You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Marcus DesouzaMD

Marcus Desouza

Data Privacy and GDPR Expert (CIPP/E and CISSP)

€463/day
London, GB
3-7 years

Average response time: 1 hour

About Marcus

I am a data protection and information security specialist holding both CIPP/E and CISSP certifications. I aim to help organisations understand the interrelation between data protection and information security, and develop strategies and frameworks to maintain compliance with applicable data protection laws.

I also seek to demonstrate to organisations how they can leverage a robust data protection and information security programme to cultivate value and differentiate themselves from competitors in the market.

My preference for a working environment is remote; however, I'm open to on-site opportunities where necessary.
  • English

    Native or bilingual

Remote only
Primarily works remotely

Experience

  • Sophos Limited
    Senior Data Privacy Paralegal
    March 2025 - Today (1 year and 3 months)
    • Act as lead privacy legal support in a fast-paced cybersecurity environment, ensuring compliance with global data protection legislation and regulation, including GDPR, CCPA/CPRA, emerging U.S. state laws and other jurisdictions. Drafting and negotiating complex DPAs, including cross-border data transfer mechanisms (e.g., SCCs, UK IDTA), in support of SaaS, MSSP, OEM, Distribution and Channel Partner agreements.
    • Providing governance and managing risk for engaging with suppliers and product development of solutions utilising Generative AI.
    • Partner with security engineers and product teams to embed privacy-by-design into products and solutions.
    • Oversee DPIAs for high-risk processing activities related to threat telemetry, user behaviour analytics, and automated incident response systems.
    • Manage regulatory audits and liaise with supervisory authorities regarding compliance inquiries, breach reporting, and data subject rights.
    • Coordinate privacy reviews of internal tools and third-party vendors, integrating privacy risk assessments with the company's broader cybersecurity risk management processes.
    • Design and deliver targeted privacy training to information security, sales, and marketing teams, bridging the gap between legal obligations and technical execution.
    • Contribute to policy development on data retention, encryption, access controls, and secure data sharing in alignment with industry best practices (NIST, ISO 27001, etc.).
  • Brunel University London
    Data Protection Advisor
    March 2023 - June 2023 (3 months)
    • Drafting and reviewing the university's IT policies and processes.
    • Promoting and embedding the data protection strategy, associated policies, and procedures across the university's Professional Services Directorate.
    • Managing data subject rights requests received by the university, ensuring compliance with its legal obligations.
    • Handling the university's personal data incident response procedure, investigating potential breaches, collating evidence to support notification to the UK ICO per the UK GDPR, and ensuring that all breaches, including notification decisions, are recorded and all relevant breaches are notified.
    • Supporting the DPO to manage the privacy compliance programme by supporting data mapping, conducting data protection impact assessments of new projects/services and scoring this against relevant frameworks, and drafting policies and procedural documents for University staff.
    • Ensuring the robustness of all data protection due diligence processes and that they can be applied and enforced within all partnership and supplier contracts that may require the sharing of personal data.
  • HCA International Limited
    Data Protection Advisor
    March 2022 - January 2023 (10 months)
    • Responsible for conducting and managing all the DPIAs initiated by HCA Healthcare UK.
    • Drafting and updating policy documents regarding the formal DPIA process across the entire organisation.
    • Providing GDPR training, with a specific focus on the data protection and security concerns faced within the health industry, to staff across a number of healthcare facilities.
    • Responding to and handling SARs received from patients and former employees.

Recommendations

Be the first to recommend Marcus

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Certification Consortium Certified Information Systems Security Professional (CISSP)
    The International Information System Security
    2025
    Certification Consortium Certified Information Systems Security Professional (CISSP)
  • Certified Information Privacy Professional/Europe (CIPP/E)
    International Association of Professionals
    2025
    Certified Information Privacy Professional/Europe (CIPP/E)

Certifications

  • CIPP/E
    IAPP
    EU Compliance Europe GDPR lawyer
  • CISSP
    The International Information System Security Certification Consortium
    IT-Security Cybersecurity

Skill set

Categories