Skip to main content
Top expert badge
Recommended expert
Profile header background

Henry (Michael) Hanau-Interim CISO, DPO, AI Officer

Henry (Michael) Hanau - Interim CISO, DPO, AI Officer - profile avatar
Profile header overlay
Available
Essen, Germany

Check rate

Experience

Jan 2026 - Present

Interim Manager IT-Compliance

Int. Fertigungsunternehmen

Position summary
Interim Manager IT-Compliance at Int. Fertigungsunternehmen
Industries
Automotive
Manufacturing
Business areas
Information Technology
Legal
Project Management
  • Industry: mechanical engineering, vehicle manufacturing
  • Regulations: Data Act
  • Project focus: data governance, legally compliant use of machine data, data platforms
  • Assigned by: CFO, platform product owner

Successes/Results (early phase):

  • Compliance support for the setup of an internal standardized data usage platform based on Databricks.
  • Created the basis for the legally compliant and effective use of machine data, including:
  • Technical: gap analysis and closing of gaps in the segmentation and maintenance of collected machine data.
  • Technical: consideration of data flows from the platform to users and third parties.
  • Organizational: drafting and finalizing the required data usage agreements.
Jan 2023 - Dec 2024

Interim Manager IT-Compliance

Nationaler Energieversorger

Position summary
Interim Manager IT-Compliance at Nationaler Energieversorger
Industries
Energy
Information Technology
Business areas
Information Technology
Legal
  • Industry: IT energy
  • Regulations: GDPR, KRITIS
  • Project focus: data protection, IT risk management, organizational development
  • Assigned by: Vice President Compliance

Successes/Results:

  • Built an organization-wide data protection management system (organizationally and technically); built a trust network between the group companies, which led to a high level of acceptance and compliance already in the first year (first run of the Deming cycle).
  • Implemented OneTrust as the central data protection management tool, standardized data protection controls across all subsidiaries, and reduced manual reporting by 50 %.
Jan 2022 - Dec 2024

Leitung Abteilung GRC ad interim

Int. Konzern des Maschinenbaus

Position summary
Leitung Abteilung GRC ad interim at Int. Konzern des Maschinenbaus
Industries
Automotive
Manufacturing
Business areas
Human Resources
Information Technology
Legal
  • Industry: vehicle manufacturing, heavy machinery engineering
  • Regulations: GDPR, NIS-2, SOX, BetrVG, ISO 27001, TISAX
  • Project focus: data protection, IT security, IT risk management, organizational development, digital transformation
  • Assigned by: management (CFO)
  • Personnel responsibility: 4 FTE (ad interim)

Successes/Results:

  • Restructured the IT function in terms of people and content, and linked IT operations (networks, workplace, SAP) with the newly created IT GRC function.
  • Prevented the resignation of key staff (2 FTE), staffing adjustment (1 FTE).
  • Built and scaled an enterprise-wide IT GRC function, hired and trained a 4-person team, and reduced compliance gaps by 70 % during the assignment: ensured SOX compliance, license compliance, and increased IT security by 80% compared to before.
  • Integrated the German IT GRC unit into the national organization. Connected the German GRC unit to the international parent organization. Set up permanent exchange committees and increased the visibility of German branch interests by 100%.
  • Led the rollout of Microsoft 365 (M365) across all EU/international branches, negotiated enterprise agreements, and added works council agreements.
  • Structured analysis to determine NIS-2 applicability. Trained managers on the resulting obligations.
  • Introduced ISO 27001 ISMS, prepared the organization for NIS-2 compliance, and reduced third-party risk. Coordination with coverage under the existing cyber risk insurance policy.
  • Negotiated more than 10 works council agreements for platform services and HR tools; ensured legal compliance while maintaining operational flexibility.
Jan 2021 - Present

Interim IT-Compliance Manager

Globales Healthcare Unternehmen

Position summary
Interim IT-Compliance Manager at Globales Healthcare Unternehmen
Industries
Healthcare
Pharmaceutical
Business areas
Audit
Information Technology
Legal
  • Industry: healthcare, pharma
  • Regulations: GDPR, AI Act, BetrVG, labor law
  • Project focus: works agreements, IT audit, AI governance
  • Assigned by: chair of the general works council Germany

Successes/Results:

  • Architect of the new, structured negotiation process for digital initiatives with co-determination relevance, reduction of time-consuming preliminary coordination between employer and works council, improved cross-departmental cooperation, significant shortening of negotiation cycles -> doubled project approval speed.
  • Architect of the first risk-based process for assessing and then gradually introducing AI applications.
  • Feature-driven AI application inventory and assessment of AI use cases from the perspectives of data protection, AI regulation and co-determination. Selected topics: ATS, compliance investigations, employee evaluation and many more. Assessment of the need for DPIAs, FRIAs and contractual integration of vendors.
  • AI vendor audits with a focus on model, data origin, training, bias, safeguards, data protection suitability and other guarantees (especially IP protection).
  • Revision of AI usage guidelines and liability rules.
  • Negotiation of more than 20 works council agreements on AI, platform services, information security and HR tools; ensuring legal compliance while maintaining operational flexibility.
Jan 2021 - Feb 2025

Secondment für den Datenschutzbeauftragten

Int. Bankengruppe

Position summary
Secondment für den Datenschutzbeauftragten at Int. Bankengruppe
Industries
Banking and Finance
Business areas
Audit
Information Technology
Legal
  • Industry: banking
  • Regulations: GDPR, BDSG
  • Project focus: data protection, IT compliance, IT audit, IT risk management
  • Assigned by: group data protection officer

Successes/Results:

  • Led an 18-month enterprise-wide GDPR compliance audit, identifying several high- and medium-risk gaps; implemented remediation measures that reduced regulatory risk to 0. Completed on time and within budget with full positive final approval.
  • Drafted and introduced a uniform data protection control framework -> significant reduction in response time for audits and data subject requests.
  • Revised the complete CMS with regard to acceptance and effectiveness, fully translated into English.
  • Conducted complex data protection impact assessments (DPIAs).
Jan 2018 - Dec 2020

Group Data Protection Officer (global)

Global Healthcare Company

Position summary
Group Data Protection Officer (global) at Global Healthcare Company
Industries
Healthcare
Business areas
Information Technology
Legal
  • Industry: Healthcare, medical devices
  • Regulations: GDPR
  • Main focus: Data protection, IT security, IT risk management, organizational development
  • Mandated by: Senior Vice President Risk Management
  • Personnel responsibility: 2 FTE (direct), 15 (indirect)

Achievements/Results:

  • National Data Protection Officer for all German entities.
  • Group Data Protection Officer.
  • Development of a group-wide data protection organization and set-up of a global data protection network. Promotion of a compliance culture, reflected in the compliant handling of data subject requests and data deletion requests that had previously not been managed consistently. Increase in compliance with statutory deadlines by 100%.
  • Conducted data protection risk analyses and data protection impact assessments for a number of major applications (healthcare platform, SAP Concur, SAP SuccessFactors, online application platform).
  • Supported the succession process for the Group Data Protection Officer role.
  • Prevented significant fines in two major IT projects through early risk management and by showing alternative ways to reach the project goal.
Jan 2017 - Dec 2026

Secondment for the Head of Data Protection / In-house Counsel

International Banking Group

Position summary
Secondment for the Head of Data Protection / In-house Counsel at International Banking Group
Industries
Banking and Finance
Business areas
Audit
Information Technology
Legal
  • Industry: Banking
  • Regulations: KWG, GWG, MaRisk, eIDAS, BAIT, DORA, GDPR, ISO 27001
  • Main focus: Data protection, IT security (2nd line of defense), IT audit, IT compliance, IT risk management
  • Mandated by: management, group data protection officer, technical project managers

Achievements/Results:

  • Analysis and assessment of specific apps and their provider/user relationship on behalf of the 2nd line of defense and in light of data protection, information security, terms and conditions, DORA.
  • Analysis and assessment of specific video identification solutions on behalf of the 2nd line and in light of data protection, information security, terms and conditions, and GWG.
  • Analysis and assessment of specific digital signature solutions on behalf of the 2nd line and in light of data protection, information security, terms and conditions, and eIDAS.
  • Conducted structural audits on behalf of the 2nd line of the implemented ISO 27001 ISMS (protection needs of IT assets, gap analyses, risk analyses). Relevant tool experience: OneTrust, Schleupen R2C.
  • Revised the procurement process for IT products and IT services from an information security perspective, designed a streamlined process / specific requirements on behalf of the 2nd line; accepted rollout of a new aligned procurement policy, inclusion of relevant clauses in the company terms and conditions with consideration of future legal requirements (especially DORA).
  • Supported the 1st line of defense in recurring asset reviews.
  • Analysis of the technical setup of various cloud services with regard to compliance: Microsoft O365, SAP on hyperscalers.
  • Further development of the existing framework to comply with the EU GDPR. Supported the in-house counsel leading the project in all data protection matters.
  • Development and successful rollout of a semi-automated template for assessing data protection risks of processing activities. Conducted data protection impact assessments and transfer impact assessments for data transfers to unsafe third countries.
  • Development and implementation of an ISO 19600-oriented data protection management system (DPMS) -> reaching a 90% compliance rate on the first day the GDPR became applicable.
  • Served as company data protection officer for a subsidiary.
Jan 2016 - Dec 2017

Data Protection Officer (Germany))

Global Healthcare Company

Position summary
Data Protection Officer (Germany)) at Global Healthcare Company
Industries
Healthcare
Business areas
Information Technology
Legal
Operations
  • Industry: Healthcare, medical devices
  • Regulations: GDPR
  • Main focus: Data protection, IT security, IT risk management, organizational development
  • Mandated by: Senior Vice President Risk Management
  • Personnel responsibility: 2 FTE (direct), 15 (indirect)

Achievements/Results:

  • National Data Protection Officer for all German entities.
  • Group Data Protection Officer.
  • Development of a group-wide data protection organization and set-up of a global data protection network. Promotion of a compliance culture, reflected in the compliant handling of data subject requests and data deletion requests that had previously not been managed consistently. Increase in compliance with statutory deadlines by 100%.
  • Conducted data protection risk analyses and data protection impact assessments for a number of major applications (healthcare platform, SAP Concur, SAP SuccessFactors, online application platform).
  • Supported the succession process for the Group Data Protection Officer role.
  • Prevented significant fines in two major IT projects through early risk management and by showing alternative ways to reach the project goal.
Jan 2008 - Dec 2014

Data Protection Manager (global) - Head of IT Audit

Global B2B Trading Company

Position summary
Data Protection Manager (global) - Head of IT Audit at Global B2B Trading Company
Industries
Retail
Business areas
Audit
Information Technology
Legal
  • Industry: Wholesale, specialty products
  • Regulations: GDPR, HGB
  • Main focus: Data protection, IT security, IT audit, IT risk management, organizational development
  • Mandated by: Corporate Compliance Officer (legal department)
  • Personnel responsibility: 2 FTE (direct), 8 (indirect)

Achievements/Results:

  • Chair of an international data protection organization in 8 countries, aligning locally different procedures with EU standards and significantly reducing cross-border compliance risks.
  • Set up the IT audit department within group internal audit / defining the annual audit plan.
  • Led the audit: Cut-over to SAP ERP 6.0 Global (no findings in the annual audit).
  • Managed complex cross-border IT audits.
  • Wrote audit reports tailored to the target audience (C-level, IT, accounting, tax).
  • Follow-up management.
  • Trained a traditional internal auditor to become an IT auditor, including CISA certification.
Jan 1998 - Dec 2005

Head of Department / Partner

Well-known IT security consulting firm

Position summary
Head of Department / Partner at Well-known IT security consulting firm
Industries
Professional Services
Business areas
Audit
Information Technology
  • Industry: Consulting
  • Regulations: AktG, BDSG, GmbHG
  • Main focus: IT security, IT audit, IT risk management, data protection, organizational development
  • Personnel responsibility: 4 FTE (direct)

Achievements/Results:

  • Partner for IT security consulting.
  • Head of department for IT security audits and process management.
  • Development of consulting products (consulting packages) in the field.
  • Portfolio of different analysis services: business processes, information value, protection needs, risks, vulnerabilities, impacts.
  • Quantification of IT risks.
  • Consulting on the implementation of information security management systems (ISMS).
  • IT security audits including penetration tests.
  • SAP security consulting.

Industry experience

See where this freelancer has spent most of their professional time.

Experienced in Healthcare, Banking and Finance, Professional Services, Retail, Pharmaceutical, and Automotive.

Healthcare
Banking and Finance
Professional Services
Retail
Pharmaceutical
Automotive
Profile match chart

Business area experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Audit, Legal, Human Resources, Operations, and Project Management.

Information Technology
Audit
Legal
Human Resources
Operations
Project Management
Profile match chart

Summary

Long-standing and experienced advisor for IT law, IT audit, and IT governance, risk and compliance (GRC), who turns compliance risks into strategic advantages and combines management skills with solid technical and legal expertise.

Proven success in reducing regulatory risks, closing compliance gaps, and turning legal obligations into practical, enforceable controls aligned with business needs.

Trusted guide at the interface of GDPR, Data Act, AI Act, NIS-2, DORA and ISO 27001, bridging legal, technical and business requirements (360° view of converging topics). Bridge builder between the different affected departments.

Special experience in working with works councils and in complex stakeholder environments (CIOs, legal, compliance, business units such as HR, IT, procurement ...).

Leadership experience: building, staffing and leading departments for IT audit, GRC including information security and data protection.

Manager mindset -> risk-aware doer, not risk-averse blocker.

Industry experience in finance, healthcare, (automotive) manufacturing, commodities (energy), wholesale. From upper mid-sized companies to globally operating corporations.

Strong communication skills, high trustworthiness -> long-running projects.

My focus: reducing liability exposure, speeding up decisions, and ensuring sustainable compliance without blocking operational processes.

More than 25 years of proven IT-GRC experience in regulated industries: from strategy at C-level to hands-on implementation.

Skills

  • It Law And Regulatory Compliance (Gdpr, Bdsg, Eprivacy, Nis-2, Dora, Ai Act, Data Act (Data Economy) And Related Legal Areas (Kwg, Betrvg And Many More))
  • Data Protection (Dpias, Records Of Processing Activities, Handling Data Subject Rights, Handling Data Breaches And Authority Requests, Onetrust, Schleupen R2c)
  • Information Security And Risk Management, Especially For Third Parties
  • It Audit (Gap Analyses, Risk Analyses, Remediation Measures, Internal Controls, Supplier Audits)
  • It Governance, Risk And Compliance Frameworks (Grc) (Iso 27001 And Related Standards, Iso 37301, Iso 42001, Cobit, Itil)
  • Building Compliance Management Systems: Creating Company Policies And Operating Instructions Tailored To Target Groups, Role Assignments, Staff Selection
  • Digital Transformation (M365, Ai Governance, Cloud Security, Negotiations With Works Councils)
  • It Management To Turn The Above Into Usable It Services

Languages

German
Native
English
Native

Education

Oct 2021 - Jun 2023

Universität Oldenburg

Master of Laws · IT law · Oldenburg, Germany

Oct 1992 - Jun 1998

Universität Essen

Diplom-Betriebswirt · Business informatics · Essen, Germany

Certifications & licenses

AIGP: AI Governance Professional

CDPSE: Certified Data Privacy Solutions Engineer

CGEIT: Certified in the Governance of Enterprise IT

Cyber Security Practitioner

Microsoft M365 Security Administrator

SCRUM Master and Product Owner Training

Additional audit procedure competence under the BSI Act (KRITIS)

Statistics

Experience

Total positions 10
Experience in Healthcare 10.5 y
Avg length 4 y 6 m
Longest experience 9 y 8 m

Expertise

Recent roles Interim Manager IT-Compliance, Leitung Abteilung GRC ad interim, Interim IT-Compliance Manager
Main industries Healthcare, Banking and Finance, Professional Services
Main business areas Information Technology, Audit, Legal

Qualifications

Highest degree Master
Certifications earned 15

Profile

Member since
Last update
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Have questions? Find more information here.

Henry is based in Essen, Germany and can operate in on-site, hybrid, and remote work models.

Henry speaks the following languages: German (Native), English (Native).

Henry has at least 26 years of experience. During this time, Henry has worked in at least 9 different roles and for 9 different companies. The average length of individual experience is 3 years and 7 months. Note that Henry may not have shared all experience and actually has more experience.

Based on recent experience, Henry would be well-suited for roles such as: Interim Manager IT-Compliance, Leitung Abteilung GRC ad interim, Interim IT-Compliance Manager.

Henry's most recent position is Interim Manager IT-Compliance at Int. Fertigungsunternehmen.

In recent years, Henry has worked for Int. Fertigungsunternehmen, Nationaler Energieversorger, Int. Konzern des Maschinenbaus, Globales Healthcare Unternehmen, and Int. Bankengruppe.

Henry is most experienced in industries like Healthcare, Banking and Finance, and Professional Services. Henry also has some experience in Retail, Pharmaceutical, and Automotive.

Henry is most experienced in business areas like Information Technology, Audit, and Legal. Henry also has some experience in Human Resources, Operations, and Project Management.

Henry has recently worked in industries like Banking and Finance, Healthcare, and Pharmaceutical.

Henry has recently worked in business areas like Information Technology, Legal, and Audit.

Henry holds a Master in IT law from Universität Oldenburg and a Bachelor in Business informatics from Universität Essen.

Henry has 15 certificates. Among them, these include: AIGP: AI Governance Professional, CCSK: Certificate of Cloud Security Knowledge, and CDPSE: Certified Data Privacy Solutions Engineer.

Henry is immediately available part-time for suitable projects.

Daily rate distribution

0 2 4 6 8
<€640 €800-​960 €960-​1120 €1120+

The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 940 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 980 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 1 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.