Privacy engineering and AI governance
Privacy and AI governance built into your systems, not just your policies.
Technical consulting for tech, fintech and health tech companies that need to turn data protection law and AI governance into controls that work in code, data and products.
Where compliance usually stays on paper
Deletion done by hand
Deletion requests handled manually, with no assurance the data left backups, logs and vendors.
Retention nobody can state
Retention periods that are undefined or not enforced automatically in your systems.
An inventory always out of date
Data maps kept in spreadsheets, months behind what your systems actually do.
LLMs in production, untested
Customer-facing AI chatbots launched without testing for personal data leakage, improper access or prompt injection.
Start with the diagnostic
A privacy engineering and AI governance maturity diagnostic. Team interviews, a review of your systems and a clear picture of where you stand and what to do first.
- Duration
- 2–3 weeks
- Deliverable
- One-page report
- Next step
- 90-day roadmap
8 dimensions assessed
- Data inventory and mapping
- Privacy by Design in the development lifecycle
- Data subject rights, deletion and retention
- Data sharing and vendors
- AI governance
- LLM guardrails and evaluations
- Incidents
- Program operations and metrics
Services
Fixed-scope projects, from diagnostic to implementation.
Maturity diagnostic
Interviews, a one-page report and a 90-day roadmap.
Personal data mapping and classification
Inventory built from your systems, a classification taxonomy and an updated record of processing (LGPD art. 37).
Vendor privacy assessment
Risk tiers, questionnaire, processor clauses (LGPD art. 39) and first assessments.
Privacy by Design in the product lifecycle
A review process embedded in development, risk criteria and AI-assisted triage.
Data subject rights and deletion engineering
Retention schedule, technical design for data subject requests and deletion across systems, with assisted rollout.
AI governance program
AI inventory, risk classification, policies and approval flow (NIST AI RMF, ISO/IEC 42001 and the EU AI Act where relevant).
LLM guardrails and evaluations
Risk map, adversarial tests (leakage, improper access, prompt injection, toxic output), guardrails and a golden set.
Privacy and responsible AI training
A one-day workshop or a four-week track for engineering and product teams.
Pricing on request, based on scope.
Who it is for
Tech, fintech and health tech companies that process personal data at scale.
DPOs
Who need technical evidence that deletion, retention and the data inventory actually work.
CISOs and security leaders
Who want privacy and AI controls built into security, not run as a parallel program.
Product and engineering leaders
Who are shipping AI features and need guardrails tested before customers find the gaps.
About
I'm Fred Gomes. I trained as a lawyer, have worked in digital law since 2011 and in privacy and data protection since 2018.
From 2024 to 2026 I was a Privacy Engineer in Uber's EngSec team, applying Privacy by Design to products and services and building internal automations with LLMs.
Privacy Seed brings both sides together: a precise legal reading of the LGPD, the GDPR and the EU AI Act, and the ability to implement controls in real systems. I lead every engagement myself, from diagnostic to delivery.
What we don't do
To be clear about where Privacy Seed adds value:
- Acting as your DPO (DPO as a Service).
- Legal opinions and litigation.
- Implementing or configuring SaaS privacy platforms.
- Paper-only compliance: policies and notices without implementation.
- Open-ended hourly staffing without a defined scope.