
.png)
About GRC Privacy
Solutions
About Owen Behle, J.D.
Founder, Data Privacy Officer
Owen Behle is a dedicated data privacy professional with a comprehensive background in the legal, operational, and auditing facets of the field. Holding a Juris Doctor from the Nebraska College of Law, where he graduated with an emphasis in Cyber, Space, and Telecommunications Law, Owen is driven by the conviction that individuals have a fundamental right to control their personal data. His expertise includes a deep understanding of global, sector-specific, and US state privacy laws, including domestic, and privacy laws. While not an exhaustive list, on the global side, he works with regulations like the GDPR, PIPEDA, and LGPD; on the sector-specific side, he works with regulations like HIPAA, GLBA, and COPPA; and on the US state side, he works with regulations like California’s CCPA/CPRA, Utah’s UCPA, and Delaware’s DPDPA. Owen has put this regulatory knowledge into practice across the legal, operational, and auditing domains of privacy in order to build robust, compliant frameworks that mitigate organizational risk and protect sensitive data.

Owen's approach to the legal side of privacy is rooted in his Juris Doctor background and privacy certifications, which have enabled
him to navigate complex frameworks since the GDPR's rollout in 2018. Through GRC Privacy Solutions, he regularly dives deep into regulatory mapping and statutory interpretation, such as parsing California's highly specific record retention requirements for the biotechnology and financial sectors. This foundational knowledge allows him to skillfully analyze regulatory boundaries, review data processing agreements, and draft the critical privacy notices and governance charters that keep clients aligned with the law.
On the operational front, Owen's focus is on transforming statutory requirements into functional, day-to-day reality for SMBs across different business sectors. He has built comprehensive frameworks that modularize governance for emerging fields like AI, neurotech, and biotech to ensure client businesses are operationally sound. In practice, this means going directly into a company's infrastructure to build out the actual workflows for fulfilling DSARs, configuring practical consent management tools using software programs like OneTrust and BigID, and hardwiring data retention schedules directly into internal systems so compliance becomes an automated habit rather than a hurdle.
Furthermore, Owen has conducted extensive data privacy audits across diverse industries by evaluating compliance against numerous standards and frameworks like the NIST Privacy Framework and ISO 27701 Privacy Standards, the HIPAA Privacy Rule, and issuing SOC 2 Type II Privacy reports. This unique combination of legal, operational, and auditing experience makes Owen an invaluable partner in developing, assessing, and maturing your organization's privacy program.
About Michael Lakes
Partner, Head of Business Development
Michael Lakes serves as the Head of Business Development at GRC Privacy Solutions, acting as a dynamic, growth-focused strategist dedicated to scaling the firm. He channels years of diverse professional experience in client relations, regulatory compliance, operations, and strategic talent acquisition to accelerate market expansion. At the core of Michael’s approach is a potent blend of strategy, relationship building, and deal-making. His background across distinct industries has honed an acute ability to understand complex corporate ecosystems and translate that understanding into high-impact growth.
Leveraging his deep background in banking and healthcare, Michael expertly navigates highly regulated, compliance-heavy environments. This domain expertise enables him to identify and capture new market segments where organizations face increasingly stringent, sector-specific data privacy mandates.
Cultivating lasting alignment is one of Michael's primary strengths. Whether collaborating with internal corporate teams to align recruitment with business development goals or advising
.jpeg)
banking clients on long-term financial strategies, Michael has built a career on trust, transparency, and forging long-term strategic partnerships. At GRC, he translates these skills into enduring alliances with enterprises looking to robustly manage global and U.S. state privacy regulations.
An expert in high-stakes environments and full-cycle relationship management, Michael possesses the strategic vision and interpersonal agility required to engage key decision-makers and secure critical growth opportunities. His strong operational background enables him to align complex workflows with client expectations, ensuring seamless delivery at scale. At GRC Privacy Solutions, Michael channels this proactive, results-oriented mindset to consistently unlock new pipelines, establish valuable enterprise connections, and build sustainable revenue streams. By combining a strict commitment to regulatory compliance with a deeply collaborative client approach, Michael ensures the firm remains a trusted, forwardthinking partner in safeguarding corporate data while continuously expanding its market footprint.
