor?
You operationalize privacy by embedding it into product and R&D processes from the very beginning rather than treating it as a late-stage compliance check.
Do you need to be a lawyer to have a career in privacy?
No, privacy professionals do not need to be lawyers. Non-lawyers often excel by leveraging institutional knowledge and acting as a bridge between legal teams and product developers.
Why are privacy teams often asked to handle AI governance?
Privacy professionals are frequently tasked with AI oversight because they are strong problem-solvers who know how to navigate complex data challenges and emerging technologies.
What is signing authority to assume risk in M&A deals?
Signing authority to assume risk is a critical governance checkpoint used during acquisitions to ensure leadership pauses and understands the privacy and data risks associated with a deal.
speaker-1: Welcome to Compliance Chronicles, we learn from professionals shaping the world of compliance. â your host, Liisa Thomas, â Privacy and Compliance counsel an professor at Northwestern Law School, and a lifelong learner of organizational change. â From journeys to hard-earned lessons, â these the chronicles that inspire and guide. â Let's in. I am to welcome Matthew Ellis to the podcast. Matthew, can you just Introduce yourself before we
speaker-0: get started. Thanks, Liisa. My name is Matthew Ellis. I'm an opportunity creator and a problem solver in the privacy field. I've been doing this for almost 25 years. â
speaker-1: You are one of my oldest friends in the privacy space, and we met a long time ago standing in line to ask questions to the FTC before they came out with that little law, KAPA. â and so tell us a little bit about your journey and how you got to where you are right now.
speaker-0: Well, thanks. it's certainly been a journey. I graduated from college in the 90s, which wasn't the best of times. And so I went to work for an email marketing â startup, which was very cutting edge at the time. â And I got there and they said, Do you know anything about this thing called privacy? And I said, No. And they said, No one wants the job. And I said, I'll take the job. And so I did. I took the job. I worked there for about two years. â we had European investors, was the big issue for them. I went from there to Ernst and Young and I started their first privacy practice out of the Bay Area. And the reason that I ended up at EY is I'd hired them to do an assessment for me and they did a financial audit, if you would. And I said, that's not what I asked for. And they said, Well, why don't you come and start that practice for us? And so I did. I was in the the â the big four for about â seven years of my career, â then I finally made my way over to Microsoft's. Which was a great experience. and then the last 10, 15 years have primarily been â on consulting â for small to mid-tier companies. and the last couple of years have been at Peloton, which was just a total treat of a company to work for. It was lovely. I think the thing that brings me back every time is the people and being able to work with really smart people who have the same â goal in mind, which is to really Look at how privacy across the board is handled and really kind of taking privacy from just a compliance issue and making it â operational and making it you know something that is â is a success factor. So for instance, â you know, working with product teams early on is always a great experience for me. â you think about privacy before you even come up with the product, whether it be a widget or a bike or whatever it is. It doesn't â privacy isn't something that pops up at the end, let's partner on this, let's figure out how to solve for success. You know, you become an integral part of the RD process. And it's really great when it works. and you know, in my career, I've really not had to say no that many times. So when people hear it, they're like, â my gosh, he sent no. The complexity today for privacy is a hundredfold of what it was when we first started. You know, when we first started, it was How do we make sure that we have ethics and morals in what we're doing related to customer pri customer data and customer privacy? The privacy people for the most part ended up getting AI because we can do something with nothing. And so companies look at that and go, our privacy people are great. They're good problem solvers. â and so I think that's the one thing that brings me back.
speaker-1: Well, that takes us to my next question, which is the challenges you've faced along the way and the tools that you've used to overcome them.
speaker-0: Yeah, I think challenges along the way in the beginning was â are you a lawyer? Because I think some people always connect privacy with legal. And the reality is, no, I'm not a lawyer. The way that I am able to bridge the gap between legal and product is huge because product will say, We want to do this, and legal will say we need you to do this. And I gotta be able to speak both languages Also, â in the beginning of â privacy back in nineteen ninety nine, when we were looking at doing MA type of opportunities, people didn't know what they needed to look for during a â during an acquisition or you know, a divesture. So you know, we had to really come up with here's the game plan, here's the blueprint, and here's how you do that. not being a lawyer in the last five years has probably not really been a detriment, but it's been a bit of a kind of struggle bus for those of us who weren't lawyers throughout the years. but when you have the institutional knowledge and history that those of us who've been at this for a while have, people eventually realize they know they're they're really good. They know what they're doing. And I bring teams with me, which I think all the difference. â Some of the other challenges would be working diverse parts of a business and a portfolio and having them understand that privacy and data Can be a plus, it can be a plus or a minus. So yeah, I've I've done some work with PEs and VCs, and they always want to look at the deal of how do we price it the highest and how do we only have to pay the lowest? and they've got a million different ways they do that. And so one of the questions I always ask â the company, it's like, what is your signing authority to assume risk? And The response back to that would be, is there a signing authority? Not a good comeback, you know, you're in trouble. Or if they're working with an organization that has a fairly, robust privacy program, they can look at it and say, we're gonna need to bring others in, â to get this deal Now, signing authority to assume risk is just a way stop and be like, everyone think about what it is we're trying to do here. It's never meant to be a good deal breaker or anything like that. If you have an active buyer and you have an active seller and everyone wants a deal to happen, it's happening. you just want to see what you're getting before you actually have to get it. And one of the other issues early on for me was in the MA world and also just the large acquisitions. I did the HP compact merger from a privacy perspective at the time, was really just understanding you're in a clean room And if this deal doesn't go through, you're out on both sides. And that's a really interesting place to be when you're a late twenties person leading a new practice at a firm. So that was a big challenge.
speaker-1: So these are the challenges, lessons that you've learned over the time that you've been facing these challenges. What are some of those lessons?
speaker-0: The key ones are gonna be that if someone's interested in learning and they're interested in like privacy as a potential career path, we'll take them all. I used to joke at EY in the beginning, days I'm like the bad news of a practice. I will take whomever â is interested and has a passion learning. And most of those become very, very successful on their own right and privacy. learning and growth myself, now that I look back and I I think like it's been 25 years, â should have gone to law school? Should I I have gotten my MBA? These are all questions that I ask myself, on a fairly consistent basis. And the reality was no, because the way I approach is it's a leadership opportunity for everyone. And I think that learning and growth within your own career and also within an organization is really a kind of an exciting opportunity to do things you never thought you could do before. I never said no to an opportunity in my first probably 15 years on privacy. Hey, would you like to come to Microsoft and do North America privacy? Sure, let's do that. Hey, would you like to refocus on working in large pharmas when I was with Deloitte? Sure, I'd love to do that. And I think with privacy, you get a lot of access and you have to know how to use it sparingly. you also just want to make sure that you have your I's dotted and your T's crossed because you know someone's gonna be looking at it from an exact perspective. And I remember another attorney that I worked with over the years and she looked at me and she said: You should stick with this. This is gonna be a great career for you. And she was absolutely right, it was some of the best career advice I ever got. I think the learning and growth is the opportunity for people to really try new things. And you have to be able to feel that you can be vulnerable and you have to be able to raise your hand and say, I'd like more. â
speaker-1: So parting advice. â
speaker-0: I think parting advice is say never because you never know when something might present itself. â often in our world that people new opportunities, especially today. â you have to ask yourself the question of if you lean into privacy as your career path, will privacy still be there for you in twenty, twenty five years? â for what we see today and what I've experienced, yeah, it will, and it's gonna be even bigger and better than it is today. That being said, remember to take vacation time, remember to connect with the people that you care about, whether it's someone from work or not, and be able to laugh because this â career it be very difficult
speaker-1: So this is perfect. Dive in and breathe. I love it. Matthew, thank you so much for making the time to have this conversation. I hope you enjoyed this episode of Compliance Chronicles, where we get guidance and inspiration from the personal journeys of leaders in the profession. If you did, I'd love it if you'd consider subscribing or leaving a rating or review. It helps others discover the show.