Reinbo - consult-V4 (pdf)
Download
After two decades of work at the forefront of the privacy sector, I have built my career around making the intricacies of privacy risk management and data protection services understandable. I enjoy passing on my passion for privacy by translating often complicated legal concepts into sustainable business processes that align with information governance standards.
You'll receive the services of an experienced consultant, speaker, trainer, auditor, negotiator, and project manager. I use my knowledge of data protection laws and information governance to help businesses develop and grow, engage their stakeholders, and deliver real value to my clients. I have also variously played a spoon, aggressive cat, a talking rat, and a seriously upset crowd (voice acting!). He is also rumored to be partly made of broken dreams.
As the Director of the Institute Operational Privacy by Design, I co-host the PICASSO award-winning Serious Privacy Podcast. I have participated in the assessment of Gap Analysis and the subsequent creation of privacy management programmes for a range of organizations, from global enterprises to small and medium-sized businesses. My work has assisted organizations in enhancing their information governance as part of sustainable management systems across various sectors. I have advised and assisted global businesses with numerous projects, including international transfer frameworks, data inventories, rights requests, privacy notices, and other essential data protection services. With a strong specialization in information security, particularly in ISO/IEC 27001, I have aided over 30 organizations in successfully certifying to the standard and served as a BSi assessor to determine if organizations can achieve accredited certification. I also develop and deliver bespoke training materials for privacy and security, serving as an IAPP approved trainer and BCS ISEB course director for Information Security and Data Protection Management courses. My expertise includes utilizing and creating governance frameworks, such as writing Codes of Practice and developing standards for Committees like ISO 27001, ISO 27701, and BS 10012, which are vital for effective privacy risk management. Additionally, I am part of the Management Committee of the UK Data Protection Forum (www.dpforum.org.uk).
Principal Consultant, REINBO Consulting, specializing in data protection services. Principal Consultant, TRUSTe / TrustArc, focusing on information governance. Senior Manager and Principal Advisor for Privacy Risk Management at KPMG. Senior Compliance Solution Specialist at AvePoint, enhancing data protection services. Senior Consultant in IT Governance, ensuring robust information governance. Senior Consultant at Control Risks, providing insights into privacy risk management. Senior Security Consultant at Ultima Risk Management, emphasizing data protection services. Information Security Consultant at QinetiQ, dedicated to information governance. Client Manager/Lead Auditor at British Standards Institute, promoting compliance in data protection services. Group Information Compliance Manager at Metropolitan Housing Group, overseeing privacy risk management. Force Data Protection Auditor for Her Majesty’s Norfolk Constabulary, reinforcing data protection services. Data Protection Officer at North Norfolk District Council, committed to information governance. Telecommunications Technician with Royal Signals, part of Her Majesty's Royal Signals, contributing to data protection services.
(2025) Europrivacy Assessor – Europrivacy Academy
(2025) Europrivacy Implementer – Europrivacy Academy
(2024) AI Governance Professional (AIGP) – IAPP
(2023) Certified Information Privacy Professional (CIPP/US) – IAPP
(2022) Certified Data Protection Officer (ECPC-B DPO) – Maastricht University
(2021) Practitioner Certificate in Data Protection – Course Director - BCS, The Chartered Institute for IT
(2020) CDPSE, Certified Data Privacy Solutions Engineer, ISACA
(2016) Fellow of Information Privacy, International Association of Privacy Professionals
(2015) CIPT, Certificate in Privacy Technologist, International Association of Privacy Professionals
(2014) CIPM, Certificate in Privacy Management, International Association of Privacy Professionals
(2013) AvePoint Compliance Product Specialist and AvePoint Compliance Technical Specialist, AvePoint
(2013) CIPP Europe, Certified Privacy Professional, International Association of Privacy Professionals
(2011) ISO 27002 Implementation Exin course and ISO 27001 Lead Implementer IT Governance
(2010) BS 25999-2 Implementer, IT Governance (now ISO 22301) and ISO 27001 Lead Audit, IT Governance
(2006) Information Security Management Principles, British Computer Society, ISEB (Distinction level)
(2006) Lead Tutor for ISEB CISMP course, British Computer Society
(2006) Planning and Documenting DBsy Risk Assessments, QinetiQ
(2005) BSi Registered Lead Auditor ISO 9001 and ISO/IEC 27001, British Standards Institution
(2004) Diversity Training, Advisory Conciliation and Arbitration Service (ACAS)
(2003) CRAMM IS Risk Management, Mentis Consultancy
(2003) Data Protection Audit Manual Techniques & Methodology, Privacy laws & Business international
(2002) Project Management skills, Design Basics, Human Rights Act for supervisors. These qualifications collectively enhance data protection services and strengthen expertise in information governance and privacy risk management.
Ralph is a trusted advisor on global privacy and security compliance, practices, and management. He believes that effective information governance and robust data protection services enhance business value, helping organizations achieve their objectives and maximize return on investment. In his role, Ralph acts as a senior-level 'translator' between IT, business, and compliance professionals, while also providing thought leadership, business development, partnerships, and product development. His experience encompasses strategic GDPR adoption programs, advisory services, and assurance delivery in global multinational environments.
Before this, he served as an experienced product and services business development lead, principal consultant, and manager, where he delivered training, consultancy, and audit of data protection, business continuity, and information security. He has managed consultancy and audit teams across multiple topics, responding to tenders and delivering solutions proposals. Ralph is also a BSi lead assessor and BCS/ISEB lead tutor in information security management.
His work spans a wide variety of industry sectors with a focus on defense, public sector, pharma, and financial services, representing both multinational corporations and boutique specialist consultancies.
Ralph remains a hands-on practitioner, merging business-level consultancy with training and technical expertise. He has implemented the ISO 27002 code of practice and has repeatedly assessed and implemented ISO/IEC 27001, BS 10012-2, ISO 9001, and BS25999-2 standards, leading to successful certification. Notably, he was responsible for the first global joint 27001/25999 management system to achieve certification.
With a focus on business processes and the protection of information, along with an ethos centered on management assurance, privacy risk management, and knowledge transfer, Ralph continues to ensure effective protection of assets tailored to meet the business needs of his clients.