For Organizations · Operating Model & Product Readiness

I build the Privacy Leader, the organization — and privacy-ready digital products.

I support organizations in building a sustainable privacy function, making digital products ready for privacy and responsible AI use, and — for selected companies — also as an external DPO. The common denominator: clear governance, strong internal ownership and responsibility that actually works inside the organization.

Privacy must work in the organization — and in the product.

I develop the internal Privacy Leader and the ecosystem around them: governance, processes, capable interfaces and digital products whose privacy setup is clear, defensible and ready to scale.

Corporate capability · Product Readiness

Privacy-ready Products

Not just documenting privacy, but setting it up properly in the product.

I join an existing or pre-launch digital product, review the product, UX, data flows and AI use cases, and create clarity around roles, legal bases, consent, transparency and governance. Where relevant, I address profiling, automated decision-making and sensitive data, connect privacy with IT security and TOMs, and build the customer-facing and internal evidence the product needs to scale with fewer privacy surprises.

  • Privacy & AI Product Launch Readiness
  • Data flows, roles & legal bases
  • Consent, transparency & Privacy UX
  • AI use cases, profiling, automated decision-making & sensitive data
  • Processor setup, TOMs & security interfaces
  • Customer, investor & due-diligence readiness
  • Minimum privacy documentation & DPMS foundation
The outcome

A product whose privacy setup can be clearly explained and evidenced to management, customers, procurement and due-diligence teams, and investors.

When this program fits

The first serious build

Privacy has been scattered, project-based or bought in externally. Now it needs to become a function with clear ownership.

Change in the organization

Reorganization, international growth, carve-out or M&A, a change of DPO, bringing external advice in-house — or a tool was introduced without governance behind it.

The person exists, the role doesn't yet

Someone owns privacy on paper, but the role doesn't carry yet. The program builds that person into an internal leader.

A digital product needs to become privacy- and AI-ready

A product is approaching launch, growth, enterprise customers, investor discussions or due diligence. Data flows, roles, legal bases, consent, transparency, AI and sensitive data need to be not only documented, but properly built into the product and explainable to management, customers and investors.

What we build together

Privacy & Responsible AI Governance

Roles, review paths and a workable responsibility split across DPO, Legal, Product, HR, Security, Customer Care and management. Who decides, who reviews, who documents and who carries responsibility — for privacy and responsible AI use.

Privacy management system architecture

Processes and tooling that fit the organization. We first exploit what already exists — SharePoint, Jira, Confluence — before buying expensive specialist tools.

The internal Privacy Leader

Role profile, capability building, training, prioritization, reporting, management communication and personal positioning inside the company.

Organizational enablement

Privacy coordinators in the business units, an internal academy, short trainings, templates and self-service — so ownership sits where the data is processed.

Core processes

DSARs, DPIAs, RoPA, incidents, vendor privacy, deletion, transparency obligations. The focus is process design and governance — not me handling cases indefinitely.

Relationships and boundaries

How privacy works with product, IT security, HR, legal, the works council, customer care and management: joint effort with clear boundaries instead of turf disputes.

Three to six months, with a defined end

  1. 01

    Where you stand

    A clear picture of the organization, roles, processes, tools and risks.

  2. 02

    Target model and governance

    The operating model, the responsibility split and the decision paths.

  3. 03

    Build

    Processes, templates, the coordinator network, the internal academy — and the leader developing in parallel.

  4. 04

    Handover

    Handover, reporting rhythm, a development plan and the open items prioritized.

Privacy does not end after six months — my involvement does. What remains is an organization that can keep going, and a plan for what comes next. Strategic reviews at longer intervals remain possible.

Selected engagements

External Data Protection Officer

Not every organization needs the same model. Sometimes the right next step is a strong internal Privacy Leader. In other constellations, an external DPO function makes sense.

For selected organizations, I also take on the role of external Data Protection Officer. My approach remains the same: the privacy function is not fully outsourced. Business units retain responsibility, internal contacts are enabled and governance remains anchored inside the organization.

  • A strategic DPO function instead of an outsourced privacy department
  • Clear internal ownership and strong points of contact
  • Operating model, product privacy and the DPO role designed as one system

Whether and in what form a Data Protection Officer is formally required is assessed in the specific setup. The organization needs a functioning privacy organization regardless.

What is different afterwards
  • Lower external costs: Internal resources are used strategically instead of permanently outsourcing tasks.
  • Clear ownership: Business units know what they are responsible for — privacy is no longer only the DPO's job.
  • A visible Privacy Leader: One person steers, prioritizes, reports and represents the function to management.
  • Transparent resource use: Leaders understand what the DPMS covers, where effort arises and what capacity is needed.
  • Traceable governance: Roles, decision paths and responsibilities are documented and understandable for management and business units.
  • Joint effort instead of silos: Legal, Product, Security, HR, Customer Care and management work together with clear interfaces.
  • Less reactivity: Recurring topics run through defined processes instead of spontaneous ad-hoc requests.
  • More independence: External advice and tools are used deliberately, not out of structural dependency.
Why me
  • Consulting and in-house: I know data protection from both external advisory and daily responsibility within a company.
  • Start-up to corporate group: I have experienced and built privacy structures across different organization sizes and maturity levels.
  • DPMS from practice: I know what a management system must actually carry in everyday life — not just how it should look in theory.
  • Tool experience: I have contributed to the development of DPMS solutions and know the possibilities and limits of specialized privacy tools.
  • Pragmatic in-house solutions: I have built privacy management with existing general-purpose tools and internal systems instead of automatically buying new software.
  • Maximum use of existing resources: My approach starts with the question: What is already there — people, processes, systems, knowledge — and how can a working model emerge from it?
  • Leader + system thought together: I don't just develop processes, but simultaneously the person who will steer them long-term.
  • Enablement instead of dependency: My goal is not to be needed permanently, but to build an organization that works independently.
Who I usually work with
Management & foundersGeneral Counsels & Legal leadsPeople & HR leadershipCOO, Compliance & Risk

Let's take 30 minutes on where your organization stands today.