For Organizations · Privacy Operating Model Program

I build a privacy organization with you — one your company can carry on its own.

A time-boxed build & enablement program — not an open-ended consulting retainer. In three to six months we create the roles, decision paths, processes and the internal Privacy Leader who runs the function afterwards.

A privacy management system is not a tool. It is an operating model.

For individuals, I build the Privacy Leader. For organizations, I build the environment in which Privacy Leadership works.

When this program fits

The first serious build

Privacy has been scattered, project-based or bought in externally. Now it needs to become a function with clear ownership.

Change in the organization

Reorganization, international growth, carve-out or M&A, a change of DPO, bringing external advice in-house — or a tool was introduced without governance behind it.

The person exists, the role doesn't yet

Someone owns privacy on paper, but the role doesn't carry yet. The program builds that person into an internal leader.

What we build together

Privacy Governance

Roles, decision paths and a workable responsibility split across DPO, Legal, Product, HR, Security, Customer Care and management. Who decides what — written down, not assumed.

Privacy management system architecture

Processes and tooling that fit the organization. We first exploit what already exists — SharePoint, Jira, Confluence — before buying expensive specialist tools.

The internal Privacy Leader

Role profile, capability building, training, prioritization, reporting, management communication and personal positioning inside the company.

Organizational enablement

Privacy coordinators in the business units, an internal academy, short trainings, templates and self-service — so ownership sits where the data is processed.

Core processes

DSARs, DPIAs, RoPA, incidents, vendor privacy, deletion, transparency obligations. The focus is process design and governance — not me handling cases indefinitely.

Relationships and boundaries

How privacy works with product, IT security, HR, legal, the works council, customer care and management: joint effort with clear boundaries instead of turf disputes.

Three to six months, with a defined end

  1. 01

    Where you stand

    A clear picture of the organization, roles, processes, tools and risks.

  2. 02

    Target model and governance

    The operating model, the responsibility split and the decision paths.

  3. 03

    Build

    Processes, templates, the coordinator network, the internal academy — and the leader developing in parallel.

  4. 04

    Handover

    Handover, reporting rhythm, a development plan and the open items prioritized.

Privacy does not end after six months — my involvement does. What remains is an organization that can keep going, and a plan for what comes next. Strategic reviews at longer intervals remain possible.

In selected cases I also take on an external DPO mandate afterwards. That is an option, not part of the program.

Whether or not you need a formally appointed DPO, you need a functioning privacy organization.

What is different afterwards
  • Lower external costs: Internal resources are used strategically instead of permanently outsourcing tasks.
  • Clear ownership: Business units know what they are responsible for — privacy is no longer only the DPO's job.
  • A visible Privacy Leader: One person steers, prioritizes, reports and represents the function to management.
  • Transparent resource use: Leaders understand what the DPMS covers, where effort arises and what capacity is needed.
  • Traceable governance: Roles, decision paths and responsibilities are documented and understandable for management and business units.
  • Joint effort instead of silos: Legal, Product, Security, HR, Customer Care and management work together with clear interfaces.
  • Less reactivity: Recurring topics run through defined processes instead of spontaneous ad-hoc requests.
  • More independence: External advice and tools are used deliberately, not out of structural dependency.
Why me
  • Consulting and in-house: I know data protection from both external advisory and daily responsibility within a company.
  • Start-up to corporate group: I have experienced and built privacy structures across different organization sizes and maturity levels.
  • DPMS from practice: I know what a management system must actually carry in everyday life — not just how it should look in theory.
  • Tool experience: I have contributed to the development of DPMS solutions and know the possibilities and limits of specialized privacy tools.
  • Pragmatic in-house solutions: I have built privacy management with existing general-purpose tools and internal systems instead of automatically buying new software.
  • Maximum use of existing resources: My approach starts with the question: What is already there — people, processes, systems, knowledge — and how can a working model emerge from it?
  • Leader + system thought together: I don't just develop processes, but simultaneously the person who will steer them long-term.
  • Enablement instead of dependency: My goal is not to be needed permanently, but to build an organization that works independently.
Who I usually work with
Management & foundersGeneral Counsel & Legal leadsPeople & HR leadershipCOO, Compliance & Risk

Let's take 30 minutes on where your organization stands today.