Privacy engineering and AI governance

Privacy and AI governance built into your systems, not just your policies.

Technical consulting for tech, fintech and health tech companies that need to turn data protection law and AI governance into controls that work in code, data and products.

Where compliance usually stays on paper

  • Deletion done by hand

    Deletion requests handled manually, with no assurance the data left backups, logs and vendors.

  • Retention nobody can state

    Retention periods that are undefined or not enforced automatically in your systems.

  • An inventory always out of date

    Data maps kept in spreadsheets, months behind what your systems actually do.

  • LLMs in production, untested

    Customer-facing AI chatbots launched without testing for personal data leakage, improper access or prompt injection.

Start with the diagnostic

A privacy engineering and AI governance maturity diagnostic. Team interviews, a review of your systems and a clear picture of where you stand and what to do first.

Duration
2–3 weeks
Deliverable
One-page report
Next step
90-day roadmap

8 dimensions assessed

  1. Data inventory and mapping
  2. Privacy by Design in the development lifecycle
  3. Data subject rights, deletion and retention
  4. Data sharing and vendors
  5. AI governance
  6. LLM guardrails and evaluations
  7. Incidents
  8. Program operations and metrics

Services

Fixed-scope projects, from diagnostic to implementation.

  • Maturity diagnostic

    Interviews, a one-page report and a 90-day roadmap.

    Estimated duration: 2–3 weeks

  • Personal data mapping and classification

    Inventory built from your systems, a classification taxonomy and an updated record of processing (LGPD art. 37).

    Estimated duration: 4–8 weeks

  • Vendor privacy assessment

    Risk tiers, questionnaire, processor clauses (LGPD art. 39) and first assessments.

    Estimated duration: 3–6 weeks

  • Privacy by Design in the product lifecycle

    A review process embedded in development, risk criteria and AI-assisted triage.

    Estimated duration: 4–8 weeks

  • Data subject rights and deletion engineering

    Retention schedule, technical design for data subject requests and deletion across systems, with assisted rollout.

    Estimated duration: 6–10 weeks

  • AI governance program

    AI inventory, risk classification, policies and approval flow (NIST AI RMF, ISO/IEC 42001 and the EU AI Act where relevant).

    Estimated duration: 4–8 weeks

  • LLM guardrails and evaluations

    Risk map, adversarial tests (leakage, improper access, prompt injection, toxic output), guardrails and a golden set.

    Estimated duration: 3–6 weeks

  • Privacy and responsible AI training

    A one-day workshop or a four-week track for engineering and product teams.

    Estimated duration: 1 day to 4 weeks

Pricing on request, based on scope.

Who it is for

Tech, fintech and health tech companies that process personal data at scale.

  • DPOs

    Who need technical evidence that deletion, retention and the data inventory actually work.

  • CISOs and security leaders

    Who want privacy and AI controls built into security, not run as a parallel program.

  • Product and engineering leaders

    Who are shipping AI features and need guardrails tested before customers find the gaps.

About

I'm Fred Gomes. I trained as a lawyer, have worked in digital law since 2011 and in privacy and data protection since 2018.

From 2024 to 2026 I was a Privacy Engineer in Uber's EngSec team, applying Privacy by Design to products and services and building internal automations with LLMs.

Privacy Seed brings both sides together: a precise legal reading of the LGPD, the GDPR and the EU AI Act, and the ability to implement controls in real systems. I lead every engagement myself, from diagnostic to delivery.

What we don't do

To be clear about where Privacy Seed adds value:

  • Acting as your DPO (DPO as a Service).
  • Legal opinions and litigation.
  • Implementing or configuring SaaS privacy platforms.
  • Paper-only compliance: policies and notices without implementation.
  • Open-ended hourly staffing without a defined scope.

Let's talk

Book a 30-minute call or send a message. I reply within two business days.

Send a message

We use this data only to reply to you. Privacy notice