Fiyinfoluwa Adeleke

Fiyinfoluwa Adeleke

REGULATORY AND GOVERNANCE LEADERSHIP ACROSS PRIVACY, AI AND DIGITAL REGULATION

I represent organisations before regulators, and build governance across the digital rulebook.

Global regulatory leadership across EMEA, APAC and Latin America
Doctoral researcher, UCD Sutherland School of Law
Dublin, Ireland

ABOUT

I lead international privacy at Yahoo, covering Europe, Asia-Pacific and Latin America, with responsibility spanning regulatory engagement, governance and incident response.

My work runs from building the governance and controls intended to prevent problems, through leading the response when incidents occur, to representing the organisation when a regulator tests whether any of it worked.

I regularly advise the Board on significant regulatory matters, framing the risks and options and making recommendations for decision.

I qualified as a litigator before I became a regulatory lawyer, which is why I am as comfortable in contested proceedings as in advisory work.

I research the regulation of algorithmic decision-making at doctoral level at UCD.

HOW I OPERATE

I translate regulatory obligations into requirements that organisations can build against.

Assessed Yahoo’s advertising pixel against GDPR processor requirements, identified the gaps and produced the product requirements engineering implemented, including an erasure endpoint, enabling the product to operate in full processor mode.

I engage regulators before they come to me.

On CSAM detection I consulted the Data Protection Commission on the approach; on security incidents I report ahead of deadline and engage on the substance rather than filing and waiting.

The governance I build survives independent audit.

At Hertz the programme passed independent audit twice, and the board then widened the scope of its annual audit to include privacy.

CAPABILITIES

01

Regulatory Engagement and Enforcement

I represent organisations before data protection authorities, including in contested regulatory proceedings.

  • Represented Yahoo in contested proceedings before the CNIL’s restricted committee concerning cookie compliance, in which the committee imposed a sanction materially below the rapporteur’s recommendation, and subsequently before the Conseil d’État on appeal.
  • Lead technically complex regulatory investigations end to end, drafting Yahoo’s formal submissions in Data Protection Commission inquiries and appearing in person before regulators in Ireland, France and Italy.
  • Represented both Yahoo entities before data protection authorities following the 2025 separation of the EMEA business, addressing how data was managed and how data subject rights were protected through the restructuring.
02

Regulatory Strategy and Public Policy

With public policy teams, I shape the positions organisations take on digital regulation.

  • Serve as the subject-matter lead Yahoo’s global public policy team relies on when forming the company’s position on EU digital regulation, across platform regulation, competition, ePrivacy and online safety instruments.
  • Represented Yahoo in the European Commission's data sharing consultation under the Digital Markets Act, and before the UK Competition and Markets Authority.
  • Represented Yahoo at an Ibec Technology Ireland industry roundtable on the Irish regulatory landscape, including implementation timelines for instruments such as the e-Evidence package, ahead of Ireland’s 2026 Presidency of the Council of the European Union.
03

Governance and Programme Building

I build privacy and AI governance programmes that stand up to audit, regulatory examination and board scrutiny.

  • Led the privacy workstream on the 2025 separation of Yahoo’s EMEA business, building the governance structure for the newly established entity from the ground up and putting it into operation.
  • Built Yahoo’s privacy and AI governance programme, including committee structures, business-line accountability and mapped controls, and scaled it from Europe into the global template used across all regions including the United States. Designed the governance structure evidencing that key data protection decisions are taken in Ireland, supporting the Irish Data Protection Commission as lead supervisory authority under the GDPR one-stop-shop, and secured formal approval from the Yahoo EMEA Board. Regulatory response time fell by 60 per cent.
  • Led the GDPR compliance programme at Hertz International across global IT systems: discovery and classification of the systems estate, gap analysis, remediation, and a quarterly second-line testing cycle. The programme passed independent audit by Cognizant, retained by the audit committee of the Hertz board in the United States, against plan in December 2017 and against delivery in April 2018. Hertz then expanded the scope of its annual audit to include privacy compliance, conducted by PwC.
04

AI Governance and Algorithmic Accountability

On AI governance and automated decision-making, I advise product and engineering teams, and research the regulation at doctoral level.

  • Led the privacy assessment for a global contactless vehicle rental implementation using facial recognition to authenticate customers and unlock vehicles: evaluated competing identity verification providers, authored the data protection impact assessment, and set the conditions on which deployment proceeded.
  • Advise product and engineering teams on recommender systems, automated processing and emerging model architectures under the EU AI Act and GDPR.
  • Research the regulation of algorithmic credit scoring at doctoral level at UCD Sutherland School of Law, examining how EU law protects individuals against algorithmic discrimination where protected characteristics are inferred rather than processed directly.
05

Trust, Safety and Law Enforcement

The privacy and regulatory brief for online safety, content moderation and law enforcement response sits with me.

  • Act as in-region privacy partner for the Global Trust and Safety team.
  • Led Yahoo’s Digital Services Act transparency reporting, covering law enforcement disclosure practices and right to be forgotten requests, and established the CSAM reporting format.
  • Led the privacy and regulatory workstream for Yahoo’s CSAM detection implementation, authoring the data protection impact assessment, consulting the Data Protection Commission on the approach, and establishing the safeguards and conditions for deployment.
06

Information Security, Incident and Breach Response

I lead the legal and regulatory side of information security, from governance and risk through incident response and regulatory engagement.

  • Led the regulatory response to a cyber attack and resulting personal data breach at a Hertz UK subsidiary, drafting the full breach reporting documentation and conducting the engagement with the Information Commissioner’s Office. The ICO concluded the matter without enforcement action. Also handled the civil claims that followed.
  • Took on Yahoo’s information security governance programme as one of the first business-critical workstreams on joining, establishing the EMEA decision-making framework through which security risk is governed: reporting and escalation routes, documented allocation of responsibilities, and the controller-side governance of Yahoo Inc as processor.
  • Lead the privacy aspects of security incident response across EMEA, owning regulatory assessment and submissions, reporting ahead of deadline and engaging the Data Protection Commission on the substance.

THE DOCKET

MATTERFORUMOUTCOME
Cookie compliance, contested proceedingsCNIL restricted committee, then the Conseil d’État on appealSanction materially below the rapporteur’s recommendation; decision upheld on appeal
Cyber attack and personal data breach, Hertz UKInformation Commissioner’s OfficeConcluded without enforcement action; subsequent civil claims handled
GDPR programme across the global systems estateIndependent audit by Cognizant for the Hertz board audit committeePassed against plan and against delivery; annual audit scope widened to privacy
Separation of Yahoo’s EMEA business, 2025Data protection authorities, both entitiesNew entity’s governance built from the ground up and put into operation
CSAM detection implementationIrish Data Protection CommissionProactive engagement; safeguards and conditions established

RESEARCH

Regulating Algorithmic Credit Scoring and Protecting Data Subjects’ Rights in the EU

UCD Sutherland School of Law · Supervisor: Dr TJ McIntyre

AI credit scoring promises financial inclusion through better prediction, but relies on alternative data that may entrench existing inequality. My research asks whether EU law actually protects people against algorithmic discrimination, across equality law, GDPR, the AI Act and the consumer credit framework. It examines how equality concepts apply when protected characteristics are inferred rather than processed directly, whether transparency obligations are sufficient for discrimination to be detected at all, and what remedies are genuinely available.

→ UCD research profile

SELECTED SPEAKING ENGAGEMENTS

  • Recommender Systems: Practical Challenges in Compliance and Enforcement

    Dentons Privacy Academy · May 2026

  • Innovate & Empower: Responsible AI for a Diverse Future

    AWS Experience · October 2025

  • Recommender Systems: Practical Challenges in Meeting EU AI Act and GDPR Compliance

    Dentons Privacy Academy · April 2025

  • Ad Tech: Managing Compliance in a New First Party (or NO) Cookie World

    Privacy+Security Academy Forum · March 2022

  • Cookies and adtech: preparing your organisation for regulatory risk

    Society for Computers and Law, Annual Data Protection Update · January 2022

CREDENTIALS

Admitted to practise

  • Ireland · Solicitor
  • England & Wales · Solicitor
  • Nigeria · Barrister & Solicitor

Professional

  • IAPP Fellow of Information Privacy (FIP)
  • CIPM · CIPP/E · CDPSE · GRCP · Lean Six Sigma Green Belt

Education

  • PhD Candidate (Part-Time), Law · UCD Sutherland School of Law
  • LLM Information Technology and Intellectual Property Law · University College Dublin
  • LLM Finance and Law · Duisenberg School of Finance, University of Amsterdam
  • BL · The Nigerian Law School
  • LLB · Obafemi Awolowo University

CAREER

Yahoo · Dublin

  • Senior Director, Associate General Counsel, Head of International Privacy · 2022 to present
  • Director, Assistant General Counsel, Global Privacy · 2021 to 2022

Employment transferred to Yahoo International following the 2025 separation of Yahoo’s EMEA business. Responsibility for both entities retained.

Hertz International · Dublin

Director, Senior Privacy Counsel and Head of Privacy · 2017 to 2021

EQUINITI · Amsterdam

KYC/AML Analyst, then Lead Analyst, then Quality Lead, Products and Services · 2014 to 2017

G. Elias & Co., Solicitors and Advocates · Lagos

Associate, Corporate and Commercial · 2011 to 2013

CONTACT

Emailfiyinfoluwa.adeleke@gmail.com
LinkedInlinkedin.com/in/fiyinfoluwaadeleke
Mobile+353 83 043 5545

Dublin, Ireland

© 2026 Fiyinfoluwa Adeleke