Data protection & privacy
Corporate DPO in a multinational group, implementing GDPR, CCPA/CPRA, LGPD, PIPL and other regimes across 20+ countries, on 5 continents. DPIA, TIA, RoPA, data subject response and international transfers.
About Ahkoris
Founder · Certified DPO & Senior Auditor
Twenty years in privacy, internal audit and risk management, the most recent leading data protection compliance at international scale. As Corporate DPO and Senior Auditor at a multinational consumer goods group, he rolled out privacy programmes across more than 20 countries, on 5 continents, reaching over 95% compliance and cutting compliance risk by up to 90%.
Before that, he developed and implemented GDPR programmes and change-management programmes in the Portuguese public sector (city councils) at a technology consultancy, and managed operational compliance and risk across multinational industrial groups. That experience — across healthcare, industry, consumer goods, public sector and energy — shapes how Ahkoris works: programmes proportionate to the risk and to the organisation, with clear ownership and evidence that holds up to scrutiny.
That is the Ahkoris promise: operational proactivity, less bureaucracy and a high level of compliance that keeps working after the project ends.
Experience
Corporate DPO in a multinational group, implementing GDPR, CCPA/CPRA, LGPD, PIPL and other regimes across 20+ countries, on 5 continents. DPIA, TIA, RoPA, data subject response and international transfers.
Internal audit, SOX audits, third-party due diligence within SOC 2, ISO 27001 and NIST scope, and business risk management methodologies. Executive-level compliance reports and roadmaps.
Ethics and compliance, anti-corruption, whistleblowing channels, ISO 27001 and ISO 31000, and the design of sustainable, auditable governance programmes.
Representative work
These examples reflect work carried out by the founder over his career, in previous roles. They are anonymised and presented as a reference of experience — they are not Ahkoris client engagements.
Context: a multinational consumer goods group operating in 20+ countries, on 5 continents, with no harmonised data protection programme.
Intervention: design and rollout of a corporate privacy framework — RoPA, DPIA, international transfer assessments (TIA), data subject response and policies common to several regimes (GDPR, CCPA/CPRA, LGPD, PIPL).
Result: over 95% compliance within an average of 12 months, compliance risk cut by up to 90%, and audit-ready evidence.
Context: public sector organisations (city councils) with no clear view of their data protection maturity.
Intervention: maturity assessment and GAP analysis, mapping of processing activities and data flows, prioritisation and action plan, with staff and executive training.
Result: a clear view of what applies, defined priorities, and internal capacity to maintain the programme after the project.
Context: a multinational industrial group with scattered regulatory exposure and critical suppliers left unassessed.
Intervention: internal audit (including SOX scope), technical and contractual third-party due diligence within SOC 2, ISO 27001 and NIST, actionable recommendations and an executive-level roadmap.
Result: a significant reduction in compliance risk, documented decisions and clear reporting to the management body.
Credentials
Want to understand where to start in your organisation?
Schedule a conversation