Privacidade · Proteção de Dados · Governança de IA

Expertise regulatória
para organizações
orientadas a dados

Consultoria independente em privacidade e DPO como Serviço — para organizações que navegam exigências de GDPR, LGPD e governança de IA.

CIPP/E — Certified Information Privacy Professional/Europe
CIPM — Certified Information Privacy Manager
CIPT — Certified Information Privacy Technologist
CDPO/BR — Certified Data Protection Officer Brazil

Privacy practice, end to end

From governance frameworks to operational controls, I help organisations translate regulatory obligations into workable practice — across GDPR, LGPD, and AI governance requirements.

Compliance

GDPR & LGPD Programmes

Structured compliance programmes covering legal basis mapping, data flows, contractual arrangements, and accountability documentation.

  • Records of Processing Activities (RoPA)
  • Data Protection Impact Assessments (DPIA)
  • Legitimate Interest Assessments (LIA)
  • Privacy notices & consent architecture

DPO Services

DPO as a Service

Fractional or full DPO function — programme oversight, regulatory liaison, incident coordination, and ongoing advisory support without the overhead of a full-time hire.

  • Privacy programme oversight
  • Data subject request handling
  • Data breach response & notification
  • Supervisory authority coordination

Risk

Privacy Risk Assessment

Risk-based analysis of processing activities, vendor relationships, and third-party transfers — grounded in enforcement trends and regulatory guidance, not generic checklists.

  • Third-party & processor due diligence
  • International transfer mechanisms
  • Vendor DPA review & negotiation
  • Data breach risk evaluation

Governance

Privacy Governance Frameworks

Design and implementation of accountability structures, privacy-by-design practices, and governance documentation that withstand regulatory scrutiny.

  • Governance policy development
  • Privacy-by-design integration
  • Internal training programmes
  • Accountability documentation

Emerging Tech

AI Governance & Regulation

Advisory on AI Act compliance, biometric data governance, algorithmic risk assessment, and responsible AI implementation in data-driven organisations.

  • AI Act readiness assessment
  • Biometric data governance
  • Algorithmic risk & bias analysis
  • AI privacy-by-design review

Cross-Jurisdictional

GDPR / LGPD Comparative Work

Specialist advisory for organisations operating across the EU and Brazil — comparative regulatory analysis, alignment strategies, and cross-border transfer frameworks.

  • Regulatory gap analysis
  • Cross-border transfer architecture
  • Accountability mechanism alignment
  • Bilateral compliance frameworks

Privacy practice grounded in regulation, not in checklists

I advise organisations on data protection and AI governance — from programme design to day-to-day operational decisions.

My work covers GDPR and LGPD compliance, privacy governance frameworks, DPIAs, legitimate interest assessments, vendor due diligence, and AI governance advisory. The focus is always on what the regulatory framework actually requires — not on documentation that looks right but does not hold up.

Academic background in data protection law: LL.M. dissertation on online privacy, postgraduate research on facial recognition and algorithmic bias, and peer-reviewed work on biometric data governance. Four IAPP certifications — CIPP/E, CIPM, CIPT, and CDPO/BR.

Languages

Portuguese Native English C1 Italian B2 Spanish B1
GDPR
End-to-end compliance programmes — legal basis mapping, DPIAs, LIAs, RoPAs, privacy notices, and accountability documentation
LGPD
Full LGPD compliance advisory — governance frameworks, data subject rights, regulatory risk, and cross-border alignment with GDPR
AI
AI governance and EU AI Act readiness — risk classification, biometric data governance, and privacy-by-design integration
DPO
DPO-as-a-Service — programme oversight, incident response, supervisory authority coordination, and ongoing advisory support

Technical rigour over comfortable answers

Privacy advice that tells an organisation what it wants to hear is not advice — it is liability. My work is grounded in what the law, the regulators, and the enforcement record actually support.

Regulatory realism

Analysis anchored in enforcement trends, supervisory authority guidance, and case law — not reverse-engineered to fit a predetermined business outcome.

Risk transparency

Alternative interpretations and associated risks are documented clearly. Business decisions belong to decision-makers, fully informed of the regulatory picture.

Operational focus

Recommendations translate directly into governance processes and controls that organisations can implement — not abstract compliance frameworks that sit in a drawer.

Cross-jurisdictional reach

Practical experience working across GDPR and LGPD frameworks, with specific focus on cross-border accountability, transfer mechanisms, and regulatory alignment.

Let's talk about your privacy programme

Whether you need a DPO function, a GDPR compliance review, or advisory on an AI governance question — get in touch and I will respond within one business day.

Send a message

I respond within one business day. All enquiries are treated confidentially.