You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Nataly SilvaNS

Nataly Silva

Data Privacy Consultant | Specialist e

€250/day
Franca, BR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Nataly

Specialist in Privacy, Information Security, and Data Governance, with strong command of regulations such as GDPR, LGPD, ISO/IEC 27001, and 42001. Experience in structuring and automating privacy and GRC programs, using platforms such as OneTrust, Privacy Tools, and Securiti.ai for advanced management of ROPA, DPIA, DSARs, consent, cookies, third parties, and incidents.

Implementation of policies, workflows, audits, compliance metrics, and dashboards. Focused on risk control, regulatory compliance, and operational sustainability, serving organizations in Latin America and Europe.
  • Portuguese

    Native or bilingual

  • English

    Conversational

  • Spanish

    Conversational

Remote only
Primarily works remotely

Experience

  • ISH TECNOLOGIA
    Senior GRC Consultant / OneTrust Specialist
    April 2022 - Today (4 years and 2 months)
    Specialist in GRC, Privacy, and Data Protection, with strategic performance in the management and administration of the OneTrust platform. Responsible for the technical implementation of privacy programs based on automated and integrated flows, ensuring efficiency, traceability, and regulatory compliance (LGPD, GDPR). Worked with large national and multinational organizations such as Banco Itaú, Mercedes-Benz, CNJ, Sebrae, Grupo Águia Branca, Waelzholz Brasmetal, and CredSystem.

    Expertise in ServiceNow, with queue management, call prioritization, and technical evolution of demands in cyber risk environments. Robust experience in tuning and operating the main OneTrust modules:

    • ROPA: automation of mappings, inventory, and treatment plan, with conducting interviews and technical survey;
    • DPIA/RIPD/LIA: creation of models and visibility rules;
    • Consent and Cookies: parameterization via Web/API, banners with geolocation rules, and compliance scanners;
    • Incidents: structuring forms and attributes for violation management;
    • Third Parties: supplier evaluation, controls, and contract inventory;
    • Policies: document management, versioning, target audience, and reading control;
    • DSAR: automated workflows, integration with Data Discovery and APIs;
    • Audits: customization of criteria, attributes, and evidence governance.

    Development of dashboards, reports, KPIs, and indicators for decision-making. Administration of users, permissions, and segregation of profiles with a focus on information security and access control.
  • SODIMAC (VIA CONSULTORIA VITARA)
    DPO as a Service – Autonomous
    November 2021 - April 2022 (5 months)
    • Acting as DPO as a Service, supporting the structuring and execution of the organization's privacy program, focusing on compliance with the LGPD and good data governance practices;
    • Conducting interviews with business and technical areas for detailed surveying of data processing operations, with structured registration in the ROPA (Record of Personal Data Processing Operations) via the OneTrust platform;
    • Supporting the legal team in the analysis of contractual clauses focusing on data protection, collaborating in the identification of points of attention and proposing recommendations to ensure adherence to the LGPD in contracts with suppliers and partners;
    • Supporting the mapping, categorization, and classification of personal and sensitive data, defining purposes, and identifying risks related to processing;
    • Responsible for the operationalization of the OneTrust tool, using modules such as ROPA, DSAR, Consent, and Cookies to support data governance and compliance with the LGPD;
    • Active participation in the organization's Privacy Committee, collaborating with technical and strategic guidance, aligning actions between areas, and evolving data governance practices;
    • Preparing technical reports and recommendations for improving policies, flows, and internal controls related to privacy and data protection.
  • 9NET TI, TELECOM E SERVIÇOS
    Internship in Privacy and Data Protection
    August 2021 - November 2021 (3 months)
    • Supporting the initial implementation of the OneTrust platform in projects to adapt to the LGPD, with participation in the survey of information for the inventory of personal data;
    • Legal research on the fundamentals of the LGPD, the rights of data subjects, and the obligations of controllers and operators;
    • Participating in interviews with clients to collect information about data flows, documents, and internal processes;
    • Supporting the legal team in reviewing contracts and privacy policies, focusing on clauses related to data protection;
    • Contributing to operational tasks of document organization and versioning of compliance and privacy materials.

Recommendations

Be the first to recommend Nataly

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Postgraduate
    Faculdade i9 Educação
    Pós-Graduação
  • Postgraduate
    Faculdade i9 Educação
    Pós-Graduação

Skill set

Categories