About Fiona Chan

I build and run privacy, data, and AI governance as one operating problem, and I write about what makes that work.

For more than fifteen years, I have built privacy, data, and AI governance programs inside regulated businesses across financial services, critical infrastructure, energy, healthcare, and government. The writing on this site comes from that work: making governance practical in the business, not just complete on paper.

01.

Profile

I lead privacy, data, and AI governance inside regulated businesses, bringing legal, risk, and operational disciplines into one working model.

I set the architecture and I do the work. I build the model, assign ownership, simplify artefacts, and push governance into the decisions the business already makes.

I have led programs across financial services, critical infrastructure, energy and utilities, healthcare, automotive, government, and technology with scope spanning Europe, Asia-Pacific, Australia and New Zealand, and global operating environments. Financial services taught me discipline at scale. Europe sharpened my regulatory judgment.

With my legal training, I worked in internal audit at KPMG and corporate tax at EY before moving into privacy, data, and governance leadership. That foundation still shapes how I assess control design, regulatory exposure, and execution risk.

Alongside the writing, I also speak and brief boards, executive teams, and governance forums on privacy, data, and AI governance.

02.

Credentials

Admitted SolicitorLLBLLMCIPP/ECIPMCIPTAIGP
03.

Selected Speaking

4th International Conference of Company Secretaries Institute of Company Secretaries of India / September 2025

Invited speaker on cross-border data governance and privacy compliance for corporate governance professionals across India and the Asia-Pacific region.

Data Protection and AI Governance Webinar Series International Webinar Series / December 2024

Webinar series on data protection and AI governance focused on the collision point between privacy regulation and emerging AI obligations.

Medtech and GDPR Briefing Series Brussels / GDPR / Health Technology

Brussels-based GDPR series for medtech audiences during a period of rapid regulatory change, translating legal obligations into practical governance and compliance steps for senior stakeholders.

GDPR Gap Assessment and Roadmap Readouts Brussels / Client Advisory / Implementation Roadmaps

Gap assessment findings and remediation roadmaps presented to clients across GDPR readiness engagements, translating assessment results into prioritised implementation plans for senior management teams.

04.

Get in Touch

Contact

If the work here is close to what you are dealing with, I would be glad to hear from you.

The contact form is the best way to get in touch.