Security and compliance

10 data privacy consultants

These ten data privacy consultants hold consulting or advisory roles focused on privacy and data protection. A reader can learn how to scope a privacy program, prepare for GDPR and U.S. state privacy law obligations, and run privacy impact assessments and vendor reviews that a small team can sustain.

10 professionals10 companiesData retrieved September 29, 2026

Professionals to explore

01—10
  1. Brock N. Rutter

    LinkedIn

    Experience: Lead Privacy Consultant · Privily

    Lead Privacy Consultant at Privily since 2021. Former Senior Associate, Data Privacy and Cybersecurity at PwC (2016–2017), and the profile also lists a Cybersecurity and Privacy (contractor) role at PwC (2017–2022). His profile describes a senior privacy and information risk consultant with operational expertise in privacy, vendor risk management and AI governance, and a background as a Big Four consultant, startup counsel and privacy program builder.

  2. Elizabeth Cobb

    LinkedIn

    Experience: Senior Privacy Consultant · Tevora

    Senior Privacy Consultant at Tevora since 2024, and a freelance Privacy and Risk Management Consultant since 2023. Former Privacy Director at Korn Ferry (2021–2023) and former Assistant Vice President, Privacy Practices at Unum (2015–2020). Her profile describes consulting on, implementing and managing data privacy compliance programs and privacy incident response, including implementing OneTrust vendor risk management, privacy impact assessment and DSAR modules.

  3. Janalyn Schreiber, CIPM, CISSP, CDPSE

    LinkedIn

    Experience: Senior Managing Director · Data Privacy Simplified

    Senior Managing Director at Data Privacy Simplified since 2016, and Co-Founder of Logical AI Governance since 2023. Former Managing Director at Navigant (2015–2016) and former Principal at Deloitte (2010–2014). Her profile says she advises executive teams and boards on building AI governance, managing regulatory investigations and operationalizing global privacy and cybersecurity programs.

  4. Joshua Vaughan

    LinkedIn

    Experience: Senior Data Privacy Consultant · ZAVIANT

    Senior Data Privacy Consultant at ZAVIANT since 2023, and former Data Privacy Consultant at ZAVIANT (2022–2023). Former Managing Director at Fychan Group, LLC (2014–2022). His profile describes him as a qualified privacy professional who assists tech-savvy businesses in navigating complex global data privacy and compliance issues.

  5. Maria Godoy

    LinkedIn

    Experience: Senior Privacy and Data Protection Consultant - Team Lead · Hitachi Cyber

    Senior Privacy and Data Protection Consultant - Team Lead at Hitachi Cyber since 2023, and Senior Privacy & Data Protection Consultant there since 2022. Former Privacy & Data Protection Analyst at Hitachi Cyber (2021). Her profile says she has advised startups, scale-ups and multinationals across North America, Latin America, Asia and Europe through GDPR, LGPD and CCPA rollouts and the EU AI Act.

  6. Matthew McCabe

    LinkedIn

    Experience: Owner & Principal · McCabe Privacy Consulting LLC

    Owner & Principal at McCabe Privacy Consulting LLC since 2021. Former Data Privacy Manager, North America at Coloplast (2019–2021) and former Senior Manager, Privacy at PwC (2017–2019). His profile describes experience developing, maintaining and revising policies, standards and procedures for the operation of data protection, data governance and data privacy programs.

  7. Michael Spadea, JD, CIPP

    LinkedIn

    Experience: US Practice Leader (Technology) Risk & Compliance, Information Governance, Privacy & Security · FTI Consulting

    US Practice Leader (Technology) Risk & Compliance, Information Governance, Privacy & Security at FTI Consulting since 2024. Former Senior Managing Director Data Risk & Privacy Practice, Western US at PwC (2017–2024) and former Director Privacy, Cybersecurity, and Information Assurance Practice at IBM Promontory (2012–2017). His profile says he builds privacy, risk and security programs that hold up under regulatory scrutiny, board pressure and real incidents.

  8. Sharon S. Kamowitz

    LinkedIn

    Experience: Principal Privacy Consultant · American Cyber Security Management

    Principal Privacy Consultant at American Cyber Security Management since 2022, and Principal at Sharon Kamowitz Privacy & Compliance Consulting since 2019. Former Senior Privacy Consultant at TrustArc (2021–2023) and former Assistant Privacy Officer at Fresenius Medical Care (2014–2019). Her profile describes an attorney and CIPP/US-certified privacy professional with experience developing, implementing and managing privacy and compliance programs.

  9. Simon Wynn

    LinkedIn

    Experience: Privacy and Data Protection Consultant, Owner · Simon Wynn Consulting

    Privacy and Data Protection Consultant, Owner at Simon Wynn Consulting since 2018, Privacy and Information Security Consultant at Lucid Privacy Group since 2023, and Data Protection Officer (DPO) at Hyros since 2023. Former Director, Privacy Product Management at Meta (2020–2023). His profile describes him as a privacy and data protection consultant and fractional DPO/CISO with CIPP/US and CIPP/E credentials.

  10. Wendi Lozada-Smith - CIPP

    LinkedIn

    Experience: Managing Consultant Founder- Privacy, Ethics and Data Protection Consulting · PrivaQuest

    Managing Consultant Founder- Privacy, Ethics and Data Protection Consulting at PrivaQuest since 2017, and Senior Privacy Consultant at TrustArc since 2017. Former AVP Executive Director at AT&T (2009–2017). Her profile describes her as an independent consultant and global privacy and data protection leader whose work covers CPRA, GDPR and privacy program development.

Choose the right perspective

Match the consultant's background to your need: attorneys and former in-house privacy officers suit policy and regulatory questions, while consultants who have implemented privacy tools and assessments suit operational rollouts. Confirm which laws and regions their client work has covered before engaging them on a specific regime.

Questions to take into the conversation

  1. 01What are the first steps you take to map personal data and assess privacy risk in a new engagement?
  2. 02How do you prioritize obligations when a company is subject to GDPR and several U.S. state privacy laws at once?
  3. 03How do you set up data subject request and vendor review processes that a small privacy team can sustain?

About this directory

This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.

Request a correction or removal

Other perspectives in Security and compliance