New Governance, Chief Privacy Officers, and the Corporate Management of Information Privacy in the United States: An Initial Inquiry


Kenneth A. Bamberger, Professor of Law, University of California, Berkeley—School of Law, Boalt Hall NA446 MC #7200, Berkeley, CA 94720-7200, USA. Telephone: (510) 643-6218; Fax: (510) 868-2013; E-mail:; Deirdre K. Mulligan, Assistant Professor, School of Information, UC Berkeley, 102 South Hall, Berkeley, CA 94720-4600, USA. Telephone: (510)642-0499; Fax: (510) 642-5814; E-mail:


While the turn from traditional regulation to more collaborative, experimentalist, and flexible forms of governance has garnered significant academic focus, far less attention has been paid to the effects of such “new governance” approaches on regulated firms' understanding of the laws' demands, and on the structures employed within business organizations to meet them. This article targets this analytic gap by examining internal corporate practices regarding consumer privacy, an arena in which the Federal Trade Commission and the states have adopted new governance models. Using data from qualitative interviews with leading corporate Chief Privacy Officers, as well as internal corporate documentation, it examines the way privacy practices have been catalyzed in the shadow of new privacy governance approaches and the combination of regulatory, market, and stakeholder forces they seek to harness. Specifically, it suggests the convergence of a set of practices adopted by privacy officers identified as “leaders,” regarding both high-level corporate privacy management and the integration of privacy into entity-wide risk management goals through technology, decision-making processes, and the empowerment of distributed expertise networks throughout the firm.