Skip to Main Content
Overview

Heidi draws on her notable background as one of the first U.S. attorneys focused on data privacy and cybersecurity, as well as her experience as a corporate executive, to advise clients on matters involving consumer and employee privacy, data protection, cybersecurity, data ethics, and artificial intelligence.

Heidi counsels clients on a wide range of  laws, regulations, and standards, including the California Consumer Privacy Act (CCPA), Family Educational Rights and Privacy Act (FERPA), EU and U.K. General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Fair Credit Reporting Act (FCRA), Gramm-Leach-Bliley Act (GLBA), and National Institute of Standards and Technology (NIST) frameworks, as well as various U.S. state laws and regulations touching on healthcare and financial privacy, biometrics, and information security. In a world where data protection touches every organization, her work spans a wide array of industries.

Heidi also helps clients address emerging issues in artificial intelligence, guiding the development of corporate AI policies, advising on specific use cases, and helping organizations protect confidential data that might not be covered by traditional privacy laws. In addition, she regularly advises on cybersecurity risks from a legal perspective and is working toward certification as an AI Governance Professional.

Heidi first began her career as a litigator. While working full-time, she pursued an LL.M. in intellectual property at George Washington University, completing all the necessary coursework and lacking only her thesis to complete the degree. Her early work with technology companies evolved to focus on data privacy, leading to an in-house role at Sprint Nextel which combined intellectual property and privacy-related responsibilities. She later advised clients at several major law firms and held executive positions at two large multinational corporations, Thomson Reuters and Leidos. In these positions, Heidi was part of the in-house legal team while also managing the practical, day-to-day aspects of privacy operations. At Leidos, she established and led the company’s global privacy office and, along with her team, developed a first-in-class corporate data protection program. She also held leadership positions on various executive committees, including the Data Governance Steering Committee.

Heidi’s experience gives her a unique perspective: she has “been in clients’ shoes” and personally understands the realities of business leadership. At the same time, she’s practiced data privacy, cybersecurity, and intellectual property law for more than 20 years and is passionate about staying current on the constant changes in these evolving fields. In practice areas where applicable law often lags behind technology, Heidi has the experience not only to help clients comply with current laws, but to anticipate what’s coming next.

Industries

Services

Education

  • J.D., University of Baltimore School of Law
  • B.A., McGill University

Admissions

  • District of Columbia
  • Maryland

Professional Memberships and Certifications

  • Certified Information Privacy Professional/U.S. (CIPP/US)
  • Certified Information Privacy Manager (CIPM)
  • Certified Information Privacy Professional /Europe (CIPP/E)
  • International Association of Privacy Professionals (IAPP); Diversity in Privacy Board, 2021-2023; KnowledgeNet DC Chapter, 2012-2015; Publications Advisory Board, 2009-2011
  • U.S. Chamber of Commerce, Global Information Security Working Group and Global Privacy Working Group, 2016-2017
  • Software Information Industry Association (SIIA), 2014-2017

Languages

  • French, conversational
Experience
  • Established and led first global privacy office function for a $13.7B company.
  • Developed numerous data protection programs adaptable to ever-changing privacy and data protection laws for U.S. and multinational companies.
  • Negotiated approximately 150 data processing, data sharing, data transfer, software licensing, and HIPAA business associate agreements.
  • Advised c-suites, GCs/AGCs, CIOs, CISOs, HR executives, and business unit leaders at roughly 150 companies, ranging from start-ups to Fortune 50 companies, as well as regional and national 501(c)(3) organizations.
  • Served as executive co-chair of data governance, data loss prevention, records retention, and data ethics governing councils and working groups at two large multinational companies.
  • Counseled clients in the aftermath of 100+ data breaches and data security incidents.
  • Represented clients in matters involving the California Invasion of Privacy Act (CIPA).
  • Advised clients on AI and data ethics.
  • While serving as vice president of a multinational conglomerate, helped build a global data protection program supporting five global businesses and 25+ internal entities across the EU, U.S., Australia, Canada, Asia, Australia, and Latin America.
  • Guided clients' business and legal decisions related to numerous privacy and data protection laws and standards such as the GLBA; HIPAA; EU data protection laws; FCRA; Electronic Communications Privacy Act (ECPA); Digital Millennium Copyright Act (DMCA); PCI-DSS; NIST Privacy, Cybersecurity, and AI Frameworks; and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
Outside the Office

Heidi loves to hike and stay active. She regularly teaches group fitness classes and enjoys connecting with others through fitness.

Most of all, Heidi loves spending time with her two rescue dogs and family.

Community Leadership

Heidi is passionate about animal rescue and volunteers with local rescue organizations, such as Lost Dog and Cat Rescue in Falls Church, Virginia and Homeward Trails Rescue in Fairfax Station, Virginia. She also provides remote support, from time to time, to Puerto Rican animal rescue organizations.

In-House Counsel Experience
  • Sallie Mae, Deputy Privacy Officer & Compliance Director, 2025
  • Leidos, Chief Privacy Officer, 2017-2022
  • Thomson Reuters, Vice President & Senior Privacy Officer, 2013-2017
  • Sprint Nextel Corporation; Special Counsel & Director, Privacy & Intellectual Property, 2003-2005; Senior Counsel & Director, Privacy, 2005-2006