About Rasha Hisham

More than ten years in compliance and privacy, in house and on the advisory side

I have spent over ten years in compliance and privacy — in-house and on the advisory side — building programs that continue to operate once I step back. Applied Privacy Consulting exists because the capacity gap is real and a template does not close it.

What I do and who I do it for

I work with customer-facing companies that hold real volumes of personal information or operate in a space where that information is specifically regulated — multifamily and proptech, consumer services, healthcare-adjacent businesses, financial services, and organizations deploying AI against customer or employee data.

At that size the privacy obligation is genuine, the regulatory map usually spans several US state laws and often GDPR or UK GDPR, and the work is steady — but it tends to sit with a general counsel, IT lead, or compliance generalist who already has a full-time job. That is also the point where a full-time privacy hire is hard to justify. Those organizations get better coverage from a fractional owner with depth than from a junior hire who needs supervision they cannot provide internally.

They typically fall into one of three situations: no program and a clear understanding that one is needed; a program that has quietly stopped keeping pace with the business; or a need for an independent read on whether what exists holds up before a regulator, a customer, or an acquirer tests it.

Why I started Applied Privacy Consulting

I started Applied Privacy Consulting after seeing the same pattern repeat across more than ten years in compliance and privacy, in-house and on the advisory side. The businesses I worked with were growing and changing constantly, and the regulatory landscape was moving just as quickly, but the privacy function was almost always a small team or a single person carrying it alongside another full-time role. The result was not indifference. It was a genuine capacity gap, where the obligations were understood and the work simply could not keep pace.

The traditional answer to that gap does not fit it. Large consulting firms arrive with a standard methodology, spend limited time understanding how the business actually operates, and deliver material built to a template rather than to the organization in front of them. Every business has complexities that shape what compliance has to look like in practice — from how it is structured to how its data moves to what its people can realistically absorb — and a standard framework does not account for any of it. What gets handed over is a policy pack or a lengthy report, and the business is left to operationalize it alone, which is precisely the thing it does not have the capacity to do. The advice is rarely wrong. It is just not executable by the people who have to live with it.

I founded Applied Privacy Consulting to close that gap. Whether the need is data mapping, regulatory tracking, an annual audit, or ongoing ownership of the function itself, I start by understanding the business rather than applying a template to it, and the work is delivered so that it continues to operate once I step back. Practical rather than theoretical, and built to run.

Career

  • Director, Global Data Privacy and Corporate Compliance (previously Compliance Director, North America) — Greystar

    Oct 2022 – Jul 2026 · Atlanta, GA · The world's largest multifamily real estate operator, managing over one million units globally

    I joined to lead development and construction compliance across North America, then expanded into global ownership of the data privacy and AI governance function. The central piece of that work was bringing Greystar's privacy program in-house after years of it being delivered through outside counsel and consultants, then rebuilding it as an owned internal capability spanning the US, EU, UK, APAC, and LATAM.

    That meant transferring knowledge and deliverables from the outgoing advisors, rewriting policies and public-facing notices to reflect how the business actually operated, standing up DSAR intake and fulfilment at a volume exceeding 1,000 requests annually, delivering more than 100 PIAs and DPIAs, and building a ROPA covering over 100 processing activities. I implemented DataGrail to scale privacy operations and built the vendor and third-party review process.

    As AI-driven leasing, resident screening, biometric, and smart-access tools entered the portfolio, I extended the function to cover AI governance — authoring AI usage guidelines, designing an AI tool intake and risk review framework, building an AI horizon scanning capability, and leading the evaluation and implementation of Harvey alongside Copilot optimisation for legal users. I served as the senior internal advisor to legal, IT, marketing, and operations, and briefed executives as new state AI legislation moved from proposal to enforcement.

  • Conduct and Compliance Consultant — PwC

    Apr 2022 – Sep 2022 · Atlanta, GA · Big Four professional services firm; US risk and regulatory consulting

    I advised financial services clients on regulatory conduct, compliance, and risk. I conducted a comprehensive risk and control self-assessment for a digital bank in response to a regulatory finding, mapping risks to controls across the institution and identifying the gaps requiring remediation. For a fintech client I led compliance audits against applicable regulatory requirements, assessing the control environment and surfacing gaps ahead of examination. Across engagements I translated regulatory expectations into concrete control frameworks and remediation steps, working with client teams to drive findings toward closure.

  • Attorney, Fintech and Financial Regulation — PwC Middle East

    Jan 2021 – Mar 2022 · Dubai, UAE · Regional arm of PwC, advising regulators and financial institutions across the GCC

    I worked at the intersection of regulators and market participants. I drafted the open banking regulation for the Saudi Central Bank, including the regulatory benchmarking and market surveys that informed it, then led market consultation sessions for regulators and fintechs that each drew more than 100 attendees, and drafted the accompanying regulatory compliance guidance.

    On the industry side, I helped five fintechs secure fund administration and money transfer licences, drafting their compliance policies, business plans, and regulatory applications, and advised global companies on licensing as they planned entry into the Middle East market.

  • Senior Regulatory Paralegal — Abu Dhabi Investment Authority (ADIA)

    Nov 2017 – Jan 2021 · Abu Dhabi, UAE · One of the world's largest sovereign wealth funds

    I was a founding member of ADIA's regulatory compliance team. I assessed regulatory compliance across all asset classes — from equities to global real estate — mapped to ADIA's investment activity worldwide. I drafted compliance playbooks tailored to the distinct risk profiles and requirements of more than seven investment and operations departments, and designed and operationalized the organization's horizon scanning framework, including a monthly regulatory alert that kept the business ahead of emerging change.

    I also delivered regulatory compliance training to over 1,000 investment professionals across 10 sessions, building compliance literacy throughout the investment function.

At a glance

Certifications
CIPP/US
In-house experience
Built Greystar's global privacy & AI governance function from the ground up
Experience spans
Greystar · PwC Legal Middle East · Abu Dhabi Investment Authority
Jurisdictions
US · EU · UK

Credentials

  • CIPP/US — Certified Information Privacy Professional (United States)
  • LLB — Cardiff University

Speaking and memberships

  • Panel Speaker — "Talent In Transition: Building Legal Teams For The Next Decade", The Legal Innovation Forum
  • Panel Speaker — "Women in Finance", Alternative Investment Forum
  • Webinar — "Privacy Best Practices for OnSite Property Management Teams" for a large property management firm
  • Mentor and Membership Lead — Link Mentorship Network
  • Circle Lead — Lean In Network
  • Banking, Finance & Restructuring Team of the Year — The Middle East Legal Awards 2021

Ready to talk about your privacy program?

Start a conversation

Tell me where you are and what is not keeping pace. I will tell you honestly what the work looks like.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.