Your Interim Privacy & Compliance Counsel for Germany and the EU
Your legal bridge into the German and EU market — pragmatic support embedded in your team and your development projects, from quick assessments to interim mandates of up to 12 months.
German attorney (Rechtsanwältin) for IT law, privacy and compliance. I don't slow innovation down — I make it legally possible.

Legal should carry projects forward — not hold them back.
0
Practicing since
0+
completed projects
0
working languages: EN / DE / PL
0
certified disciplines
Data breach or cyber attack? I'm available 24/7.
In a security incident you don't need memos — you need clear decisions. I help immediately with legal triage, the 72-hour breach notification deadline and coordinating next steps.
- Cyber attack & ransomware
- Data breach
- Authority order
- 72-hour notification deadline
Services
One counterpart for privacy, IT law, security, AI and crisis management
A single project, a standing mandate, an interim role or an acute emergency inside your team — you always get senior-level work with no hand-offs and no law-firm ping-pong.
Interim Privacy & Compliance Counsel
Embedded legal support for 3 to 12 months — remote or hybrid, right inside your team.
Learn moreCrisis management & incident response
Fast legal triage for data breaches, cyber attacks and authority orders — available around the clock.
Learn morePrivacy & GDPR advisory
From stocktaking to privacy by design inside product development.
Learn moreExternal Data Protection Officer
Appointed external DPO for companies in Germany and the EU.
Learn moreAI & emerging tech compliance (EU AI Act)
AI Act readiness, risk classification and governance for AI products.
Learn moreIT law & contracts
Contracts that match agile delivery and cloud reality.
Learn moreIT security & NIS2
Security governance that survives audits and customer questionnaires.
Learn moreWhistleblowing & HinSchG
Set up and run an internal reporting channel with confidence.
Learn moreAudits & data protection reviews
Hard evidence instead of gut feeling — for customers, investors and authorities.
Learn moreEU & German market entry
Entering the German or EU market? I'm your local legal counterpart — in your language, in your time zone overlap, embedded in your team.
Learn more
How I work
Three engagement models that fit real teams
You decide how much legal capacity you need and when. I adapt to your project rhythm, not the other way round.
- 01
Project-based
Fixed scope with a defined outcome: a DPIA, EU AI Act readiness, a contract package, a privacy audit or a gap assessment.
Fixed deliverable · a few days to several weeks
- 02
Interim / fractional counsel
I work embedded in your team — in your tools, your stand-ups, your projects. Parental-leave cover, project peaks, building a privacy or compliance function from scratch.
1–5 days per week · 3 to 12 months
- 03
Retainer & external officer roles
Ongoing support as your external Data Protection Officer, whistleblowing officer, IT security officer or AI officer, with agreed response times.
Monthly retainer · open-ended
Why easydatenschutz
Legal that speaks product
I come from the reality of software, data and AI projects. So you don't get memos nobody can implement — you get decisions your team can build on.

Alicja Wilczek, German attorney and certified privacy & compliance specialist. Since 2018 I have helped companies navigate data protection, IT law, AI compliance and crisis management — pragmatic, solution-oriented and in your language.
Tech-savvy and inside the project
I join sprints, tickets and architecture reviews. Privacy by design happens where the product is actually built.
An enabler, not a blocker
Instead of "not allowed", you get a legally sound path: options, risk assessment and a clear recommendation.
Three languages, one standard
English, German and Polish — for international teams, group headquarters and German authorities alike.
One partner across four disciplines
Privacy, IT security, whistleblowing and AI governance in one consistent framework, with no gaps between advisors.
Senior level, no hand-offs
You always talk to me. No rotating associates, no internal escalation chains.
Fast and pragmatic
A reply within 24 hours on business days, and assessments in days rather than weeks.
Credentials
Certified in five disciplines
The officer roles companies need to fill today — covered by one person.
- Certified External Data Protection Officer
GDPR-certified external DPO for companies in Germany and across the EU.
- Certified Data Protection Auditor
Certified for privacy audits, vendor audits and gap assessments.
- Certified IT Security Officer
Certified for security governance, policies and incident response support.
- Certified Whistleblowing Officer
Certified under the German Whistleblower Protection Act (HinSchG) for reporting channels.
- Certified AI Officer & AI Governance Manager
Certified for AI governance and the EU AI Act, including risk classification frameworks.
FAQ
What to know before we work together
How is interim counsel different from a traditional law firm?
I work embedded in your team, in your tools and rhythms. Instead of isolated opinions, you get practical decisions that can be implemented immediately — no handovers, no back-and-forth.
How quickly can you start?
For urgent incidents I am available within hours. For interim or project mandates, a start within 1–2 weeks is usually possible, depending on current capacity.
Do you work on-site or remotely?
Both. Many mandates run hybrid or fully remote — especially for international teams. For kick-offs, workshops or crisis situations I am also available on-site when needed.
What does a retainer or interim mandate cost?
It depends on scope, duration and responsibilities. Projects are quoted with a fixed scope; interim mandates are usually billed on a daily or half-day basis. I will prepare a tailored option in a short intro call.
Which languages do you work in?
German, English and Polish — written and spoken, including authority correspondence and contract negotiations with international partners.
Free download
GDPR & AI Act checklist for development projects
The questions I ask first in software and AI projects — as a compact checklist for your product and engineering team.
- Privacy by design: what to settle before the first commit
- Roles, processing agreements and international transfers
- AI Act risk classification in five steps
Placeholder PDF — the final edition follows. No newsletter, no sharing with third parties.
Let's talk about your project
30 minutes, free and without obligation. Afterwards you'll know whether and how I can help.
