
Dedicated Data Privacy & Compliance Analyst with 6+ years of cross-functional experience across healthcare, finance, and enterprise IT, helping organizations protect sensitive data while meeting evolving regulatory expectations. My transition from SQL Server Database Administrator to Privacy Officer gave me a rare advantage: the ability to bridge technical architecture and day-to-day operations with privacy and compliance obligations and translate requirements into controls that work in real environments.
I’ve led and supported privacy initiatives aligned to HIPAA, GDPR, and CCPA/CPRA, including privacy risk assessments (PIA/DPIA support), policy and SOP improvements, and privacy-by-design reviews across systems and workflows. I also bring strong execution in privacy incident response and breach management, from triage and containment support to documentation, evidence collection, and remediation tracking with cross-functional teams (Legal, Security, IT, and Operations).
With a deep technical foundation, I’m highly effective in operationalizing safeguards like data classification, access controls, encryption (at rest/in transit), auditing/monitoring, secure backups, and high-availability and disaster recovery practices ensuring confidentiality, integrity, and availability while supporting compliance and audit readiness. I’m experienced with governance and workflow tools including OneTrust, RSA Archer, ServiceNow, Jira, and other risk and compliance platforms to manage vendor risk assessments, third-party reviews, KPIs/KRIs, and continuous program improvement.
I’m passionate about building privacy programs that are practical, measurable, and trusted protecting individuals, strengthening organizations, and enabling innovation responsibly.
Key Responsibilities & Achievements
• Privacy Program Governance & Operations
• HIPAA, GDPR, CCPA/CPRA, HITECH, PIPEDA, and U.S. State Privacy Laws
• Privacy Impact Assessments (PIAs) & Data Protection Impact Assessments (DPIAs)
• Privacy Incident Response, Breach Management & OCR/HHS Reporting
• Data Mapping, Records of Processing Activities (ROPA) & Data Inventory Management
• Data Classification & Information Governance
• Data Subject Access Request (DSAR) Management
• Third-Party Privacy Risk Management & Vendor Assessments
• Business Associate Agreements (BAAs) & Data Processing Agreements (DPAs)
• Privacy Policies, Procedures, SOPs & Governance Frameworks
• Privacy Key Performance Indicators (KPIs), Key Risk Indicators (KRIs) & Metrics
• Audit & Regulatory Support (OCR, ISO 27001, SOC 2, HITRUST, NIST)
• Cookie Consent Management & Online Tracking Governance
• Privacy by Design & Privacy by Default
• Emerging Technology & AI Privacy Reviews
• Security & Privacy Controls Collaboration (DLP, Encryption, Access Controls)
• Privacy Training, Awareness & Workforce Education
• Cross-Functional Collaboration (Legal, IT, Security, Compliance)
• Privacy Tools & Platforms: OneTrust, RSA Archer, Navex (EthicsPoint)
Conducted Privacy Impact Assessments (PIAs) for systems, products, applications, cloud services, and customer-facing platforms, identifying privacy risks and recommending mitigating controls prior to implementation.
• Supported enterprise privacy compliance across retail and digital banking operations in alignment with GLBA, CCPA, and applicable U.S. state privacy and breach notification laws.
• Advised business, product, and marketing teams on privacy by design, data minimization, purpose limitation, and lawful processing of customer and employee financial information.
• Reviewed and advised on privacy provisions in contracts, including vendor agreements, service provider contracts, and data-sharing arrangements, ensuring alignment with banking regulatory requirements.
• Managed consumer and employee privacy rights requests (DSARs), ensuring accurate responses, identity verification, and fulfillment within statutory timelines.
• Coordinated privacy incident intake, investigation, and breach response, supporting internal escalation, documentation, and regulatory notification obligations in accordance with GLBA and state breach laws.
• Performed third-party and data-sharing privacy assessments, evaluating vendors, affiliates, and service providers for compliance with contractual and regulatory privacy requirements.
• Executed cross-border data transfer and data-flow reviews for global banking operations, assessing risks related to international processing and shared services.
• Reviewed data retention and records management practices and tracked privacy metrics to monitor compliance trends and operational effectiveness.
• Prepared and coordinated documentation for regulatory examinations, audits, and internal reviews, collaborating with Legal, Compliance, Risk Management, Information Security, and Technology teams