Author

Donal Nugent, journalist

If there’s one word Tom Hyland FCCA often circles back to in conversation about his role it’s ‘trust’. As director at KPMG Ireland’s enterprise risk services practice, Hyland works at the centre of a 250-strong specialist team helping organisations strengthen governance, risk management and compliance in an evolving digital privacy landscape.

The goal is, naturally, to support regulatory compliance but also, he says, 'to help our clients build trust with their customers'. Hyland sees the General Data Protection Regulation (GDPR), which became directly applicable across the EU in 2018, as foundational to much of this, representing a legislative milestone that has reshaped how organisations handle personal data both in Europe and around the world.

‘Design your processes and view your risk landscape with trust in mind’

The CV

2020
Appointed director, risk and regulatory consulting, KPMG Ireland

2013
Appointed head of audit at AIB’s business and corporate banking, property lending and strategic solutions unit

2010 
Joins PwC in London as a Senior Manager, Banking Capital Markets with responsibility for Model Risk Management.

2005 
Joins EY in New York, rising to manager of risk advisory services specialising in Model Risk Management and Internal Audit.

2003
Completes ACCA qualification

‘GDPR is probably one of the most significant pieces of regulation ever implemented at an EU-wide level,' he says. 'It also connects with what the public wants. Companies focused solely on meeting their obligations may lose sight of the benefits that come from robust and clear messaging about protecting personal data, as well as being upfront and honest when things go wrong.' The learning from experience, he says, is that 'you need to design your processes and view your risk landscape with trust in mind: trust for the customer, trust for your own employees and trust for the brand you have. The right practices and controls are key to building those trusting relationships.'

Shaping perspective

Hyland moved to KPMG in 2020, after spending three years as head of audit at AIB’s business and corporate banking division. ‘When I look at my career today, it sits at the intersection of compliance, technology, regulation and trust,’ he says. That internal audit experience proved especially valuable because ‘it taught me to understand how organisations make decisions, where risk crystallises and how assurance can support better governance. With internal audit, you get a privileged view of where the key risks lie within an organisation.'

Time spent in New York and London has also helped shape his worldview, as well as providing early proof of the credibility of the ACCA qualification. ‘As soon as I completed my ACCA exams in 2003, I headed straight to the US. My first role was as an insurance agent broker in New York. That gave me a bedrock of understanding in two important areas: how to assess risk and how to sell.’

Attending an ACCA networking event led to him joining a professional services firm in the heart of Manhattan. In subsequent years, he worked across a gamut of banking and capital markets-based clients in New York and London before returning to Ireland. ‘ACCA was definitely a passport and the credential that opened doors,’ he says. Recently joining the ACCA Ireland panel for large enterprises, he is ‘looking forward to contributing with both my current role and my previous experience in mind’.

Comfort required

A 2025 survey by the Data Protection Commission found 76% of respondents were concerned about their personal data being shared, sold or traded online. How does Hyland’s experience in the sector shape his response to those concerns?

‘I think everyone should be aware of where and how their personal data is being processed,’ he says squarely. ‘We rightly expect that our personal data is held as securely as possible, in a way that we understand and that it is clear to us. There are mechanisms within GDPR to request copies of our personal data from organisations. For me, if companies are not clear about their approach, always ask the question. If you don’t get the level of comfort or detail you expect in the reply, then ask yourself "do I trust this organisation with my data?”.'

 

‘The more meaningful interactions you have, the greater benefits to you and those around you'

Hylands says clarity of action is as important as clarity of purpose when it comes to best practice. ‘Organisations often spend a lot of effort and time putting elaborate policies and procedures in place – and then put those polices on a shelf where no one knows about them. Individuals at every level of an organisation need to understand what their role is if an information breach happens.’

It won’t be a surprise that AI is a growing presence on Hyland’s in-tray. While he understands and shares enthusiasm for the technology’s ability to automate and improve processes, he is also clear that it ‘creates new questions in terms of risk. Guardrails and knowledge of what data the AI agents access along with the human-in-the-loop roles is critically important. If AI is being used, it needs to be switched on with the right layers of governance, accountability, training and control in place. To coin an old phrase, once the genie leaves the bottle, it is impossible to get it back in.’

The value of interaction

Today living in Co. Meath, Hyland also positions work-life balance among his top priorities. ‘I spend all my free time with my family. My kids play a lot of sports, so I am an active sideline dad. I show up where I can, and I try to make as many of the games as possible.’

What he has come to appreciate over the years, he says, is ‘the opportunity to build relationship networks, at every level, whether in your career or socially. Every day is a learning day, and the more interactions you have, the greater the benefit to you and those around you.’

Privacy risks

Current priority privacy risk domains include:

  • AI and large language model governance, including transparency, lawful basis, data minimisation and safeguards for model training and deployment
  • data breaches and operational security failures, including phishing, misdirected correspondence and weak incident response
  • third-party, cloud and cross-border data processing risks, including international transfers and reliance on complex technology supply chains
  • poor execution of privacy-by-design controls, particularly where new products, AI agents or analytics tools are deployed at speed
  • data subject rights and transparency failures, including delays or weaknesses in access, erasure and fair processing responses.

Emerging privacy risks and regulatory trends include:

  • personal data being used to train or fine-tune AI models without sufficient transparency, lawful basis or individual expectation
  • AI models retaining, inferring or exposing personal data through outputs, prompts, model inversion or extraction attacks
  • automated decision-making and profiling risks where AI outputs influence financial, employment, health, education or customer-service decisions
  • children’s data, biometric data and other vulnerable data subjects receiving greater regulatory attention
  • increased scrutiny of the interaction between GDPR, the EU AI Act, the Digital Services Act, the Data Governance Act and other digital regulation
  • greater cooperation among European data protection authorities and more coordinated enforcement on cross-border technology and AI use cases.
Advertisement