Privacidade · Proteção de Dados · Governança de IA
Consultoria independente em privacidade e DPO como Serviço — para organizações que navegam exigências de GDPR, LGPD e governança de IA.
What I do
From governance frameworks to operational controls, I help organisations translate regulatory obligations into workable practice — across GDPR, LGPD, and AI governance requirements.
Compliance
Structured compliance programmes covering legal basis mapping, data flows, contractual arrangements, and accountability documentation.
DPO Services
Fractional or full DPO function — programme oversight, regulatory liaison, incident coordination, and ongoing advisory support without the overhead of a full-time hire.
Risk
Risk-based analysis of processing activities, vendor relationships, and third-party transfers — grounded in enforcement trends and regulatory guidance, not generic checklists.
Governance
Design and implementation of accountability structures, privacy-by-design practices, and governance documentation that withstand regulatory scrutiny.
Emerging Tech
Advisory on AI Act compliance, biometric data governance, algorithmic risk assessment, and responsible AI implementation in data-driven organisations.
Cross-Jurisdictional
Specialist advisory for organisations operating across the EU and Brazil — comparative regulatory analysis, alignment strategies, and cross-border transfer frameworks.
About
I advise organisations on data protection and AI governance — from programme design to day-to-day operational decisions.
My work covers GDPR and LGPD compliance, privacy governance frameworks, DPIAs, legitimate interest assessments, vendor due diligence, and AI governance advisory. The focus is always on what the regulatory framework actually requires — not on documentation that looks right but does not hold up.
Academic background in data protection law: LL.M. dissertation on online privacy, postgraduate research on facial recognition and algorithmic bias, and peer-reviewed work on biometric data governance. Four IAPP certifications — CIPP/E, CIPM, CIPT, and CDPO/BR.
Languages
How I work
Privacy advice that tells an organisation what it wants to hear is not advice — it is liability. My work is grounded in what the law, the regulators, and the enforcement record actually support.
Analysis anchored in enforcement trends, supervisory authority guidance, and case law — not reverse-engineered to fit a predetermined business outcome.
Alternative interpretations and associated risks are documented clearly. Business decisions belong to decision-makers, fully informed of the regulatory picture.
Recommendations translate directly into governance processes and controls that organisations can implement — not abstract compliance frameworks that sit in a drawer.
Practical experience working across GDPR and LGPD frameworks, with specific focus on cross-border accountability, transfer mechanisms, and regulatory alignment.
Contact
Whether you need a DPO function, a GDPR compliance review, or advisory on an AI governance question — get in touch and I will respond within one business day.
I respond within one business day. All enquiries are treated confidentially.