Consultant for Data Protection and Information Security
Hilpoltstein, Germany
Experience
Jul 2020 - Present
5 years 2 months
Consultant for Data Protection and Information Security
DatenSchutzBeratung Dr. Kaufmann GmbH
Consulting and training on data protection and information security management systems.
Carrying out data protection and information security consulting in various projects:
ISMS implementation with successful ISO 27001 certification at a software manufacturer.
ISMS revision and certification preparation for ISO 27001 at an IT service provider.
Migration of ISMS to ISO 27001:2022 at a software manufacturer.
Data protection update at a medium-sized industrial company.
Fixed appointments:
Data Protection Officer (DPO) at a hospital.
DPO at a small software consulting firm.
Information Security Officer (ISO) at a healthcare software company.
May 2018 - Jun 2020
2 years 2 months
Vice President Corporate Data Protection (Chief Data Protection Officer)
LEONI AG
Building a data protection management system for accountability under GDPR.
Implementing data protection measures:
Introducing a global contract for internal data exchange within the group.
EU-wide data protection training.
Establishing and expanding the record of processing activities.
Setting up reporting channels and procedures for incidents and data protection requests.
Project support and audits.
Deleting data from an SAP HR system.
Internal Data Protection Officer of LEONI AG and external Data Protection Officer for 14 German subsidiaries.
Span of control: up to 1.5 full-time positions directly and up to 30 data protection coordinators functionally across various EU locations.
Apr 2010 - Apr 2018
8 years 1 month
Vice President Corporate Information Security (Chief Information Security Officer, Chief Data Protection Officer)
LEONI AG
Ensuring secure (confidential, integral, and available) and BDSG-compliant information processing.
Representing information security goals group-wide by building and running an information security management system:
Developing and introducing policies.
Raising awareness within the company.
Developing and implementing a mid-term plan for IT security technologies.
Conducting assessments and audits.
Preparing and supporting customer audits (e.g., VDA TISAX).
Leadership in the global data privacy compliance field.
Developing and updating data protection policies.
Monitoring proper use of data processing applications.
Span of control: up to 5 direct and up to 80 functional reports.
Dec 2005 - Dec 2006
1 year 1 month
Team Leader SAP Logistics
LEONI AG
Leading a team responsible for customizing and programming SAP R/3 logistics modules (PP, SD, MM, APO) for group companies.
Span of control: up to 10 direct reports.
Dec 2000 - Mar 2010
9 years 4 months
Consultant for Cross-Functional Roles in Central IT and Organization, later Manager IM Administration
LEONI AG
Building IT strategy, IT controlling, IT security, and project portfolio management.
Participating in the rollout of international transfer pricing for IT costs.
Supporting IT audits for annual financial statements.
Introducing ITIL elements in the Information Management area.
Creating and training a project management manual.
Assisting with the rollout of a group-wide intranet and ticket system.
Span of control: up to 3 direct reports.
Jun 1995 - Jul 2000
5 years 2 months
PhD in Business Informatics
Dissertation: “Design of a marketplace for heterogeneous components of enterprise application systems”.
Major subject/professional skills: Business Informatics.
Institution: Friedrich-Alexander University Erlangen-Nuremberg.
Jun 1995 - Jun 2000
5 years 1 month
Research Associate
Bayerisches Forschungszentrum für Wissensbasierte Systeme (FORWISS)
Participating in research: cooperative software development.
Conducting chair activities (Business Informatics I, Prof. Dr. Dr. h.c. mult. P. Mertens), including lectures.
Oct 1989 - May 1995
5 years 8 months
Diploma in Business Informatics
Institution: Technical University of Darmstadt (formerly Darmstadt University of Applied Sciences).
Summary
Consulting or training on data protection and information security, especially data protection or information security management systems.
Languages
German
Native
English
Intermediate
Education
Jun 1995 - Jul 2000
Friedrich-Alexander University Erlangen-Nuremberg
PhD in Business Informatics, Design of a marketplace for heterogeneous components of enterprise application systems · Business Informatics · Erlangen, Germany
Oct 1989 - May 1995
Technical University of Darmstadt
Diploma in Business Informatics · Business Informatics · Darmstadt, Germany