Amtrak’s privacy leader on how to win allies and budget for your privacy program

In the latest Privacy Huddle, Colleen Barry is joined by Maria Buccieri, Senior Director of Enterprise Compliance at Amtrak, to talk about the people and persuasion side of in-house privacy leadership. She has built programs at a community bank, a state transportation agency, and Amtrak, after a career start selling cars.

  • Privacy RegulationsState Privacy Laws
  • Episode 104
  • September 24, 2026
  • Host: Colleen Barry

Stream this episode on

Summary

A lot of privacy advice hinges on regulatory guidance and tech evaluation. The other half of in-house privacy leadership is people and persuasion: winning allies, budget, and respect before a crisis forces the issue.

This episode sits with Amtrak's Senior Director of Enterprise Compliance, who has built privacy programs across three very different organizations: a community bank, a state transportation agency, and now one of the most recognized brands in the country. The career start was selling cars. Sizing people up on the lot translates surprisingly well to getting an organization to care about privacy.

Privacy teams should treat ally-building as a core control. Listen first, bring legal, risk, and the business into one budget case, and do not wait for a finding or a headline to make the ask.

Transcript

Colleen

Well, hello folks. I am so pleased to welcome you to another episode of the privacy huddle. My guest today used to sell cars and now she gets a federal transportation agency to care about privacy. Now you might be wondering what is the harder sell and so am I, so let's get into it, Maria. Hi, what a

Maria

pleasure to have you on the podcast. Thanks for having me.

Colleen

So we have to start with this, this very interesting tidbit in your, in your history, right? Selling cars. Now, be honest with you, do you still size people up the way you did on the car lot?

Maria

Oh, yeah, absolutely. It is tremendously helpful when trying to get people to buy into your program because really, it's still a sell at the end of the day. Just a different, slightly different sell.

Colleen

Oh my gosh, I love it. Now, are there tells you learned that if you've already won, you've lost? What are the tells that help you from the lock days?

Maria

Well, people like to talk about themselves. So, if you can get them to start, I mean, we're on a podcast where I'm talking about myself. So if you can get people to talk about themselves, you can generally get buy in a little faster. And it was the same way with the car and asking what they actually needed. Don't try to sell something, try to solve a problem.

Colleen

That's right. Isn't that timeless advice? I love it. Well, folks, we're gonna unpack all this with Maria. If you haven't joined before, welcome to the Privacy Huddle. My name is Colleen Barry. I lead marketing at Ketch, and the Privacy Huddle is our almost weekly show where we talk all about privacy headlines, news, tips, tricks, trends, in house, best practices, and that kind of thing. And my guest today is the lovely Maria, who is senior director of enterprise compliance at Amtrak. Now, if you've joined and listened to the podcast before, know that a lot of times we focus on news and recent headlines and kind of what's been trending in new privacy content. But today, Maria has brought such an interesting background as a guest here that I want talk about privacy in a little different way than we typically do. She's built privacy programs across three very different organizations, and so let's talk about the part that nobody necessarily puts in the headlines or in the frameworks, which is really the people. Right? How do you get an organization to care about privacy investment through people and relationships and hopefully some other secrets she's willing to share? So let's go ahead and dive in, Maria. We covered little bit of the car sales chapter, but, you know, everybody, in my experience, everybody has an interesting journey into privacy. So tell me a little bit about what got you into this field.

Maria

Sure. So I actually was, I mean, the car sales aside, I did sales for a number of years out of college in banking and finance, and I did mortgage lending. I did retail banking. I got robbed a couple of times. And that actually was when I started thinking, I'm getting a little too old for this, and I wasn't even old at the time, I think about that now. And I started thinking about back of house type stuff and what I really liked. And one of my former employers, which was Wells Fargo, been in the headlines for some compliance and privacy issues. I think I can say that pretty safely, not say anything that people don't know. And I was just fascinated about the kind of lack of controls that had gotten them to that space. Started as a consultant in banking, banking privacy and compliance, and then really just kind of grew from there. Became a CCO for a regional bank, went to the Massachusetts Department of Transportation, and now I'm here. I gave track. It's a transferable skill set. I think people don't realize that from industry to industry. Privacy, compliance, ethics, it's the same. It's the same framework,

Colleen

just different people. Absolutely. And I would think too your background as from, you know, legal background as well as that IT background, that's gotta help, right? Especially as privacy has become so much more of a data and IT problem.

Maria

Oh, very, very much so. I mean, I think it's if you talk about it again, like this more nebulous way of like, oh, privacy rules, people don't realize what it is. But I think if you can actually, especially with your internal clients, start to tie it back to, what do you think people are doing with your data, with your social security number, with your HIP data when we start to go down that path around medical records, medical information? And I think you can get people to care about your program internally a little bit more when you start to make connections about what it actually is, and it's not just a law. I resort to citing law as the last possible tool in the toolbox. Only works with other lawyers, probably. Yes, it does. Nobody else wants to hear about

Colleen

it. Know I'm a partner, that wouldn't work with me. Yeah.

Maria

No, it would not. You are not interested in the citation. You are not interested in this policy that took me six weeks to draft that three people are gonna actually read in its entirety. What you are interested in though, is that if we don't do this correctly, you will not be able to market your product safely for a little while. And that's really, I think to me, that's the balance that needs to happen in that space about getting people to really appreciate the framework. They don't necessarily have to care about it, but if they can appreciate it and have some respect for why it needs to be there and what the guardrails are, I think you're halfway there.

Colleen

Yeah, so as you've built that kind of respect and mentality for, like, billion those guardrails across these different companies, is there, like, continual kind of habit or belief or instinct that you've carried into every one of those roles? No. To your point, it's transferable, right? No matter the company, is there something you always carry with you?

Maria

Yeah, I think there's definitely always a couple of members of your in house counsel team, if you have one, that are gonna back you because they see you as law adjacent. So even though you're not an attorney for the company, you still understand where they're coming from. One of the biggest things that I got out of law school was not necessarily the practice of law, because I don't practice law, but understanding how attorneys think and how to communicate with them in that space and the way they look at problems versus the way a CPA looks at problems and being able to bring both of those skill sets to the table at the same time. And the IT piece, it's always your CISO, your deputy CISO. Someone in that function needs to be bought into what you're trying to build because they don't they might not realize it, but they own a part of it instinctually.

Colleen

Yeah. No doubt. So I'd love to start kind of unpacking these three different programs that you built because we have a lot of listeners that run-in house privacy programs. And as you said, every every company needs this on some level. So there's just I found such there's just such a huge variety in the way people manage these programs and the way their stakeholders care about privacy or don't care about privacy. Like, can you just talk to us? Like, walk us through that journey of what each of these programs kinda looked like or how you tackled it. Just, what were some of the differences, the different experiences in each

Maria

of those industries? Sure. My My favorite part in meeting people in the privacy space is that all of us think every other team or every other function, like another organization has this huge privacy team that's tackling all these problems. If I only had the budget of such and such corporation or the staffing of such and such place, and when we actually all sit down at privacy summits or other conferences, you realize you're all kind of in the same boat. It doesn't matter what size of your org is. For us or for me rather, it's a little bit easier because I've been mostly domestic privacy facing. Do a little bit with Canadian privacy now and some with GDPR because of our customer base. But prior to that, prior to being here, it was all domestic privacy, which is still hard in and of itself because the states are all doing their own thing and the federal government can't figure out what we want to do with privacy on a national level. Then when you start layering in the international privacy space, it definitely becomes, I think, more complex. So that is something that in every one of these programs that I've built, it's not necessarily gonna be solved by having more people. It's by having solutions that get you the answer that you need at a particular time that you need it because you don't need to know every part of GDDR. But if you have a breach, you need to at least be able to find all the information real quick.

Colleen

Yeah. Absolutely. As you worked across these organizations from, you know, community bank, state transportation agency, now Amtrak, I mean, on the other side of it, has there been anything you expected to carry over role to role that that hasn't, that you've had to be more kinda nimble about?

Maria

A little bit, yeah. So the first two programs that I built were more reactive. They came out of an issue. In the state's case, they came out of a control finding that had led to a much larger news article that starts to really put the focus on the program. So you get funding and resourcing a little bit easier when you're actively building a program and a framework that's solving a problem. I came to Amtrak, it was a proactive build. Amtrak started looking forward the next five years, what are we gonna need? They had safety buttoned up obviously, that's our primary focus is transporting our passengers from one place to another safely. But there's so many other pieces to compliance, including privacy that weren't in an enterprise framework. They were all siloed apart. And they had said, hey, our executive team had had a study done, said we should really look at bringing this all together into an enterprise framework, recruited me to come on board and start building that. And I was excited because I thought this will be a little bit easier. There's no pressure that I'm solving a problem in X amount of time because I need to respond to state legislature or a regulator. But in some ways, it's a little bit harder because people don't understand why you're here. When you go into an organization to solve a problem, they know exactly why you're there. You're a fixer. They're like, okay, she's here, she's gonna fix this, she's gonna build our framework, we're gonna give her resourcing. When you come to an organization, that's okay, they're like, why are you asking questions? Why do you care about our data privacy? No one's read our cookie banner since we deploy it. Why are you this interesting where these buttons are on our banner?

Colleen

Yeah, you're creating problems, right?

Maria

Yes, that is the thought. So really the first year of any organization I've been in, I'd say the first six months, a year might be a little too long, but the first six months, I just try to listen. And you have to do it at an accelerated pace when you're solving a problem. You get the grace of less stress when you're just trying to find solutions. And for me, that's been the experience here is it's taken a little longer to get traction because there's not a immediate issue that we're solving for, but being able to listen to people and see what they actually need and to your point, not being the one who's finding problems, but you're trying to find solutions. Our privacy problem We're problems. Right, our privacy problem becomes, hey, how can we generate more revenue by appropriately collecting consent, appropriately opting people out so that the people who want to hear from us are actually hearing from us in the correct way, in the compliant way. So that's a carryover and a little bit of a learning curve over the last few years.

Colleen

Yeah, interesting. I'm curious, so as you said, the difference between when you're building reactive state, in a reactive state or proactive state, I mean, with Amtrak, I mean, do you think that ability or desire to be proactive, in your case, that mostly been due to just their leadership and opinion, or is it also just all these external factors, right? During the time you've been at Amtrak, of course regulation has heightened, enforcement has heightened, like has it been both factors or more internal versus external? You know?

Maria

I think it's both. I think internally, you know, we've had a really good executive team that's been more forward focused, and it's still about running trains and it's still about running a good railroad, but realizing that this is not fifty years ago. There were multiple components to this. Your customers have different expectations. It's not just about getting from point A to point B, it's about what you do with their data, how you process their credit cards, what's their onboard experience like. Customers have gotten a little pickier, rightfully so, and they want shiny new things. And I think our executive team understood that and realized that some of that framework would help them move faster in the future in the ways that mattered. I also think in the transportation industry overall, the bipartisan infrastructure bill that was signed a few years ago really pushed an influx of funding into the transportation space like they had never seen. And it allows you to do great big mega projects. But with that, you need some good controls. And if it's not something that was already set up, then that's the time to really make sure that you've got it in place proactively, not when there's an audit and someone's asking you how how do you handle x, y, or z.

Colleen

Yeah. Yeah. You reflect on these three programs, is there I I one, I know you're still in Amtrak, but like, which one feels like it's been the hardest or how is it? Does it have to do with that reactive proactive state or more with the company itself? Any perspective on that?

Maria

I mean, they're all hard in their own way. I don't have kids, but I'm pretty sure this would be like picking a favorite child. Great point.

Colleen

It's an

Maria

ironic You're

Colleen

right. Shame on that.

Maria

I will say from a stress standpoint, working at the Commonwealth through no fault of their own was probably the most stressful job I've had. And even in talking to peers there, there's no you're never really off the clock in those roles because you're a small organization with a sharp lens on you from taxpayers, and there's a lot of questions that come along with that. And especially if you're starting in a reactive posture, kind of always in this defense cycle. Even when you're doing well, you're still trying to make sure that people are understanding the why and what you're doing for preventative measures. I think that's really hard and combine that with you live in the same space. It was the same way in banking. You live where you work, so people would disagree with something and then see you in the grocery store and they have opinions. Yeah. Even now, I mean, when I introduce myself and people find that I work from Amtrak, I will generally hear good, bad, or ugly what their last experience on our train was as if I had anything to do with it whatsoever.

Colleen

I have no doubt. Everybody has a personal Amtrak story. Right? They do. Yeah.

Maria

Some are great, and, you know, some people love it. I've had people reach out, and their families have worked here for generations. We have a lot of generational railroaders, so that's been really cool. Yeah. But sometimes trains are not on time, and I get all of those stories as well. I'm sure

Colleen

you do. Now you have to share because I have from our prep discussion, that was one thing that fascinated me, the answer is but of course, but just the culture of the kind of fandom at Amtrak, right? There are people

Maria

that's crazy. It is. It's the it's the coolest thing. So I will say I was not a train girly before coming to Amtrak.

Colleen

That's like train girl, I've never heard that one.

Maria

Exactly, exactly. You will find me on a plane more often than not. I love a good airport, but from a trains I didn't realize that there was this just really love for trains in The US. And really, I mean, when you look at railroads overseas and kind of just the service levels that you see in Europe or the Far East, just what that train service looks like compared to what we've been really trying hard to build here for a passenger railroad system. It is very different, but people love Amtrak. I mean, families have worked here for generations. Customers will continue come back and have traditions where they bring their kids on a certain ride, or when we launched our new Acela, there was just so much love and excitement for it. We had done a parade, we were a sponsor of a parade here in DC, and we had a float and people were absolutely fangirling, cheering, screaming how much they love Amtrak. And I think this might have been the story I told you, this woman came up to us and she had a tattoo of our logo on her forearm I was like, I thought it's a bold fashion choice. Right.

Colleen

I hope there's some kind of like discount for like I don't

Maria

know if there is. I don't know if she's scanning like a QR code when she gets on board, but I'm pretty sure it's just the, she met her significant other on Amtrak. Candidly, as did I. We knew each other, but that's how we realized that we had a connection, on an Acela train to New York. So people really connect that emotion to our brand. And I can't say this enough, it is amazing to work for a brand that has that much recognition. When I was interviewing to come here, one of the questions our now president asked me is, Why Amtrak? And I said, you're an amazing brand, like the chance to come and build a compliance and privacy framework at one of the most recognized transportation brands in the country is awesome. And here I am. So evidently the answer worked, but it's also true.

Colleen

Yes. No, I love it. That's incredible. So, okay, let's get back to this idea of kind of like making the case without a crisis, because I hear this all the time from in house professionals, like, and I think the most recent example that comes up often is just, I know my organization's not doing enough. We're not spending enough to kind of invest or really fortify our privacy program. I, as the privacy leader, know there are risks out there. Right? I know my peers are getting slammed with these demand letters. I've heard of people actually getting investigated, but, like, my leadership kind of believes it, but we haven't been hit yet. And so I need to figure out how to get the money, but I need to figure out to convince people. So I would love to hear, Maria, just talk more about getting that investment and attention in absence of a very urgent event. Like, how have you learned to make privacy compete for attention and budget?

Maria

I mean, it depends on the year whether I would tell you I'm successful in this space or not.

Colleen

Yeah.

Maria

Go with mildly successful. I definitely think it's hard. So I think civil money penalties and settlement demands where you see a lot coming you know, **** coming out of California, I think there's a way to use that. It's more the stick than the carrot approach. I have found that doesn't necessarily work in the years that I've been doing this because you can always rationalize that in some way. You can always say it's not gonna happen here, that we haven't had an issue. There's always some way to kind of push off the fine piece of it, the penalty piece of it. I've had organizations that I've worked for, not my current org, but I've had organizations where the CEO has said, okay, well, what's the fine? If we just pay it, what happens? Not really what you wanna hear as a compliance and privacy officer ever, but it's a part of this industry. It's a part of program that is still, even when you look at the history of compliance and privacy frameworks, relatively new. And and I think you have to figure out what your why is and how you're gonna be in a position of influence without just making people fear the penalties that come with it. For us, a lot of times the conversation that I have internally are more around reputation and more around the fact that we take the trust customers place in us with their safety very seriously. So why would we not take that same trust that they place in us with their data? To me, it's one and the same. It's just a different type of safety, and it's a different way to show that you care about your customer base. I think that that's been more consistent in being able to have those conversations and keeping our reputation and running a good railroad and putting our customers first in the center of that conversation. So I found in building out these programs, particularly if you have revenue generating customers, was a little bit harder at the state because your taxpayers are driving on your roads whether they want to or not. You don't really have other options. So it's a little bit different. You're more respectful of them from a tax paying standpoint than a customer base. But when you have a customer base, that's really to me more of a responsibility that you take and looking at, I guess, is this a conversation? We work so hard to get our customers and that whole customer experience cycle. Do we really want something that we have control over, like compliance and privacy, to be what knocks that off of its access? And usually, that's the business case that you can make.

Colleen

Yeah. So back to what you said, right, quoting from the regulation or the settlement is a last resort, and you're spending that first six months hopefully listening to see what these business leaders care about, right, to what you wanna map to.

Maria

Yeah, absolutely. And I mean, at the end of the day, they want to succeed in their spaces just like we do from our seat in privacy. And they're not mutually exclusive. You can both be successful in your spaces together, even though it seems that there are certain functions within the org that would be at odds with each other. But I think figuring out what your North Star is, if it's customers, if it's shareholders, whatever that happens to be, and just continuing to drive towards that is a more personal message that I think gets across to your peers and your executive team stronger than telling them, you know, such and such company just got a $2,500,000 violation.

Colleen

Right. Make it more of the the carrot, as you say, the positive bit. Yep. Now you you mentioned marketers specifically before, and I just wanna talk about them because, you know, I every privacy leader I speak with, it seems to be kind of the problem child because marketers do present so much risk to the organization.

Maria

You you are you are a risky you are a risky bunch. I'm married to I'm married to one of you, so I understand.

Colleen

You you so then you've seen the underbelly. You know we're just throwing tags, places, Maria. We're

Maria

doing all trying. You're trying. Whatever you can to get out there. I get it.

Colleen

So every privacy leader I've talked to is just concerned with what marketing is doing, always trying to find ways to make them care more, get kind of their partnership more. Like, you talked a little bit about keeping that revenue in mind, and, like, you can you can collect more permission data and more opt ins if you have privacy top of mind. I mean, does has that message really gotten through to the marketers that you've worked with? Like, how unpack more how you're kind of talking with marketing teams.

Maria

They probably have, like, a 50% success ratio in that space. Okay. Sometimes it's worked well, sometimes it hasn't. It depends. I think it depends on a couple of things. I think there are some I'm gonna overgeneralize. I think there are some marketers that are in an organization to make a splash and move on to the next best thing. And I respect that. Everybody's got to hustle, I understand. I think there are some that are really there and they're trying their hardest to do the best that they can with what they've got. So trying to understand what they're solving for, and instead of just always saying no, and I'm not the first person to say this, but being the department of no, K N O W, and actually bringing some knowledge forward that maybe they don't have in a certain space, Or saying like, you can do this. And you need to add this disclosure language to the bottom of the consent box. Put that in there too. So they're not immediately on the defensive. I've tried with our team, We obviously communicate a lot with our passengers when they're in the middle of a trip. There's a lot of transactional emails that go out, updates, not just their initial ticket confirmation. But I gave our team their own quick reference guide to understand the separation between a transactional email and a marketing email. And who do those go to? And that way, they don't feel that they have to ask for permission every time they're doing something. People wanna be emboldened and have the autonomy to just do their work. They don't wanna come and ask the compliance privacy people, hey, can I do this? Is this okay? Am I touching some reg I'm not supposed to touch in a certain state? They just want to hit their deadlines and get the information out and do what they were hired to do. And I respect that. I mean, you guys are an incredibly creative bunch. You think of ways to get around privacy laws very creatively. You see that? I'm like, woah. I hadn't seen that one before. So it does it keeps me on my toes, keeps me young. But I think if you can share that knowledge and empower the team that's doing that marketing work to understand, here's some guardrails. Know? Like, just if you stay in this lane, you're good. If this customer doesn't wanna talk to us, do we really want to keep harassing them? Have already told us they don't want to talk to us. It's not going get better if we keep calling them or we keep messaging them. So just getting that point across has been fun with our team.

Colleen

Yeah, mean I frankly love the idea of, to your point, like, cheat sheet guardrail type of things. Like, for the time being, until further notice, you can always do these kinds of things. These things probably check with me. Like, that that kind of, I think, stuff helps.

Maria

Yeah. We've done some approved language so that they already know that they can do that. We worked with our team around new pixels being deployed or when the app stores update things. Like, what are some levers that they can pull with, again, those safety guardrails already in place so they don't feel like they have to have a meeting, another meeting, and a meeting about the meeting to get their project forward. So I found that that helps both of us.

Colleen

Yeah, absolutely. Now you've also talked about the importance of finding friends in an organization, finding allies to support your program. It seems to me this especially becomes important frankly when it comes to budget, right? I've talked with university teams that don't have a lot of budget and you need kind of reach across to marketing or IT or whoever. Can you talk about, like, how have you found those kind of friends and allies in the programs you've built in? How do you identify them? What makes them good allies? That kind of thing.

Maria

Goes back to the car sales conversation. I'm sizing them up when I get here, Colleen. Like, you wanna buy into this program.

Colleen

Good vibes. It's a vibe. Yeah. Exactly. It's all

Maria

the vibes all the time. I mean, everybody's fighting for every budget dollar right now. I don't care what organization you're in. If you're for profit, if you're a government funded like we are, it's a whole other level. But the the budget discussion is the same, I feel like, with every practitioner I speak to across board. So I don't think any of us are immune to it. I think the more you can collaborate with partners, whether it's the business, whether it's your risk management team, your internal audit team, and you can bring things forward together, I've seen that there is a lot of strength in numbers. If you're bringing a budget ask forward for a project or an update or an upgrade, and there's four of you from different businesses saying, we all need this, there is a much higher likelihood that you might not get it, but at least somebody will listen to you.

Colleen

Right.

Maria

At least let you do the pitch. And that's you know, you're halfway there if they're listening and they're not killing it immediately. So that's been really a priority for me here. And when I was at the state, I had some great internal partners that we would bring things forward together and we would say, hey, here's what's going to work for their department. Here's what's going to work for us on the privacy side. Here's what's going to protect us from litigation on the legal side. And you really start to build a business case that includes an ROI, includes cost savings, all the things that your finance people want to see. I think we in the privacy and compliance space struggle with the numbers part of it because it's not second nature to us. Regulations are second nature to us. Right? You know, math is not usually. Right. But if you can tie those things together, that makes a more compelling case. And then you might get a quarter of the budget you asked for.

Colleen

And also, I mean, and I have to say too, in those cases, like, if you're working with outside vendors to support your program, oh my gosh make them do that work for you. Like they're trying to sell you their advisory services or tech or what have you like make them do the work and do the homework. I mean, that's a great example of a place you can rely on outside vendors too.

Maria

Our vendors are fantastic at building business cases for us. I mean, they're up and running like, all right, we can show you how you're gonna save x, y, and z. I'm like, fantastic, let's bring it to you.

Colleen

Absolutely, use the resources at your disposal and I love what you say just about finding that kind of group internally because personally I've learned that in my career just as I've grown too. Mean the importance of building consensus if you want something done is just, it can't be overstated, think, from any seat in the organization. And it doesn't have to be nasty or political either. It's just about consensus building and getting folks to understand.

Maria

Yeah. Well, and I think we're at a weird time in this timeline overall where people are very adversarial for no particular reason. And work seems like one of those places that you can still build more bridges than not. And I find that no one comes into the office, if you're in the office or on teams, to start an argument with peers every day. So I think people want to build consensus. They just have to come at it from the right angle, and you can bring them there depending on the case that you're bringing forward. You can be a source of unification in the privacy space instead of an adversary.

Colleen

Absolutely. Know, Marie, if I can recall something else from our prep chat, you know, if you're new from if you're new in the business and starting from zero with these relationships, I recall you, it's back to what you said before, It's keeping the business and the customer as your North Star because that's what matters to your colleagues, right?

Maria

Yeah, absolutely. I mean, we all want to be gainfully employed. There's, you know, no matter what your organization is, you have a widget or a person or a something that ties you all together. So keeping that in the center of it is the most important part. And it really should be especially if you're a privacy officer, it really should be something you care about. Like, I don't think you can do this work, be kind of lukewarm about it. Like, you really do have to be somewhat passionate about the work that you do in this space, particularly because you've got, you know, half the states that don't have a concern about privacy at this point. I mean, you really do have to be passionate about it, just as much as you focus on your California and New York customers, there's a whole bunch of customers in the middle, they have no laws protecting them. Like you've got to worry about them too.

Colleen

Yeah, absolutely. I love it. Well, Maria, do you think, I mean, do privacy pros have to go back to the car lot or is this stuff learnable? I mean, how would you say folks can develop these kind of, know, ally building people skills

Maria

that think they you could could pick up a side job and go No, sell I think you can pick it up. I think mentorship, whether it's within your organization or outside of it is hugely important. A lot of times mentorship outside of your organization is even more important because you can gripe a little bit and find an answer to a problem that you might have without fearing that you're losing internal capital. I've got a couple of people that I'm struggling to figure something out, I know I can call them and ask some questions and they have nothing to do with here. Conversely, there's some great practitioners that reach out to me, and I have nothing to do with their organization, but we can talk through a problem that they're having. And hey, how would you approach this? Or how would you get reporting for this? I think that is not as prevalent, I've found, in our field as it is in some others. And I think part of it is that, I don't wanna say privacy is new, but it's newer when you look at it in the compliance and risk space. So there's not really a ton of organizations dedicated to that. I mean, you have WISP, you have, you know, a couple of others I can think of off the top of my head. But Yeah. Locally, getting, you know, that smaller group that you know you can reach out to, I think, is still really important. You can learn those skills.

Colleen

I'm with you. I I do think it it can be challenging prior to your point. With IPP knowledge nets, it's kind of it's like feast or famine depending on the metro area if they have an active group, but it can be a place to start to maybe find birds of a feather. Right? Like that kind of thing.

Maria

And if you're not in a metro space and I mean, I'm in DC now. I was in Boston previously, but before that, I was in a much smaller market. You don't you don't have access to those things. You're not near a big city that has a lot of traction in those spaces. So, you know, reach out on LinkedIn. I have not found a single person that I've reached out to that if they respond back, there are always gonna be people who ghost you. LinkedIn is a bit like the employee dating world, employment dating world.

Colleen

Totally.

Maria

It's always people who ghost you on the app. Yeah.

Colleen

And there's like catfish. It's like, it's

Maria

a whole situation. There's definitely catfishing going on on LinkedIn, especially with some AI lately. Like everybody calm down. We know you don't sound like that in real life. Come on, come on. But if you reach out, I've reached out to people at larger organizations and say, hey, I saw this post or I heard you on this podcast. Can I, you know, can I have a virtual coffee with you if they're not local and just hear about your career path? And that goes such a long way towards learning in your field.

Colleen

Yeah. And, actually, I think that is the benefit of it being still a small industry that it's not like it's ridden with giant influencers and such. Right? Like, people will do that for free often because they're so, to your point, passionate about the field and the industry. I love it.

Maria

Yeah. So reach out. Make a friend.

Colleen

I love it. Well, Maria, it's been such a pleasure chatting with you. Love hearing about your career history and also just your words of wisdom after building these programs. Is there anything you'd leave listeners with as they continue to fight these battles internally and gain mindshare? Don't get discouraged. If you

Maria

would have told ten years ago that you'd be doing what you're doing now, your younger self or junior career self wouldn't believe it. So, you just got to keep going forth and know that every day you're moving forward with your program and helping your customer or your organization. I think that's the biggest thing. You gotta stay upbeat about it.

Colleen

So true. I love it. Great words of wisdom. Well, Maria, thank you so much for joining me. Folks, thank you for listening to another episode of the Privacy Huddle, and we will see you next time.

Next step

See permissioning infrastructure in action

Walk through the platform with a Ketch architect, or launch the free CMP today.

Get Started Free

Get started in less than 5 min