Why Companies Must Make Privacy Central to Their Business Operations
July 2019
By
Axiom Law
“Operationalizing privacy is important and something businesses need to look at not only as it applies to privacy regulation, but also to general compliance. Companies need to understand where compliance fits into their organization and how it informs their business operations,” says London-based lawyer Angelo. As privacy regulations increase globally, “there’s a suite of issues that need to be looked at, and privacy has lots of touch points operationally and strategically. Companies need to have compliance on a more executive level.”
With a wide range of legal experience in both the public and private sector, Angelo is in a unique position to examine the business implications of proliferating privacy regulations. He offered his insight into how companies can better make privacy compliance central to their operations.
Understanding both sides of the regulation
After nearly 25 years working as a lawyer in government, in-house, and private practice Angelo has seen the wide-ranging impact that changing regulations can have on how companies run their business. After studying law at Oxford, Angelo worked for the government legal service in the UK. There he worked closely with senior ministers and the president of the UK board of trade, where he advised on anti-trust decisions and merger clearances. He then worked as a prosecutor for the UK customs service. Realizing his strength and interest fell into the intersection of government policy and business, Angelo returned to Oxford for a post-graduate degree specializing in regulatory policy, competition, and anti-trust law. He has since built a career focused on how regulatory policies impact businesses on a global level.
While working in-house for an Australian telecom company he traveled to Hong Kong, Tokyo, Australia, New Zealand, and the United States. In doing so, Angelo saw how regulations such as anti-trust and anti-money laundering laws impact global companies. After this experience, he spent ten years working at various UK law firms. Due to his experience in both the public and private sector, Angelo has strategic insight into both how regulators make decisions and how those regulations impact businesses globally.
A new model for being a lawyer
As Angelo moved up the ranks in traditional private practice he found he was moving farther away from the practice of law and the opportunity to be recognized for efficiently producing high-quality legal work. “When you are a business that charges by time, the firm does not value completing work efficiently, and personally I trained to be a great lawyer,” he explained.
Angelo joined Axiom in 2011 and found that it gave him a chance to refocus on legal work. “Because Axiom has people who are really good at and love doing client care it has been an opportunity where I can be valued for actual work I do,” he explained. Working with in-house legal teams he found that he could, “work quickly and get to the heart of the matters versus just making more work. It was refreshing that we could set out and make a decision.”
Lessons learned from GDPR
On a recent engagement with a global engineering business Angelo focused on working with the company’s Chief Privacy Officer on compliance with the European Union’s General Data Protection Act (GDPR), which went live in 2018. Angelo explained that while “GDPR was not a massive change from previous European regulations, the big change and centerpiece of compliance was the fining power of 4 percent of a company’s revenue.” The company already had a global privacy program in place and Angelo worked with the CPO to make sure they could apply the policies they were putting into place for GDPR across all jurisdictions.
Angelo noted that while the company had a formal set of policies in place, the act of enforcing the policies and ensuring they were practical on a business level was another issue. He explained, “It’s one thing to put a set of policies and procedures in place to legally satisfy regulators, [it’s] another to ensure everyone is compliant and [those policies] are incorporated into business operations. It was surprising how different the operating procedures, documentation, [and] training looked in practice than the original, written policies.”
Angelo explained that he helped the CPO revise and streamline their existing privacy policies and procedures to better serve the business on a practical level. For businesses going through the work of repapering their contracts to be compliant with new regulations, Angelo explained, “there’s a lot of background work to make sure those [contracts and policies] reflect the reality of business processes, how people do their jobs, and even business practicalities such as how the company IT network functions.”
Preparing for evolving regulations
As more countries and US states bring privacy regulations online, compliance will continue to evolve. For example, the California Consumer Protection Act (CCPA), which goes into effect on January 1, 2020, “is very different in its theoretical ideas than GDPR,” says Angelo. Given that California is the fifth largest economy in the world, the CCPA could end up causing European regulators to tweak their privacy laws as well.
“This is where there’s a risk for companies from a privacy perspective,” Angelo explains, “will new regulations gravitate more towards GDPR, which will make compliance relatively straight forward, or will the global center of gravity shift towards California or another jurisdiction? We may end up with a load of inconsistent laws, which will require a more fragmented approach and put more risk into business.” It’s especially important, he notes, that companies don’t assume that countries will handle privacy in the same way as the EU or California.
While Angelo acknowledges it's impossible for any one person to know everything about new regulations, he stresses it’s important to understand the legal and political direction that laws are moving and to have specialists focused on major jurisdictions.
The role of Chief Privacy Officer has also become increasingly important. As privacy impacts multiple operational and strategic touch points, Angelo explains that the CPO can ensure that compliance has a voice at the executive level.
Beyond compliance, Angelo advocates businesses take a wider approach. “Build compliance with ethics so failure to comply is a failure to uphold the ethical standards for that company,” he advises. This can be effective “especially if a business wants to incorporate compliance into the company’s DNA. Businesses with strong ethical values tend to outperform their peers, so look at the spirit of what the law intended and work to own it as a business. Ethics isn’t just a manual, but an operation.” Angelo acknowledges this can be a challenge because, “it can be easy to see the privacy function and the increase of work it brings and view it as a pure cost center rather than a question of how we do business better.”
What about Brexit?
For companies based in or doing business with the UK, Brexit raises an additional host of questions around data privacy and regulation. According to Angelo, there are two realistic options companies must consider: Brexit with a formal agreement with the EU or a no deal Brexit.
If there is a “no deal” Brexit and the UK becomes a “third country” in terms of the GDPR, companies transferring data between the EU and the UK must repaper their contracts to show compliance with EU rules. “Internal compliance will be the biggest difficulty,” Angelo notes.
Brexit also will raise long term questions for the way the UK approaches data privacy. “While there’s a benefit to approaching privacy ‘our way’ there’s a compliance cost,” says Angelo. “As jurisdictions like California start passing privacy regulation and the global movement towards privacy continues to grow and competing theories of privacy arise this may shift the direction the UK, and other countries, take on privacy.”
Privacy help is closer than you think
One aspect of working for Axiom that Angelo especially appreciates is the company’s focus on improving businesses processes. Axiom’s lawyers are available to help Axiom’s clients take a new approach to how they conceptualize and utilize legal services.
Navigating shifting privacy regulations can be intimidating and taking an innovative approach to new regulations can be especially so. However, Axiom’s attorneys like Angelo are here to help and support. “Doing what has always been done is easy, but one of the disruptive approaches we can help our clients take is this: let’s get back to principles – why are you doing what you are doing and how are you doing it and how can you do it differently? That approach of questioning and rebuilding requires a great deal of trust, and that’s the mindset we can help with as Axiom attorneys.”
Posted by Axiom Law
Related Content
Continuous Volatility Is the New Normal: Building Corporate Legal Departments for Constant Disruption and Uncertainty
Corporate legal teams must adapt to constant global disruption by building flexible, cost-efficient resourcing models for evolving risk and demand.
Same Problem, One Fix: How a Change Management Framework Can End AI Stall and Law Firm Habit Together
Law firms and AI adoption share the same root problem: change resistance. Learn how the Beckhard-Harris model helps legal teams drive transformation.
What the Quiet Revolution Taught Us
Axiom CRO Sara Morgan on 26 years of ALSP growth: why in-house legal leaders are 3x more satisfied with alternative providers—and what comes next.
The Law Firm Reflex Is Costing You Millions
Axiom CRO Sara Morgan: 61% of legal departments default to law firms when workload spikes, and it's costing them millions. Here's how to break the reflex.
AI Governance Framework: How Legal Teams Can Get It Right
AI governance framework guide for legal teams: risk-based AI policies, data governance, vendor safeguards & compliance best practices.
The Real Reason Legal Departments Can’t Change—And What to Do About It
New Axiom research reveals mindset—not budget—is the biggest barrier to legal transformation, and how GCs can close the knowing-doing gap.
Will AI Replace In-House Lawyers? What General Counsel Need to Know
Will AI replace lawyers? Discover how AI is transforming legal work. Learn why human judgment, business acumen, and communication matter more than ever.
What the WSJ $3,400 an Hour Story Really Means for Legal Teams
Premium firms may charge $3,400/hr, but budgets break from rising associate rates. Legal teams need elastic capacity plus AI to control spend.
Best in Class: Study Ranks Axiom #1 Across Key Performance Metrics
Axiom ranks #1 in 8 out of 9 key performance metrics for flexible legal talent providers, demonstrating unmatched expertise, coverage, and cost-effectiveness. Discover why GCs trust Axiom.
ESG Reporting: Full Guide, Standards, and Requirements
Learn what ESG reporting is, key frameworks like GRI and SASB, evolving regulations, and how to build a reporting program that delivers real business value.
Law.com: The CLOUD Act, Encryption and the US-UK Standoff in 2026
The US-UK encryption standoff has trapped tech companies between irreconcilable mandates—in-house counsel must navigate strategic risks when compliance with both jurisdictions becomes impossible.
AI Contract Management: What Legal Teams Need to Know
As legal teams face mounting pressure to do more with less, AI contract management solutions offer a compelling answer, transforming the contract process.
Why 80% of In-House Teams Are Rethinking Their Law Firm Relationships
New research reveals a legal market caught between legacy habits and transformation, with significant implications for how legal work gets done.
State Privacy Laws: 2026 Changes & Compliance
Navigate 2026 state privacy law changes across 15 states. Learn compliance requirements for Indiana, Kentucky, Rhode Island & key CCPA updates.
Why Axiom Outperforms LPO on Quality, Flexibility, and Business Impact
While LPO can solve some problems, it frequently creates new ones. This is where Axiom’s model offers a fundamentally different and better approach.
Finding Professional Confidence, Personal Balance: How Axiom Empowered a Commercial Attorney's Career Transformation
Discover how Axiom empowered commercial attorney Eileen to rebuild her career and confidence while balancing single parenthood after personal tragedy.
The AI Paradox: Why Your Legal Team's Productivity Gains Are Fueling a Retention Crisis
93% of legal professionals say AI boosts productivity, yet 76% fear job loss. New research reveals how AI anxiety is driving turnover. See the new data.
Essential Resources for In-House Legal Teams: 2025 Year in Review
Explore Axiom's top 2025 legal resources on AI adoption, talent retention, budget transformation, regulatory insights for in-house legal teams, and more.
Continuous Volatility Is the New Normal: Building Corporate Legal Departments for Constant Disruption and Uncertainty
Posted by David McVeigh- North America
- Must Read
- Expertise
- Legal Department Management
- Work and Career
- Perspectives
- State of the Legal Industry
- Legal Technology
- United Kingdom
- Australia
- Hong Kong
- Singapore
- Artificial Intelligence
- General Counsel
- Central Europe
- Legal Operations
- Solutions
- Regulatory & Compliance
- Spotlight
- Data Privacy & Cybersecurity
- Technology
- Commercial & Contract Law
- Corporate Law
- Global
- Tech+Talent
- Axiom in the News
- Large Projects
- Finance
- Law Firms
- Featured Talent Spotlight
- GC Report
- Healthcare
- Cost Savings
- Intellectual Property
- Videos
- Capital Markets
- Diversified Financial Services
- Labor & Employment
- Secondments
- Budgeting Report
- Commercial Transaction
- Energy
- Investment Banking
- Regulatory Response
- Banking
- Construction
- Consulting
- Consumer Packaged Goods
- Financial Services
- Healthcare & Life Sciences
- In-House Report
- Industrial
- Legal Support Professionals
- Manufacturing
- Materials
- Mergers and Acquisitions
- Pharmaceuticals
- Retail
- Transportation
- Aerospace & Defense
- Automotive
- Business Services
- Consumer Services
- DGC Report
- Education
- Food And Beverage
- Hospitality
- Insurance
- Litigation
- Private Equity
- Professional Services
- Public Sector
- Real Estate
- Specialized Advice
- Telecom
- Utilities
- News
- Recruitment Solutions
Get more of our resources for legal professionals like you.
