I support organizations in building a sustainable privacy function, making digital products ready for privacy and responsible AI use, and — for selected companies — also as an external DPO. The common denominator: clear governance, strong internal ownership and responsibility that actually works inside the organization.
I develop the internal Privacy Leader and the ecosystem around them: governance, processes, capable interfaces and digital products whose privacy setup is clear, defensible and ready to scale.
Not just documenting privacy, but setting it up properly in the product.
I join an existing or pre-launch digital product, review the product, UX, data flows and AI use cases, and create clarity around roles, legal bases, consent, transparency and governance. Where relevant, I address profiling, automated decision-making and sensitive data, connect privacy with IT security and TOMs, and build the customer-facing and internal evidence the product needs to scale with fewer privacy surprises.
A product whose privacy setup can be clearly explained and evidenced to management, customers, procurement and due-diligence teams, and investors.
Privacy has been scattered, project-based or bought in externally. Now it needs to become a function with clear ownership.
Reorganization, international growth, carve-out or M&A, a change of DPO, bringing external advice in-house — or a tool was introduced without governance behind it.
Someone owns privacy on paper, but the role doesn't carry yet. The program builds that person into an internal leader.
A product is approaching launch, growth, enterprise customers, investor discussions or due diligence. Data flows, roles, legal bases, consent, transparency, AI and sensitive data need to be not only documented, but properly built into the product and explainable to management, customers and investors.
Roles, review paths and a workable responsibility split across DPO, Legal, Product, HR, Security, Customer Care and management. Who decides, who reviews, who documents and who carries responsibility — for privacy and responsible AI use.
Processes and tooling that fit the organization. We first exploit what already exists — SharePoint, Jira, Confluence — before buying expensive specialist tools.
Role profile, capability building, training, prioritization, reporting, management communication and personal positioning inside the company.
Privacy coordinators in the business units, an internal academy, short trainings, templates and self-service — so ownership sits where the data is processed.
DSARs, DPIAs, RoPA, incidents, vendor privacy, deletion, transparency obligations. The focus is process design and governance — not me handling cases indefinitely.
How privacy works with product, IT security, HR, legal, the works council, customer care and management: joint effort with clear boundaries instead of turf disputes.
A clear picture of the organization, roles, processes, tools and risks.
The operating model, the responsibility split and the decision paths.
Processes, templates, the coordinator network, the internal academy — and the leader developing in parallel.
Handover, reporting rhythm, a development plan and the open items prioritized.
Privacy does not end after six months — my involvement does. What remains is an organization that can keep going, and a plan for what comes next. Strategic reviews at longer intervals remain possible.
Not every organization needs the same model. Sometimes the right next step is a strong internal Privacy Leader. In other constellations, an external DPO function makes sense.
For selected organizations, I also take on the role of external Data Protection Officer. My approach remains the same: the privacy function is not fully outsourced. Business units retain responsibility, internal contacts are enabled and governance remains anchored inside the organization.
Whether and in what form a Data Protection Officer is formally required is assessed in the specific setup. The organization needs a functioning privacy organization regardless.