Rainier (Ram) Milanes

Focus profile

Privacy and AI governance

Privacy operations, data protection, and AI-governance work emphasizing privacy-risk assessment, privacy by design, and incident process, with current applied evidence through human-reviewed Shadow AI review.

Competencies

What this track emphasizes

  • Privacy operations
  • Privacy-risk assessment
  • Privacy by design
  • Data protection and compliance
  • Incident and remediation process
  • AI governance
  • Human-reviewed responsible-AI controls

Featured evidence

PrivAI Guard

Privacy-risk triage, data-subject impact review, and human-reviewed routing.

Featured project

PrivAI Guard

Shadow AI privacy-risk triage · 2026

A cloud-deployed full-stack Shadow AI governance MVP that converts potentially risky AI use into structured risk assessment, governance review, remediation, and audit evidence.

Northwestern University MSIS capstone MVP. Non-production. Synthetic demonstration data only. Human governance review — not automated legal or regulatory decisioning.

Read the PrivAI Guard case study

Experience

Selected roles

RAM Privacy & Security

October 2024Present

Principal Consultant

  • Assess cybersecurity, privacy, and technology-risk issues for regulated and high-risk organizations and translate findings into governance, control, and remediation work.
  • Conduct risk assessments and translate findings into prioritized remediation actions, implementation roadmaps, and measurable controls.

National Privacy Commission

October 2024January 2026

Innovation and Transformation Consultant

Designated Chief Information Technology Officer

  • Assessed cybersecurity, technology-risk, and information-security issues and advised on control implementation and critical-infrastructure protection.
  • Assessed cybersecurity, privacy-compliance, and technology-risk issues and advised on control implementation and critical-infrastructure protection.

National Privacy Commission

March 2021September 2024

Chief, Compliance and Monitoring Division

  • Led compliance monitoring, breach-notification processing, registration, compliance support, and regulatory reporting operations.
  • Conducted and oversaw privacy, security, technology, and compliance assessments across high-volume operational workflows.

Bankmer Realty Corporation

January 2017July 2020

Director of Operations & Data Protection Officer

  • Established the organization’s first Privacy Management Program, including privacy governance, policies, security procedures, data-handling standards, employee training, and accountability controls.
  • Conducted privacy and operational risk assessments and translated findings into corrective actions and improved data-governance practices.

Bankmer Realty Corporation

March 2015December 2016

Corporate Counsel / Facilities Manager

  • Planned IT and information-security improvements and digitalized corporate records to protect confidential organizational information.
  • Coordinated technology vendors, contracts, regulatory requirements, and implementation activities involving confidential organizational information.

Credentials

Relevant credentials

Education

Master of Science in Information Systems, Security Specialization

Northwestern University · 2026

Coursework includes Information Security Management; Information Security Strategy; Cybersecurity Attacks & Countermeasures; Disaster Recovery & Business Continuity; Artificial Intelligence; Machine Learning; Spec-Driven Software Development; and Project Management.

Certification

Certified Information Privacy Manager (CIPM)

IAPP

Certification

Certified in Cybersecurity (CC)

ISC2

Licensure

Licensed to Practice Law in the Philippines

Supreme Court of the Philippines / Integrated Bar of the Philippines

This is Philippine legal licensure. It does not imply U.S. bar admission or authorization to practice law in the United States.

Writing

Selected writing

White paper · 2026

Privacy-Preserving Machine Learning in Global Healthcare AI: Breaking the Clinical Validation Bottleneck Without Breaking the Law

A governance and architecture white paper examining how Federated Learning, Differential Privacy, and Fully Homomorphic Encryption can support clinical AI validation while reducing unnecessary movement of regulated health data. The paper connects privacy engineering, cybersecurity, clinical evidence, patient agency, infrastructure equity, and audit-ready governance.

Also available: Cybersecurity / GRC

Start a conversation

Email and LinkedIn are the public contact channels.