Home Data Privacy Roundup Meet Ron De Jesus, The First-Ever ‘Field’ Chief Privacy Officer

Meet Ron De Jesus, The First-Ever ‘Field’ Chief Privacy Officer

SHARE:
Ron De Jesus, field chief privacy officer, Transcend

Over the past five years, the number of people on LinkedIn who list their title as chief privacy officer (CPO) has increased by 35%, according to the International Association of Privacy Professionals.

And it’s no wonder: In that time, 17 US states have passed data protection laws, with more on the way. As a result, privacy compliance has shot to the top of company to-do lists.

In that sense, Ron De Jesus was a privacy executive before it was cool. He has 15 years of in-house operational experience in privacy-related roles at Deloitte, American Express, PwC, Coach and Tapestry (following the Coach rebrand), Tinder, Match Group and, most recently, Grindr.

(He was chief privacy officer at Grindr, in fact, in 2021, when the Norwegian data protection authority fined the company $7 million for GDPR violations. But more on that below.)

But now De Jesus is doing something a little different. In February, he joined data governance and privacy platform Transcend as its – and the industry’s – first-ever “field” chief privacy officer.

Rather than directly managing risk and regulatory compliance as a traditional CPO would do, De Jesus is a liaison between Transcend and the broader privacy professional community. He’s out in the field at events and taking meetings to evangelize Transcend’s technology and gather intel to inform future product development.

He also spends a lot of time talking to stressed-out CPOs about their challenges.

So, what are chief privacy officers talking about two or three drinks in at a cocktail party when they’re feeling a little loose?

“I mean, honestly, they’re probably taking the chance to not talk about privacy,” De Jesus said. “But if you’re asking what’s on their mind, it’s the evolving landscape of regulation. They’re sick and tired of dealing with a patchwork of laws and they’d really love some legislation at the federal level.”

De Jesus spoke with AdExchanger.

AdExchanger: How does Transcend’s technology work in a truly nutshell-sized nutshell?

RON DE JESUS: We’re a privacy platform that uses machine learning to help simplify and automate compliance. There are automated tools for privacy impact assessments, for data protection impact assessments, for consent management, for AI governance.

If a company is launching a new feature that collects health information, for example, the CPO is required to review that feature through a privacy impact assessment – like an audit of the proposed feature. You have to ask questions like: What personal information are we collecting? Who is it being transferred to? Are we updating our privacy policy? These are all requirements stipulated by existing laws and regulations, and we automate that process.

How does the platform change or adapt every time a new privacy bill is signed into law?

There are a lot of new laws in the US, but they do have a common baseline. Roughly 70% to 80% of these laws say the same thing, but there’s also nuance by state. It’s our job to help CPOs stay on top of all of it, including dealing with the outlier situations.

Take Maryland, for example, which passed recently. That law is being touted as even more stringent than CCPA, and the broader privacy community was surprised because some of what’s included breaks out of the norm. It has very strict data minimization requirements and rules for how to handle sensitive data and children’s data. Our platform needs to adjust to meet these requirements and also whatever else comes down the line.

Comic: SwampedYou’ve worked as an in-house CPO, but you’ve also done independent consulting to help startups set up best practices to manage privacy compliance. What sort of compliance challenges crop up for startups?

Mainly, it’s a resourcing issue. They’re subject to many of the same requirements as a fully established fortune 1,000 company, but they don’t have 100 people working in their privacy department. A 10- or 20-person company doesn’t need a full-time CPO, but they still need help navigating the laws.

I would always take a risk-based approach with smaller and medium-sized companies to identify gaps and help them prioritize what to focus on.

You were at Grindr in 2021 when the Norwegian Data Protection Agency fined the app for passing data without consent to third parties, including MoPub, Xandr, Smaato, AdColony and OpenX. What did you learn from that experience?

Suffice it to say this whole thing was an, uh … “interesting” experience.

Companies don’t typically deal with regulators on a regulator basis, but when you do, it’s clear these are very smart people.

As a company, we obviously took this very seriously, and for me, personally, it was a unique experience because it actually helped me up-level my game. It was my responsibility to provide robust documentation of how we were making changes based on their recommendations throughout that entire process.

It was challenging, but I like challenges.

This interview has been lightly edited and condensed.

🙏 Thanks for reading! As always, feel free to drop me a line at allison@adexchanger.com with any comments or feedback. And do you think someone should maybe tell Cookie Monster what’s likely coming in early 2025? It doesn’t look like he knows.

For more articles featuring Ron De Jesus, click here.

Must Read

Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS

Apple’s WebKit crackdown appears to extend well beyond The Trade Desk, putting hundreds of ad tech, data and identity vendors on a mysterious, dynamically updated block list.

Josh Reed, Zoom's VP of brand and content, speaking at AdExchanger's Programmatic IO event in New York City (September 28, 2006)

Zoom’s Marketing Challenge Is That It’s Too Well Known For Its Own Good

Zoom has 99% unaided brand awareness, which sounds great on paper. But there’s a catch: Most people still think it’s just a video-call app.

Why Agencies Think They Shouldn’t Own Agentic AI Tools Or The Data Used To Build Them

Agencies are differentiating their tech stacks by building custom agentic AI tools for their clients. And they’re rethinking owning those AI tools – particularly since licensing them creates new revenue streams.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Programmatic IO: Insurers Are Building Ad Tech’s AI Accountability Layer

Agencies and marketers discussed the future of AI governance at AdExchanger’s Programmatic IO NYC this week. The main takeaway? Expect insurers to play an increasingly important role in managing AI compliance.

Apple’s Latest Operating System Blocks The Trade Desk From Serving Ads On Safari

The Trade Desk is unable to serve ads to the Safari browser for Apple device owners that have downloaded iOS 27. Apple has been investigating the issue since last week.

Who Will Stand Up For The Open Web?

The open web is done, stick a fork in it. Banner blindness is near universal, search traffic has run dry and publishers are struggling for oxygen. But what if that’s … not true?