Privacy in Tech Field Guide: Insights from Joyce Chen
I recently hosted an “Ask Me Anything” session featuring Joyce Chen, founder of Chen and Foundry and former Chief Privacy Officer, to deconstruct how privacy operates in modern tech. Joyce’s career spans public interest law, government tech accelerators (City Innovate), big tech (Facebook, Snap), and high-growth AI startups. She offered a practical look at how privacy functions work, how AI governance is reshaping the discipline, and how public servants can position their skills for this domain.
Here's the breakdown of our conversation:
Defining Privacy Beyond "Legal Compliance"
In the private sector, privacy functions act as the operational bridge between engineering teams and external regulators. Privacy leaders focus on protecting user agency while enabling the company to ship profitable, compliant software.
Big Tech vs. Early Stage: Large tech companies run structured, gated product reviews where legal and privacy check-ins happen at every milestone from initial design to launch. At smaller companies, privacy teams are lean. Success requires embedding directly with product managers, understanding quarterly roadmaps, and solving problems without slowing down releases.
Product Counseling Skill Set: The core of in-house privacy work is product counseling. You analyze early software designs, identify data risks, and translate complex regulations into technical guardrails that protect users while advancing business goals.
Shift from Pure Privacy to AI Governance
Privacy is expanding well beyond the European Union's GDPR law. With over 20 state-level privacy laws in the US alongside sector-specific rules, privacy teams now manage a complex patchwork of requirements.
The AI Convergence: Because AI models rely heavily on data collection, training sets, and human review teams, privacy practitioners are stepping in to run AI governance, trust, safety, and risk programs.
National Security Assets: Data is increasingly regulated as an asset subject to export controls, opening up new compliance areas where public sector knowledge is highly useful.
Translating Public Sector Experience
Tech companies sometimes harbor false assumptions about government transitioners, potentially assuming they are slow-moving or overly focused on process over results. You can counter these misconceptions by highlighting your operational strengths and ability to work diplomatically and cross-functionally.
Matrixed Navigation and RACI: Government workers excel at moving projects through large, complex organizations. Frame your experience around managing RACI dynamics (Responsible, Accountable, Consulted, Informed) to show you can coordinate cross-functional teams smoothly.
Tracking Policy Signals: Public servants bring a proven ability to parse massive amounts of regulatory noise, spot weak signals, and explain how legislation will be enforced before secondary news outlets report on it.
Insider Risk and Investigations: Backgrounds in intelligence, forensics, or investigations (CIA, FBI, DHS) transfer directly into insider threat programs, incident response, and forensic data auditing inside tech privacy and security teams.
Practical Realities of Credentials and Hiring
The tech job market is crowded, and automated application systems create a heavy volume of resumes for every open role.
CIPP Certifications: Certifications like the CIPP/E (European Privacy) or CIPP/US offer a helpful signal if you are making a total career pivot. They show commitment and baseline knowledge, but they are not a substitute for practical problem-solving. Many CPOs do not hold certifications, so focus heavily on demonstrating how you apply regulations to business products.
Operational Entry Points: You do not need a law degree to work in privacy. Program management, data governance, controls frameworks, and operational compliance roles rely on business execution rather than formal legal training.
Avoid Cold Applying: Cold submitting resumes yields low response rates across tech. Build warm relationships, leverage alumni networks, and secure internal referrals to get your background flagged to hiring managers.
Bottom Line
Privacy and AI governance are evolving rapidly, meaning traditional playbooks are constantly being rewritten. Success in this field comes down to rapid learning, operational clarity, and showing tech leaders how your public sector problem-solving skills translate directly into protecting their business.

