Skip to main content
Professional background
Biography image

KimberlyPack

Counsel
Chicago

O 312.998.4262

KimberlyPack

Counsel

Kimberly focuses her practice on assisting organizations in designing their privacy programs and operationalizing applicable privacy, data security, and consumer protection requirements. She has extensive experience in enterprise privacy programs, advising on incident response, technology adoption—including artificial intelligence (AI) and blockchain—marketing and ad tech.

Kimberly has provided privacy guidance to startups, helping them implement best practices and build brand trust. She previously led the global enterprise data protection and privacy program for a Fortune 100 airline. Additionally, she led the U.S. data privacy program for a Fortune 300 beverage manufacturer, overseeing data protection strategy, governance, operations, and training in both roles.

Earlier in her career, she led a compliance team at a Fortune 50 financial services company and was general counsel and compliance officer at a financial services startup.

Focus Areas

Examples of Kimberly’s experience include:

  • Advised clients on a broad range of data protection laws, including the FTC Act, FCRA, GLBA, CAN-SPAM, TCPA, COPPA, CCPA, CPRA, BIPA, and other U.S.-based privacy legislation.
  • Advised on drafting privacy policies and procedures and developing internal compliance programs, including consumer and employee notices; data breach preparation, response, and notification; and employee training.
  • Counseled on data security incidents, including evaluating incidents, assisting with communication, insurance compliance, incident vendor selection, and data breach notification statutes.
  • Advised on marketing strategies and deployment of technology including 1st and 3rd party applications.
  • Advised on the adoption and implementation of new technologies including AI, biometrics, facial recognition, blockchain, and non-fungible tokens (NFTs).
  • Drafted and negotiated service provider agreements and DPAs for compliance with international data protection law compliance, including GDPR, EU Privacy Directive, PIPEDA, ARPPIPS, PIPL, and LGPD among others.
  • “The History of Privacy – Part Two,” Privacy Lawls Podcast, August 2023
  • “Deciphering Regulatory Enforcement Trends,” Consero Chief Privacy Forum, June 2023
  • “Understanding Cryptocurrency and NFTS,” Corporate Counsel Women of Color, October 2022
  • “Managing Privacy Compliance Across Multiple Jurisdictions,” OneTrust TrustWeek, May 2022
  • “Data Protection & Privacy,” Momentum Food & Beverage Exchange Webinar, November 2021
  • “Regulatory Issues Re: Privacy and Accessibility,” Perrin Food & Beverage Conference, October 2021
  • “Emerging Technology Risks,” NetDiligence Cyber Risk Summit, July 2021
  • “New Rules, New Tools: AI and Compliance,” Corporate Counsel Business Journal/H5 Webinar, April 2021
  • “Everything Personal: AI and Privacy,” Corporate Counsel Business Journal/H5 Webinar, March 2021

Professional Organizations

  • Certified Information Privacy Professional/United States (CIPP/US)
  • Certified Information Privacy Manager (CIPM)
  • Certified Six Sigma Green Belt (CSSGB)
  • International Association of Privacy Professionals (IAPP)
  • Women in Security and Privacy (WISP) Advisory Event Board Member Chicago Chapter

Community Activities

  • 2024 UNCF Mastermind Cohort

 

Education

  • Harvard Law School, J.D., 2005
  • Spelman College, B.A., 2002

Bar Admissions

  • Illinois