Alicja W.-Attorney-at-Law, External Data Protection Officer, IT Security Officer, AI Officer
Check rate
Experience
Integrated security and emergency documentation for a 24/7 logistics company
Mid-sized logistics company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, Vulnerability Management Policy, Business Resilience Programme, Risk Governance Plan
- Consolidation into an integrated emergency manual (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table and a formal approval structure
- Review and documentation of the applicability of NIS2 and HinSchG, including the legal reasoning for non-applicability
- Processing of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with a documented compensating control
Attorney-at-Law – IT Law and Data Protection
KONTENTIERT LEGAL
- Litigation and representation in extensive court proceedings in IT and data protection law before German courts – from out-of-court negotiations through litigation to appellate proceedings
- Legal representation of companies in data protection and IT law disputes: fine proceedings, correspondence with supervisory authorities (with a focus on LDI NRW and LDA Bayern), defense against compensation and cease-and-desist claims by data subjects
- Drafting and review of IT-related contracts: data processing agreements, IT service agreements, SaaS and cloud agreements, international data transfers (SCC, TIA), data protection impact assessments
- Advice on regulatory developments: NIS2 implementation, DORA, Whistleblower Protection Act, AI Act, TDDDG – including client information and compliance roadmaps
- Core client segments: medium-sized companies, IT service providers, e-commerce companies, logistics, manufacturing, retail and healthcare
Founder & Owner – Compliance Consulting for Data Protection, IT Security, E-Commerce
EASY DATENSCHUTZ
- Establishment and management of my own compliance consultancy for more than four years with full entrepreneurial responsibility – client acquisition, service delivery, quality assurance, pricing and office administration
- Assumption of the DPO function under Art. 37 GDPR for more than 200 clients across industries: IT service providers, e-commerce, industry, construction, logistics, retail, healthcare, coaching providers, intermediaries and other service providers – from medium-sized companies with 24/7 operating requirements to internationally structured organizations
- Cross-border compliance support for clients in Germany, Poland, Italy and the United Kingdom: parallel application of GDPR, UK GDPR, national data protection law and industry-specific requirements; correspondence with LDI NRW, UODO, Garante and ICO
- Establishment and operation of information security management systems: security policies, access control, Vulnerability Management, Business Continuity and Disaster Recovery, Incident Response with case-specific playbooks
- Lead responsibility for more than 300 data protection and IT security projects: records of processing activities, data protection impact assessments, audit reports, security documentation, emergency manuals, employee training and ongoing strategic and operational consulting
- Crisis management for data breaches and cyber incidents: coordination of internal stakeholders, IT service providers, forensics providers and supervisory authorities – including timely notifications under Art. 33 GDPR within 72 hours
- Evaluation of penetration test results (including Greenbone), development of risk-based remediation plans and formal risk acceptance procedures according to ISO 27005 / BSI standards
Judicial and public administration legal traineeship – Assessorexamen
Wuppertal Regional Court
- Civil law placement at Velbert Local Court: independent drafting of judgments, court session duties and performance of judicial tasks under supervision (service as a judge)
- Criminal law placement at the Wuppertal Public Prosecutor's Office in the department for narcotics crime, organized crime and Cyber Crime: filing of indictments, case file processing and representation at court hearings
- Administrative law placement in the administration of the NRW State Parliament, focusing on data protection and compliance – an authority-side perspective on regulatory processes
- Legal placement at a Düsseldorf commercial law firm specializing in data protection law and compliance
- Result: in-depth knowledge of German judicial and administrative practice from the inside – valuable in any subsequent dealings with courts and supervisory authorities
Student Assistant
Marco Schmitz MdL · NRW State Parliament
- Support with day-to-day political work, research on legislative procedures, meeting preparation and constituency work
- Insight into regulatory processes and the institutional framework of lawmaking in NRW
Research Associate
Boden Rechtsanwälte
- Handling legal matters in intellectual property, data protection and IT law
- Research, drafting pleadings, client communication and file management alongside university studies and legal clerkship
Crisis support following data breaches and cyber incidents
Various clients across industries
- Initial assessment within two hours, reporting decision under Art. 33 GDPR, communication with authorities and notification of affected persons under Art. 34 GDPR
- Coordinating immediate measures: securing evidence, containment, forensic investigation and recovery – with clear allocation of roles between management, IT, data protection and external service providers
- Audit-ready documentation of all decisions and communication steps as protection in any subsequent proceedings before authorities or courts
Data protection compliance for e-commerce clients
Several online retailers on the German market
- Ongoing DPO support and legal advice on developments in consumer protection, data protection and e-commerce law
- Preparing client information on regulatory changes (including implementation of EU directives in the German Civil Code, the Price Indication Ordinance and the EmpCo Directive)
- Reviewing and preparing privacy policies, general terms and conditions, data processing agreements and cookie consent concepts
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Professional Services, Government and Administration, Information Technology, Retail, Transportation, and Healthcare.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Legal, Operations, and Research and Development.
Summary
Attorney-at-law specializing in data protection and IT law, certified external data protection officer, data protection auditor, IT security officer, whistleblower protection officer and AI Officer. Combines in one person what is otherwise provided by three separate service providers in the market: legal advice, operational compliance responsibility and technical and organizational security management.
Self-employed since 2022 in my own compliance consultancy, focusing on data protection, IT security and e-commerce – working across industries for service providers, intermediaries, industrial companies, construction companies, logistics companies, retailers, healthcare organizations, coaching providers and IT companies. Cross-border mandates in Germany, Poland, Italy and the United Kingdom; bilingual working style (German/English, native language Polish).
More than 8 years of specialized professional experience, over 200 clients supported and more than 300 completed projects. Knows the German legal and business environment from both perspectives: from the judiciary and public administration – with trainee placements at the Wuppertal Public Prosecutor's Office (Cyber Crime, narcotics crime, organized crime), at Velbert Local Court in civil law and in the data protection and compliance department of the NRW State Parliament – as well as from litigation-focused legal practice, including representation in extensive court proceedings in IT and data protection law before German courts.
Stands for the fast, focused assumption of responsibility: immediate ability to act in crisis and vacancy situations, clear leadership of interdisciplinary teams and confident management of executive boards, IT departments, supervisory authorities and external service providers – with the goal of producing auditable, documented results and measurable impact.
Skills
Data Protection Law
- Gdpr · Bdsg · Tdddg
- Data Processing Agreements
- International Data Transfers
- Correspondence With The Ldi
- Representation In Fine Proceedings
Artificial Intelligence
- Ki Beauftragte
- Ki Manager
- Ai Officer
- Eu Ai Act / Ki Vo
It Security & Governance
- Iso 27001 · Bsi It-Grundschutz
- Isms Setup And Operation
- Vulnerability Management
- Bcp / Drp / Irp
- Penetration Test Evaluation
Crisis & Incident Response
- Art. 33 / 34 Gdpr Notifications
- Picerl Phase Model
- Ransomware Response
- Forensics Coordination
- Crisis Communication
Additional Regulatory Expertise
- Nis2 Directive · Dora · Hinschg · Kritis · Tdddg · Ai Act · Employee Data Protection · Video Surveillance · Healthcare Data Protection
Languages
Education
Heinrich-Heine-Universität Düsseldorf
Erstes juristisches Staatsexamen · Law · Düsseldorf, Germany
Certifications & licenses
Hinweisgeberschutzbeauftragte
Zertifizierung nach Art. 37 DSGVO
Statistics
Experience
Global experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Alicja speaks the following languages: German (Native), Polish (Native), English (Advanced), Spanish (Elementary).
Alicja has at least 8 years of experience. During this time, Alicja has worked in at least 6 different roles and for 6 different companies. The average length of individual experience is 1 year and 4 months. Note that Alicja may not have shared all experience and actually has more experience.
Based on recent experience, Alicja would be well-suited for roles such as: Integrated security and emergency documentation for a 24/7 logistics company, Attorney-at-Law – IT Law and Data Protection, Founder & Owner – Compliance Consulting for Data Protection, IT Security, E-Commerce.
Alicja's most recent position is Integrated security and emergency documentation for a 24/7 logistics company at Mid-sized logistics company.
In recent years, Alicja has worked for Mid-sized logistics company, KONTENTIERT LEGAL, EASY DATENSCHUTZ, Wuppertal Regional Court, and Marco Schmitz MdL · NRW State Parliament.
Alicja is most experienced in industries like Professional Services, Government and Administration, and Information Technology. Alicja also has some experience in Retail, Transportation, and Healthcare.
Alicja is most experienced in business areas like Information Technology, Legal, and Operations. Alicja also has some experience in Research and Development.
Alicja has recently worked in industries like Professional Services, Government and Administration, and Information Technology.
Alicja has recently worked in business areas like Information Technology, Legal, and Operations.
Alicja holds a Master in Law from Heinrich-Heine-Universität Düsseldorf.
Alicja has 5 certificates. Among them, these include: AI Officer, Hinweisgeberschutzbeauftragte, and Datenschutz-Auditorin.
Alicja is immediately available full-time for suitable projects.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Integrated security and emergency documentation for a 24/7 logistics company
