
Sooji Seo serves as 3M's Senior Vice President and General Counsel, Information & Digital, and Chief Privacy Officer, overseeing the legal support for privacy, digital, AI, cybersecurity, records management, and information governance. Working closely with 3M's IT and cybersecurity senior leadership and key stakeholders, 3M's global legal and privacy compliance team provides strategic guidance to address 3M's enterprise legal and regulatory risks.
Before 3M, Sooji worked for Dell Technologies for 15 years, advising Dell's senior management on global consumer protection and technology laws, including AI, enterprise privacy, cybersecurity, corporate crisis response, and trade compliance regulatory risk management.
Sooji has served on the International Privacy Professional Board (Asia) and chairs the Minnesota Future of Privacy Forum Chief Privacy Officers Board. She is passionate about growing talent and promoting an inclusive culture, and serves as Executive Sponsor of 3M's Asians in Action Employee Resource Network Group and Legal Affairs' Community and Service Committee.
Before joining Dell in 2007, Sooji was the Asia Pacific General Counsel of Hunter Douglas and Chubb Fire Safety and Security, and practiced law at various international law firms.
Sooji received her Bachelor of Computer Science and Mathematics degree from the University of New South Wales (Australia) and graduated from the University of Technology Sydney School of Law, summa cum laude. She is admitted to the Minnesota, Australian, Singapore, and England bars.
Q: Tell us your path to your current role as SVP, General Counsel – Information, Digital, and Chief Privacy Officer at 3M.
A: My path to my current role as SVP, General Counsel – Information, Digital, and Chief Privacy Officer at 3M has been shaped by a focus on technology, data, and privacy, as well as practical legal leadership in complex business environments and the rapidly changing digital landscape.
Q: You were educated and trained as a lawyer at leading universities in Australia, and early in your career you began building a global profile in environments where U.S.-centric hiring norms often dominate. How did you think about positioning and messaging your education and early training, and how, if at all, did being a foreign-trained lawyer shape the opportunities or challenges you encountered?
A: I would position my foreign legal education and early training as a strength: they gave me a comparative perspective, disciplined legal analysis, and the ability to work across diverse legal and business cultures. Being foreign-trained posed challenges, including learning a new legal market and building credibility, but it also created opportunities to advise on cross-border matters and to bring a broader perspective to key stakeholders, including clients and teams.
Q: Your first move in-house marked a significant transition after years in private practice. Looking back, what did you expect that move to be like, what was the reality, and what do you wish you had known, or done differently, before making that leap?
A: I expected the transition from private practice to an in-house role to mean being closer to the business and more involved in strategic decisions, and that has been true. The reality was that the role also required quicker judgment, stronger prioritization, and a broader commercial perspective than I had anticipated. I learned that being effective in-house means providing practical, smart, risk-based legal advice, building trust and credibility with stakeholders, and recognizing that the best legal answer is often the one that helps the business move forward responsibly and ethically.
Q: You've held roles where you were both a deep subject-matter expert in privacy and a segment or regional General Counsel with broad commercial responsibility, including serving as Head of Legal for Dell Technologies Australia and New Zealand. How does being a segment GC differ from being a functional expert, and how do you balance those responsibilities when they intersect?
A: As a segment GC, I focus on understanding the business, anticipating legal and strategic risks, and helping leadership make practical decisions in real time. As a functional expert, I delve into a specific area of law or process and help ensure consistency, quality, and best practices across the organization. I balance those responsibilities by staying close to the business and the legal department's strategic priorities, being clear about which role I am playing in a given situation, and partnering with wonderful colleagues to ensure urgent segment needs are addressed while functional standards are maintained.
Q: As your scope expanded from functional leadership into enterprise-wide legal, privacy, and compliance leadership, how has your leadership style evolved, particularly when managing highly matrixed, global teams?
A: My leadership style is evolving to become more intentional, adaptive, and collaborative. When managing highly matrixed, global teams, I focus on setting clear priorities, aligning stakeholders, communicating transparently, and empowering team members to make decisions while maintaining accountability to shared goals.
Q: Many of your roles required influencing senior business leaders, boards, and global stakeholders without formal authority. In reality, most of the behaviors a Chief Privacy Officer needs to shape sit outside their reporting line. What approaches have you found most effective in building credibility and alignment across regions, cultures, and leadership styles?
A: I build credibility by listening first, understanding priorities and cultural context, and consistently following through on commitments. Without formal authority, I focus on creating alignment through shared goals and transparent communication, while adapting my approach to leadership styles and ensuring everyone understands the common objective.
Q: Almost every CPO candidate says that their top priority in the first 90 days is “forging relationships.” In practice, that phrase can mean very different things. What does it actually mean to you? Is it meeting people socially, or is there something more deliberate and operational behind it, and what does effective relationship-building look like in concrete terms?
A: In the first 90 days, relationship-building means establishing trust, credibility, and clear communication with key stakeholders. Operationally, it looks like listening first, understanding priorities and pain points, setting regular touchpoints, following through on commitments, and creating practical working rhythms that make collaboration easier and more effective.
Q: Privacy, ethics, and compliance leaders are often viewed as either blockers or rubber stamps. What practical advice would you offer for becoming a trusted business partner while still preserving independent judgment and integrity?
A: I would focus on understanding the business, being responsive and practical, and giving clear, risk-based advice that helps colleagues achieve their objectives. At the same time, I would maintain independent judgment by being candid about legal and ethical risks, escalating concerns when necessary, and never compromising integrity for convenience.
Q: You've moved across multiple industries over the course of your career, from private practice to technology, cybersecurity, and now diversified science and manufacturing. What leadership principles or legal fundamentals have you found to be truly industry-agnostic?
A: I rely on industry-agnostic fundamentals: sound judgment, integrity, accountability, practical risk assessment, effective communication, and a strong understanding of core legal principles, including contracts, governance, compliance, confidentiality, and dispute prevention.
Q: Conversely, what differences between industries surprised you the most, and what would you intentionally prepare for differently if you were entering a new sector today?
A: I've found that the biggest surprises are often the differences in terminology, decision-making pace, risk tolerance, and regulatory or commercial norms. When entering a new sector, I prepare by doing targeted research, speaking with people who know the industry, learning the key business drivers, and staying curious enough to ask practical questions early.
Q: Having built and scaled global privacy and compliance programs, how do you personally measure success? What tells you that a program is not only compliant, but durable, trusted, and embedded in the business?
A: I measure this by looking for evidence that the program operates consistently across jurisdictions, keeps pace with key regulatory and critical business changes, earns stakeholder confidence, and is integrated into day-to-day decision-making rather than existing only as a policy framework.
Q: Your career reflects a steady progression into increasingly competitive and prestigious leadership roles. What do you focus on to continually demonstrate value as a senior legal and privacy leader as expectations become more enterprise-driven?
A: I continually demonstrate value by aligning legal and privacy strategy with enterprise priorities, proactively identifying risk, enabling responsible growth, and partnering cross-functionally to deliver practical and high-quality, business-oriented legal solutions.
Q: Privacy leaders often talk about the importance of “having a seat at the table,” but that phrase can be ambiguous. What does it actually mean in practice? How can a leader tell whether a role truly has a seat at the table versus symbolic access, and if you're a privacy leader today, how do you go about earning one?
A: To me, having a seat at the table means being involved early enough to shape decisions, not just being asked to approve them at the end. Real influence shows up when privacy advice changes priorities, product design, risk appetite, or go-to-market plans. Symbolic access means privacy is present in meetings and is a key stakeholder when decisions are made. Privacy leaders earn that role by understanding the business, offering practical options rather than only objections, building trust with legal, cybersecurity, IT, and commercial teams, and consistently demonstrating how privacy can enable responsible growth.
Q: When pursuing opportunities internationally, organizations often show a preference for local candidates. How have you navigated that dynamic to build a truly global career, and what advice would you give others facing similar barriers?
A: I focus on showing the value I can add beyond being non-local: relevant expertise, adaptability, cultural awareness as a global citizen, and a clear commitment of being a trusted advisor. I also build relationships early, tailor my materials to the local context, and stay open to roles that create a pathway into the region. For a global career, I would advise developing portable skills, seeking international experience, learning how different markets operate, and building a network before you need it.
Q: For experienced privacy or regulatory lawyers who aspire to broader General Counsel or enterprise leadership roles, what capabilities or experiences do you believe are most critical to build early and intentionally?
A: I would focus on building business fluency, strategic judgment, financial literacy, people leadership, and international operating experience. Privacy and regulatory lawyers should seek opportunities to advise on enterprise risk, product strategy, commercial priorities, governance, crisis response, and board-level decision-making so they are seen not only as subject-matter experts but as leaders who can help make business transformation real.
Q: You have recruited, developed, and mentored leaders who have gone on to hold highly sought-after roles, including guiding talent into first-time Chief Privacy Officer positions at public Fortune 500 companies. What is your approach to identifying, developing, and preparing talent for that level of responsibility?
A: I identify high-potential privacy professionals by assessing their legal and regulatory judgment, business acumen, leadership capability, and ability to influence cross-functional stakeholders. I then develop them through stretch assignments, mentoring, exposure to executive decision-making, and opportunities to lead complex privacy and legal initiatives, while preparing them for senior roles by building succession plans and ensuring they have experience managing risk, teams, and strategic privacy programs that adds value to the business.
Q: What do you believe distinguishes leaders who consistently develop strong successors and high-performing teams from those who struggle to do so?
A: I believe the difference is intentionality: leaders who develop strong successors and high-performing teams invest in people, delegate meaningful responsibility, give clear and real-time feedback, and create opportunities for others to lead, while those who struggle often focus too narrowly on their own execution rather than building capability around them.
Q: What are you working on that you're excited about?
A: I'm especially excited about how AI will transform how legal and privacy services will be provided at the speed of the business.
Q: What are you working on that worries you?
A: I would rephrase the question to focus on the challenges we need to stay ahead of. In this rapidly changing digital era, where data is a critical asset, it's important that legal and privacy professionals lean in and build AI proficiency so they can provide practical legal solutions that unlock the power of AI responsibly and securely, with embedded data privacy protections.
Q: Any other closing thoughts you'd like to share?
A: I am proud of the work we are doing at 3M and grateful for the opportunity to contribute. I look forward to continuing to learn, collaborate, and make a positive impact in the community where I live and serve.
Christopher Y. Chan is General Counsel of JLL Technologies (JLLT), leading legal strategy...
Read MoreAs part of our Captains of Industry Interview series, Lawrence Brown, Sr. VP Legal, Houst...
Read MoreIntroduction & Background Q: You’ve had an extraordinary career spanning the privat...
Read More