How I engage with the Chief Privacy Officer
There are a few high-quality ways I’ve typically spent the most time or gotten the most value out of Chief Privacy Officers over the years. Part of it may have to do with the business we were in at Return Path (and now, Bolster), but part of it is understanding what the Chief Privacy Officer needs from the business and working with them in that arena.
For example, I found it helpful to work with the Chief Privacy Officer to help them to deeply understand our business. Part of what I think we got right in this regard at Return Path was that we almost always made this a fractional role that was combined with other responsibilities — Tom Bartel, Dennis Dayman, and Margot Romary almost always did other senior jobs in operations or product as well. This is what most likely enabled us to play more offense with the function rather than play defense. Even with an operation or product background, the Chief Privacy Officer is typically focused on external threats and issues and I have found that working with them on business issues not only raises their knowledge, but helps them understand potential security risks.
Another thing I did was to role model training and compliance. If you mention of the word “compliance” to just about anybody in the organization, you’ll see that it doesn’t usually get anyone’s juices flowing. But it’s important for the company to live up to its obligations with customers and with its own internal policies and we found that if we involved a certain amount of employee training every year around compliance, we were able to build skills and stay on top of changing dynamics. I always try to be the “first done” on an online training course and make sure to follow related policies so that our Chief Privacy Officer has air cover…and so that I can ask others to do the same with a clear conscience.
During a crisis. I may interact with Privacy infrequently, but oftentimes when I do, it’s because something has gone wrong, or we’re worried about something going wrong. That’s ok! As long as you can be there to support your Chief Privacy Officer on an emergency response basis and practice some level of servant leadership in a crisis (“how can I help here…who do you need me to call?”), you’re doing your best work in this department.
It’s important to have a regular cadence and a strong relationship with the Chief Privacy Officer because when a crisis hits you don’t want to miss any steps. While most of the time things run smoothly in the Privacy domain, the few times when things spin out of control those are the exact moments when you need to hit the ground running, trust your Chief Privacy Officer, and help get everything sorted out.
Learning Loops
The last couple weeks, I’ve written about tools in the CEO toolbelt that I learned with my coach Marc years ago in a workshop called Action/Design — Inquiry vs. Advocacy, and The Ladder of Inference. The final post in this series is about Learning Loops (or Double Loop Learning if you prefer), popularized by Chris Argyris a couple decades ago.
Here’s the graphic on it:

What’s the tool in the CEO toolbelt here? It’s that every time you’re analyzing a result, you need to analyze it on two levels. Level 1 is the more obvious learning — “What happened…and what do I do next time to produce the same/a different result?” Level 2 is the less obvious learning — “Why did that result happen, and how do I need to think differently about the problem in the future?”
Think about how to apply this to a business result. You put a new pricing plan in place. Clients don’t bite. Loop 1 just gets you something like “ok, let’s try a different pricing plan.” But Loop 2 gets you “how did we come up with the pricing plan that failed in the first place…and how do we generate the next one so we don’t fail?”
Or think of how to apply this to a difficult conversation. You and your VP Eng on why a critical engineer left your organization abruptly. Your VP Eng is blaming Product for poor management of the agile process and product design; you believe it’s an issue of engineering team burnout. You can just go back and forth Advocating your points of view and maybe even Inquiring as to why those points of view exist, and even the powerful Ladder of Inference may not be able to help unless you have a great exit interview. Double Loop Learning is an offramp from that kind of conversation in that you can add that Level 2 questioning to the mix. It’s not about “what do we tweak so another engineer doesn’t leave tomorrow.” It’s “is there a systemic problem here with the way we produce product (or even broader – with our product/market fit) that doesn’t encourage the best team members to stay here?”
The best CEOs are the ones who are constantly listening, learning, adjusting, and executing. Hopefully these three principles — Learning Loops, Inquiry vs. Advocacy, and The Ladder of Inference will all help you on your journey.
Signs your Chief Privacy Officer isn’t Scaling
Chief Privacy Officers who aren’t scaling well past the startup stage are the ones who typically have the following characteristics and you should look for some of these telltale signs.
First, if your Chief Privacy Officer looks at you sideways when you ask for a strategy or even a mitigation plan for a breach, then you might have a bigger problem than the fact that you don’t have a plan. While we like to talk about things like Privacy by Design and using data protection as an offensive strategic weapon, the reality is that Chief Privacy Officers need to have actionable plans in place at all times for the areas where they judge your company to be the most vulnerable. If you ask to see the plan or get briefed on it and you get back a blank stare, you know you have a reactive person on your hands for what needs to be a thoughtful proactive role.
Second, you might have a Chief Privacy Officer who is not scaling if they would rather lecture you on GDPR than talk about why your data protection plan will win business. Privacy people can be geeky, legally-oriented, policy-focused and very technical. All that is well and good but there is so much more that a great Privacy Officer can do. For example, if your Chief Privacy Officer can’t engage in strategy with you and other executives and understand the levers of your business and how their role can help further them, you may as well use an outside law firm instead of taking up a valuable seat at the table internally.
The Privacy team can be small and somewhat insulated from the business, but your Chief Privacy Officer needs to be able to engage the entire company, they need to be thinking strategically about the business, and they need to have short- and long-term plans in place for contingencies and forseeable roadblocks. If they can’t bring these skills to the table at startup scale, how can they bring them to the table when things really take off?
The Ladder of Inference
Last week, I wrote about Inquiry vs. Advocacy, an important principle I learned early in life and then explored more deeply in an Action/Design workshop my coach Marc took our whole leadership team through years ago.
This week, I’ll continue to riff on the theme of communications tools in the CEO toolbelt by talking about The Ladder of Inference (detailed article here). This is a great graphic from the article:

Any time you’re struggling with opinions vs. opinions or people are jumping to conclusions based on a narrow set of evidence, this framework is your friend. The best way to start any tricky conversation with those characteristics is to start “at the bottom of the ladder,” meaning you start by reviewing the available data on the topic at hand. As John Adams said, “facts are stubborn things,” so start by agreeing on a common set of irrefutable data on the topic. Then you can take a step up the ladder to a more productive conversation about interpretations, then ultimately come to decisions or conclusions.
Jim Barksdale, the former CEO of Netscape had a great saying that supports this principle, too: “If we have data, let’s look at the data. If all we have are opinions, let’s go with mine.”
The language our team developed around this is easy. It’s like a safe word. Any time someone is jumping to conclusions without being rigorous about the underlying data, they’ll be the recipient of a comment like “wow you went right up to the top of the ladder on that one!” Either that, or someone will pull out a wonderful reference to Office Space.
Book Short: Boards That Lead
Boards That Lead, by Ram Charan, Dennis Carey, and Michael Useem, was recommended to me by a CEO Coach in the Bolster network, Tim Porthouse, who said he’s been referring it to his clients alongside Startup Boards. I don’t exactly belong in the company of Ram Charan (Brad and Mahendra probably do!), so I was excited to read it. While it’s definitely the “big company” version to Startup Boards, there are some good lessons for startup CEOs and founder to take away from it.
The best part about the book as it relates to ALL boards is the framework of Partner, Take Charge, Stay out of the Way, and Monitor. You can probably lump all potential board activities into these four buckets. If you look at it that way…these are pretty logical:
- Monitor – what you’d expect any board to do
- Stay out of the Way – basic execution/operations
- Partner – strategy, goals, risk, budget, leadership talent development
- Take Charge – CEO hiring/firing, Exec compensation, Ethics, and Board Governance itself.
There was an interesting nugget in the book as well called the Central Idea that I hadn’t seen articulated quite this way before. It’s basically a statement of what the business is and how it’s going to win. It’s about a page long, 8-10 bullet points, and it includes things like mission, strategy, key goals, and key operating pillars that underlie the goals. It basically wraps up all of Lencioni’s key questions in one page with a little more meat on the bones. I like it and may adopt it. The authors put the creation of the Central Idea into the Take Charge bucket, but I’d put it squarely in the Partner bucket.
Other than that, the book is what you’d expect and does have a lot of overlap with the world of startups. Its criteria for director selection are very similar to what we use at Bolster, as is its director evaluation framework. The book has a ton of handy checklists as well, some of which are more applicable than others to startups, for example Dealing with Nonperforming Directors and Spotting a Failing CEO.
All in, a good read if you’re a student of Boards.
What Does Great look Like in a Chief Privacy Officer?
Most Chief Privacy Officers are fairly specialized, often coming from a legal or law enforcement background, but regardless of background I’ve found that ideal startup Chief Privacy Officers do three things particularly well.
First, a great Chief Privacy Officer will work to create educated evangelists inside the company. Our Privacy team at Return Path, under Dennis Dayman’s leadership, had a lot of experience and industry certifications, but that experience was not something only for regulators and other companies, or only bragging rights within their team. They also took the time to make sure others in the company, especially in the product management and engineering teams, received some of that same training and those same certifications. By not making the Privacy team a single point of knowledge or failure, Dennis was able to make Privacy part of our product strategy and offense as opposed to a mitigation or defensive function
A second ideal characteristic of a Privacy Officer is that they also handle the basics of InfoSec, in addition to privacy. If you’re actually a security-related company or a massive consumer or financial organization, you may need a dedicated Chief Information Security Officer. If you aren’t, then a good Chief Privacy Officer should be able to handle a number of the functions that a CISO would otherwise handle, especially on the policy and communication front.
And third, a great Chief Privacy Officer is an excellent communicator, both internally and externally, and they help connect you to the relevant members of your community or ecosystem. When we had a sizable data breach on Thanksgiving Day about 10 years ago, our fractional head of privacy, Tom Bartel, was on the spot. He wrote emails and external blog posts that needed almost no review. He was also instantly communicating with dozens of his counterparts at related companies so that the industry knew where we stood and what we were doing about the problem. It was like an instant activation of an emergency response system!
Don’t wait until you have a data breach to hire a great Chief Privacy Officer because by the time you need one it will be too late.
Inquiry vs. Advocacy
My Grandpa Bill used to not want to talk about himself at dinner parties. When one of us asked him why one day, he said, “I already know what I have to say. What I don’t know, is what the other person has to say.”
There are a few principles I learned years ago in a workshop that my coach Marc led for us called Action/Design. I’m going to try writing a few posts about them, and you can find some articles on them here.
Inquiry vs. Advocacy is simple. Understand the balance of when you ask and listen vs. when you speak in a given conversation. Both are important tools in the CEO tool belt.
My rule of thumb is to ask and listen more than you speak. It’s the only way you will learn, collect data on your organization and on your customers and products. Early in your career, you should primarily be Inquiring. Even mid- and later career people who sometimes must be in a position to speak or advocate their point of view benefit most when they ask and listen and learn.
More important, though, Inquiry vs. Advocacy is the best way to guide your communications in a difficult conversation, complex negotiation, or tricky situation. And it’s in those kinds of situations that you actually need to be cognizant that both approaches are important, and you need to know which one to pull out when and pay attention to how others in the conversation are using the two as well. From an article in the resource center I linked to above:
In conversations on complex and controversial issues, when there is a high degree of advocacy and little inquiry, people are unable to learn about the nature of their differences. People may feel the speaker is imposing a view on them without taking into account their perspective, which can lead to either escalating conflict or withdrawal. When there is a high degree of inquiry, but no one is willing to advocate a position, it is difficult for participants to know where the other stands, and the lack of progress can lead people to feel frustrated and impatient. As a participant in a conversation, being aware of the balance of advocacy and inquiry can help you determine how best to contribute at a given time. If you hear that people are advocating but not asking questions, inquire into their views before adding your own. If you hear people asking questions for information but not stating an opinion, advocating your view may help the group move forward.
Inquiry vs. Advocacy has become a cornerstone of how I think about communicating and learning. I like to think I learned it from Grandpa Bill first, but the Action/Design work with my coach, and then years of practice, drove it home.
When to Hire a Chief Privacy Officer
Most startups don’t have a Chief Privacy Officer and just rely on outside advice from external counsel or a privacy consultant. In Startup CXO our Chief Privacy Officer from Return Path, Dennis Dayman, strongly advocates for privacy to be baked into a startup at the very beginning. Some startups probably don’t have any help in this area at all but given the importance of privacy and security issues today that’s a mistake.
If your startup doesn’t start life with a Chief Privacy Officer you’ll have to heed some warning signs and here are some I’ve picked up over the years. First, you’ll know it’s time to hire a Chief Privacy Officer when you wake up in the middle of the night terrified that you’re going to find your company on the front page of the newspaper or served a subpoena to testify before Congress about a data breach. Even if you’re not waking up in the middle of the night you might be concerned about privacy if you are spending too much of your own time trying to understand what PCI Compliance, or HIPAA, or GDPR means to your business. Or if you really don’t see the connections between your business and privacy issues in general, then a Chief Privacy Officer can be very helpful.
You might get tough questions from your board on what your data breach client communication plan is, and if you don’t have a great answer and aren’t sure how to get to one, then it’s time to think about a Privacy Officer.
A fractional Chief Privacy Officer may be the best option for most startups…forever. Sometimes you can find one fractional executive for both the Privacy and Chief Information Security Officer roles. You probably can’t get by without a full-time leader in this area if you are large (>$50mm in revenue) and are sitting on a massive amount of consumer data, especially if that information involves PII, financial, or health information. But if that’s not you, a fractional Chief Privacy Officer may be the way to go. While a fractional executive is similar to an outside lawyer or consultant, an executive has a company title for external credibility and the personal commitment to the organization to ensure compliance. A fractional exeuctive is way more than a consultant since they’ll be able to provide guidance to employees and represent the company as if they were a full-time Chief Privacy Officer.
Not every startup needs a Chief Privacy Officer since you can cover your bases with lawyers or consultants, but if you’re collecting lots of data from jurisdictions across the world you’d be wise to get a Privacy officer, or a fractional executive, sooner rather than later.
Bring People Along for The Ride, Part II of II
Last week, I wrote about Bringing People Along for The Ride by involving people in the process of ideating and creating change in your organization. That’s the most important thing you can do to make it easy for people to handle change.
But what about the people you don’t or can’t bring along for the ride in that way? If you organization has more than 10 people in it, there will inevitably be people where you’re IMPOSING CHANGE ON THEM. And honestly, even people who are involved in designing change still have to live through its impact.
Today’s post is about managing the actual impact.
The best thing you can do as a leader in helping your organization navigate change is to be empathetic to the fact that, even if you involve people in designing the solution, you are, in fact, making changes to their day to day lives. One of the best books I’ve ever read on this is Transitions: Making Sense of Life’s Changes, by William Bridges. And while there’s a lot more to the book than this one point, I’ll share two graphics from the book and its offshoots that say a lot.
Bridges’ basic concept is to think about changes as having three phases. The end of the old thing, the beginning of the new thing, and the time between the two – when the new thing has been announced, but the it hasn’t taken effect yet. Here’s a look at one powerful graphic on this front, where the point is that productivity (the red line) tanks briefly during the time of uncertainty with the overlay of human emotions at each phase.

Next let’s look at Bridges’ model for how to think about these three phases. This part is critical. They are not discrete phases, where everyone finished “ending” and moves onto “neutral” and then moves on to “new.” From the moment a change is in the offing, until after the change is implemented, people are simultaneously operating in all three zones at the same time, in different proportions.

That means when change starts, you’re already helping them understand that there will be a period of confusion followed by a bright new future. And it means that even when the bright new future has arrived, you’re still mindful of the confusion as well as the things that were special about the past.
I wrote about this a little bit in the second edition of Startup CEO and in this blog post on transitions and integration. The paragraph I’ll call out is:
For ourselves as leaders and me as CEO, knowing most of us would leave almost immediately post-deal, I wanted to have as elegant an exit as possible after 20 years. Fortunately, I had a good partner in this dialog in Mark Briggs, the acquiring CEO. Mark and I worked out rules of engagement and expenses associated with “the baton pass,” as we called it, that let our execs have the opportunity to say a proper goodbye and thank you to our teams, with a series of in-person events and a final RP gift pack. This was a really important way we all got closure on this chapter in our lives
The Baton Pass is a helpful analogy to think about this process. In a relay race, the two runners run alongside each other for a little while until they are at the same pace and proper spot, THEN one hands the other the baton. It’s the time when the past and the future collide, in a neutral zone. When you mark the great things and painful learnings that came before and launch into the bright new future.
The best thing you can do as a leader who is driving change through an organization is to Bring People Along for the Ride. Part of that is involving people in the creation of the new world. But it’s also recognizing that humans have to process change, and that takes time.
Bring People Along for The Ride, Part I of II
One of the CEOs I mentor asked me the other day asked me this question:
I need to start making my organization think differently – more like a startup that needs to scale and less like a project. People need to start doing more specific jobs and not swarm all over everything. How do I get people to “get” this without freaking out?
Every CEO faces dilemmas like this all the time.
One of my management mantras over the years has been, “You have to bring people along for the ride.” Fundamentally, that means two things. I’ll write about one of them here today and save the other for next week.
First, bringing people along for the ride means you have to involve the people in the organization in the origins and design of the change you’re seeking to drive.
Let’s face it. No one really likes change. But what people really don’t like is change being IMPOSED ON THEM, especially where THEY DON’T UNDERSTAND WHY.
Without being disingenuous, you as a leader can set the stage for others in your organization helping you with changes — even if you generally know the changes you want to drive. Bring people together. Talk about the challenges you see that are related to the solution you’re contemplating. Get people talking, brainstorming, grabbing post-its and whiteboard pens. Talk a little bit – bring in your perspective and help shape the discussion. But also listen closely and be open to people’s ideas and let those shape the outcome as well.
Then, bring people back for a second and third meeting to then react to some of your idea distillation and even straw man plans. You’ll find that process not only produces a better solution but also makes people comfortable with the solution, because you’ve added more transparency to the equation and brought people along for the ride. Nothing done in the vacuum of the CEO’s mind achieves this same level of impact.
More thoughts on this to come in some related posts over the next couple of weeks around some geeky sounding terms like The Ladder of Inference, Inquiry vs. Advocacy, and Double Loop Learning. Next week’s post will be about how to think about transitions and the way to lead people through them once you’ve involved them in creating the transition. Its link won’t be live until April 20, but it’s here for future reference.
