Henry (Michael) Hanau-Interim CISO, DPO, AI Officer
Check rate
Experience
Interim Manager IT Compliance
International manufacturing company
- Industry: mechanical engineering, vehicle manufacturing
- Regulations: Data Act
- Project focus: data governance, legally compliant use of machine data, data platforms
- Commissioned by: CFO, platform product owner
Successes/results (early phase):
- Compliance support for building an internal unified data usage platform based on Databricks.
- Created the basis for legally compliant and effective use of machine data, including:
- Technical: gap analysis and closing gaps in the segmentation and maintenance of collected machine data.
- Technical: consideration of data exports from the platform to users and third parties.
- Organizational: drafting and finalizing the required data usage agreements.
Interim Manager IT Compliance
National energy supplier
- Industry: IT energy
- Regulations: GDPR, KRITIS
- Project focus: data protection, IT risk management, organizational development
- Commissioned by: Vice President Compliance
Successes/results:
- Built an organization-wide data protection management system (organizational and technical); built a trust network between group companies, which led to high acceptance and compliance rates in the first year (first cycle of the Deming cycle).
- Implemented OneTrust as the central data protection management tool, standardized data protection controls across all subsidiaries, and reduced manual reporting by 50%.
Head of GRC ad interim
International group in mechanical engineering
- Industry: vehicle manufacturing, heavy machinery
- Regulations: GDPR, NIS-2, SOX, BetrVG, ISO 27001, TISAX
- Project focus: data protection, IT security, IT risk management, organizational development, digital transformation
- Commissioned by: management (CFO)
- Personnel responsibility: 4 FTE (ad interim)
Successes/results:
- Personnel and content restructuring of the IT function and linking IT operations (networks, workplace, SAP) with the newly created IT GRC function.
- Prevented the resignation of key staff (2 FTE), personnel adjustment (1 FTE).
- Built and scaled a company-wide IT GRC function, hired and trained a 4-person team, and reduced compliance gaps by 70% during the assignment: ensured SOX compliance, license compliance, and increased IT security by 80% compared to the previous state.
- Integrated the German IT GRC unit into the national organization. Connected the German GRC unit to the international parent organization. Set up permanent coordination forums and increased the visibility of the German branch's interests by 100%.
- Led the rollout of Microsoft 365 (M365) across all EU/international subsidiaries, negotiated enterprise agreements, and added works council agreements.
- Structured analysis to determine NIS-2 scope. Trained executives on the resulting obligations.
- Introduced ISO 27001 ISMS, prepared the organization for NIS-2 compliance, and reduced third-party risk. Aligned coverage with existing cyber risk insurance.
- Negotiated more than 10 works council agreements for platform services and HR tools; ensured legal compliance while keeping operational flexibility.
Interim IT Compliance Manager
Global healthcare company
- Industry: healthcare, pharma
- Regulations: GDPR, AI Act, BetrVG, labor law
- Project focus: works agreements, IT audit, AI governance
- Commissioned by: chair of the German group works council
Successes/results:
- Architect of the new structured negotiation process for digital initiatives with co-determination relevance, reducing time-consuming pre-alignment between employer and works council, improving cross-department collaboration, and significantly shortening negotiation cycles -> doubling project approval speed.
- Architect of the first risk-based process for assessing and then rolling out AI applications in stages.
- Assessed AI use cases from the perspective of data protection, AI regulation, and co-determination. Selected topics: ATS, compliance investigations, employee evaluation, and many more. Assessed the need for DPIAs, FRIAs, and contractual integration of vendors.
- AI supplier audits regarding model, data origin, training, bias, safeguards, data protection suitability, and other guarantees (especially IP protection).
- Revised AI usage guidelines and liability rules.
- Negotiated more than 20 works council agreements on AI, platform services, information security, and HR tools; ensured legal compliance while keeping operational flexibility.
Secondment for the data protection officer
International banking group
- Industry: banking
- Regulations: GDPR, BDSG
- Project focus: data protection, IT compliance, IT audit, IT risk management
- Commissioned by: group data protection officer
Successes/results:
- Led an 18-month company-wide GDPR compliance audit that identified several high- and medium-risk gaps; implemented remediation measures that reduced regulatory risk to 0. Kept within time and budget and received full positive final approval.
- Designed and introduced a uniform data protection control framework -> significantly reduced response time in audits and data subject requests.
- Revised the entire CMS in terms of acceptance and effectiveness, complete translation into English.
- Conducted complex data protection impact assessments (DPIAs).
Group Data Protection Officer (global)
Global Healthcare Company
- Industry: Healthcare, medical devices
- Regulations: GDPR
- Project focus: Data protection, IT security, IT risk management, organizational development
- Commissioned by: Senior Vice President Risk Management
- Personnel responsibility: 2 FTE (direct), 15 (indirect)
Achievements/Results:
- National data protection officer for all German entities.
- Group data protection officer.
- Development of a group-wide data protection organization and setup of a global data protection network. Promotion of a compliance culture, reflected in the compliant handling of subject access requests and data deletion requests that were previously not managed consistently. Increase in compliance with statutory deadlines by 100%.
- Conducted data protection risk analyses and data protection impact assessments for a number of major applications (healthcare platform, SAP Concur, SAP SuccessFactors, online application platform).
- Supported the replacement recruitment for the Group Data Protection Officer.
- Avoided significant fines in two major IT projects through early risk management and by showing alternative ways to achieve the project goal.
Secondment for the Head of Data Protection / In-house Counsel
International Banking Group
- Industry: Banking
- Regulations: KWG, GWG, MaRisk, eIDAS, BAIT, DORA, GDPR, ISO 27001
- Project focus: Data protection, IT security (2nd line of defense), IT audit, IT compliance, IT risk management
- Commissioned by: Managing Director, Group Data Protection Officer, specialist project managers
Achievements/Results:
- Analysis and assessment of specific apps and their provider/user relationship on behalf of the 2nd line (of defense) and in light of data protection, information security, terms and conditions, and DORA.
- Analysis and assessment of specific video ID solutions on behalf of the 2nd line and in light of data protection, information security, terms and conditions, and GWG.
- Analysis and assessment of specific digital signature solutions on behalf of the 2nd line and in light of data protection, information security, terms and conditions, and eIDAS.
- Conducted structural audits on behalf of the 2nd line of the implemented ISO 27001 ISMS (protection needs of IT assets, gap analyses, risk analyses). Related tool experience: OneTrust, Schleupen R2C.
- Revised the procurement process for IT products and IT services from an information security perspective, designed a streamlined process / specific requirements on behalf of the 2nd line; accepted roll-out of a new aligned procurement policy, inclusion of relevant clauses in the company terms and conditions with consideration of future legal requirements (especially DORA).
- Supported the 1st line of defense with recurring asset valuations.
- Analysis of the technical setup of various cloud services with regard to compliance: Microsoft O365, SAP on hyperscalers.
- Further development of the existing framework to comply with the EU GDPR. Supported the project-leading in-house counsel in all data protection matters.
- Development and successful introduction of a semi-automated template for assessing data protection risks of processing activities. Conducted data protection impact assessments and transfer impact assessments for data transfers to unsafe third countries.
- Development and implementation of an ISO 19600-oriented data protection management system (DPMS) -> achieving a 90% compliance rate on the first day of GDPR applicability.
- Served as the company data protection officer for a subsidiary.
Data Protection Officer (Germany)
Global Healthcare Company
- Industry: Healthcare, medical devices
- Regulations: GDPR
- Project focus: Data protection, IT security, IT risk management, organizational development
- Commissioned by: Senior Vice President Risk Management
- Personnel responsibility: 2 FTE (direct), 15 (indirect)
Achievements/Results:
- National data protection officer for all German entities.
- Group data protection officer.
- Development of a group-wide data protection organization and setup of a global data protection network. Promotion of a compliance culture, reflected in the compliant handling of subject access requests and data deletion requests that were previously not managed consistently. Increase in compliance with statutory deadlines by 100%.
- Conducted data protection risk analyses and data protection impact assessments for a number of major applications (healthcare platform, SAP Concur, SAP SuccessFactors, online application platform).
- Supported the replacement recruitment for the Group Data Protection Officer.
- Avoided significant fines in two major IT projects through early risk management and by showing alternative ways to achieve the project goal.
Data Protection Manager (global) - Head of IT Audit
Global B2B Trading Company
- Industry: Wholesale, specialty products
- Regulations: GDPR, HGB
- Project focus: Data protection, IT security, IT audit, IT risk management, organizational development
- Commissioned by: Corporate Compliance Officer (Legal Department)
- Personnel responsibility: 2 FTE (direct), 8 (indirect)
Achievements/Results:
- Chair of an international data protection organization in 8 countries, aligning locally different approaches with EU standards and significantly reducing cross-border compliance risks.
- Setup of the IT audit department within group audit / defining the annual audit program.
- Lead auditor for the audit: Cut-over to SAP ERP 6.0 Global (no findings in the audit).
- Management of complex cross-border IT audits.
- Writing audit reports tailored to the target audience (C-level, IT, accounting, tax).
- Follow-up management.
- Trained a classic auditor to become an IT auditor, including CISA certification.
Department Head / Partner
Well-known Consulting Firm for IT Security
- Industry: Consulting
- Regulations: AktG, BDSG, GmbHG
- Project focus: IT security, IT audit, IT risk management, data protection, organizational development
- Personnel responsibility: 4 FTE (direct)
Achievements/Results:
- Partner for IT security consulting.
- Department head for IT security audits and process management.
- Development of consulting products (service packages) in the field.
- Portfolio of various analysis services: business processes, information value, protection needs, risks, weaknesses, impacts.
- Quantification of IT risks.
- Consulting on the implementation of information security management systems (ISMS).
- IT security audits including penetration tests.
- SAP security consulting.
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Healthcare, Banking and Finance, Professional Services, Retail, Pharmaceutical, and Automotive.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Audit, Legal, Project Management, Human Resources, and Operations.
Summary
An experienced consultant in IT law, IT audit, and IT governance, risk and compliance (GRC), who turns compliance risks into strategic advantages and combines management skills with deep technical and legal expertise.
Proven success in reducing regulatory risk, closing compliance gaps, and turning legal obligations into practical, enforceable controls aligned with business needs.
Trusted guide at the intersection of GDPR, Data Act, AI Act, NIS-2, DORA, and ISO 27001, bridging legal, technical, and business requirements (360° view of converging topics). Bridge builder between the different relevant departments.
Special experience working with works councils and in complex stakeholder environments (CIOs, legal, compliance, business teams such as HR, IT, procurement ...).
Leadership experience: building, staffing, and leading departments for IT audit and GRC incl. information security and data protection.
Manager mindset -> risk-aware doer, not a risk-averse blocker.
Industry experience in finance, healthcare, (automotive) manufacturing, commodities (energy), wholesale. From upper mid-sized companies to global corporations.
Strong communication skills, high trustworthiness -> long-running projects.
My focus: reducing liability exposure, speeding up decisions, and ensuring sustainable compliance without blocking operations.
More than 25 years of proven IT-GRC experience in regulated industries: from strategy at C-level to hands-on implementation.
Skills
- It Law And Regulatory Compliance (Gdpr, Bdsg, Eprivacy, Nis-2, Dora, Ai Act, Data Act (Data Economy) And Related Legal Areas (Kwg, Betrvg And Many More))
- Data Protection (Dpias, Records Of Processing Activities, Handling Data Subject Rights, Handling Data Breaches And Authority Requests, Onetrust, Schleupen R2c)
- Information Security And Risk Management, Especially Third-Party Risk
- It Audit (Gap Analyses, Risk Analyses, Remediation Actions, Internal Controls, Supplier Audits)
- It Governance, Risk And Compliance Frameworks (Grc) (Iso 27001 And Related Standards, Iso 37301, Iso 42001, Cobit, Itil)
- Building Compliance Management Systems: Creating Company Policies And Operational Work Instructions Tailored To Target Groups, Role Assignment, Staff Selection
- Digital Transformation (M365, Ai Governance, Cloud Security, Negotiations With Works Councils)
- It Management To Turn The Above Into Usable It Services
Languages
Education
University of Oldenburg
Master of Laws · IT Law · Oldenburg, Germany
University of Essen
Diplom-Wirtschaftsinformatiker · Business Informatics · Essen, Germany
Certifications & licenses
AIGP: AI Governance Professional
CDPSE: Certified Data Privacy Solutions Engineer
CGEIT: Certified in the Governance of Enterprise IT
CIPP/E: Certified Information Privacy Professional/Europe
Cyber Security Practitioner
Microsoft M365 Security Administrator
SCRUM Master and Product Owner Training
Additional audit process competence according to the BSI Act (KRITIS)
Statistics
Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Daily Rate Distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Interim Manager IT Compliance
Nearby freelancers
Professionals working in or nearby Essen, Germany
