References

Here are some of my selected references

A focused team reviewing data protection policies in a modern office.
A focused team reviewing data protection policies in a modern office.
ISO 27701 Privacy Information Management

Conducted a gap analysis, documented findings, and advised how to acquire the certification. Project ongoing

A consultant explaining data governance strategies to attentive business leaders around a conference table.
A consultant explaining data governance strategies to attentive business leaders around a conference table.
Website Privacy Notices

Drafted privacy notices and implemented cookie banners for global leaders in insurance, software development, and media

A focused team reviewing data protection policies in a modern office.
A focused team reviewing data protection policies in a modern office.
Vendor Due Diligence

Drafted a checklist and created a process how to approve vendors from data protection perspective

A consultant explaining data governance strategies to attentive business leaders around a conference table.
A consultant explaining data governance strategies to attentive business leaders around a conference table.
Risk Mapping Tools

Drafted and implemented a risk scoring system based on “Guidelines on Data Protection Impact Assessment (DPIA) (wp248rev.01)” by the European Data Protection Board (EDPB)

A focused team reviewing data protection policies in a modern office.
A focused team reviewing data protection policies in a modern office.
Records of Processing Activities

Creating records of processing activities from scratch (+2000 employees affected). Consulting business process owners and annually reviewing the records using OneTrust’s privacy solution.

A consultant explaining data governance strategies to attentive business leaders around a conference table.
A consultant explaining data governance strategies to attentive business leaders around a conference table.
Data Subject Request

Creating processes how to handle data subject requests such as “right to be forgotten”, access and correction requests

A focused team reviewing data protection policies in a modern office.
A focused team reviewing data protection policies in a modern office.
Background Checking

Advising how to conduct background checking (criminal records and debt register extracts) across several jurisdictions and revising group practices accordingly.

A consultant explaining data governance strategies to attentive business leaders around a conference table.
A consultant explaining data governance strategies to attentive business leaders around a conference table.
Records Retention Policy and Schedule

Drafting a policy, schedule and communication how to implement group-wide data retention rules.

A focused team reviewing data protection policies in a modern office.
A focused team reviewing data protection policies in a modern office.
Data Protection Training

Hand-crafting organization-specific data protection training unit (SCORM) for +2000 employees.

A consultant explaining data governance strategies to attentive business leaders around a conference table.
A consultant explaining data governance strategies to attentive business leaders around a conference table.
Regulatory Insights

Providing data protection advice to various clients and stakeholders on a daily basis. Main focus in Switzerland, Germany, the UK, Singapore and the Philippines.

A focused team reviewing data protection policies in a modern office.
A focused team reviewing data protection policies in a modern office.
Data Incident Management

Preparing a process how to handle data incidents (detection, reporting, triage, containment, communication, post-incident analysis)