Governance · Data protection · AI · Digital sovereignty

Data and AI governance as a competitive advantage for business.

Ethical Data and AI Governance Advisor at DAMA Brazil, co-founder of Privacidade+, and Lead Auditor for ISO/IEC 27001, 27701, and 42001 standards. Three decades of experience at the intersection of technology, data, and law.

Our Journey
Consuelo Rodrigues
Who is Consuelo

An articulator between Technology and Compliance, uniting adherence to laws and standards with Data and AI solutions.

She spent over two decades at pharmaceutical multinationals such as Sanofi, Boehringer Ingelheim, and Merial, with assignments in Campinas, Lyon, and the United States. She led systemic integrations, M&A projects, and FDA and SOX validations before transitioning into the data protection field.

Currently a co-founder of Privacidade+, she works in Data and AI Governance at Keyrus and was appointed as the Ethical Data and AI Governance Advisor to the presidency of DAMA Brazil for the 2026-2028 term. Her strength lies in articulating technology and compliance, translating one field into the other and building high-performance teams.

Track Record

Three decades at the intersection of technology, data, and rights.

Nov 2022 — Present

Keyrus — Data and AI Governance Lead

Leading teams and initiatives in Artificial Intelligence Governance, focused on the integration of Data and AI Strategies, AI Agents, Trustworthy AI, and Data Sovereignty.

Sep 2020 — Present

Privacidade+ — Co-Founder and Steering Committee Member

Acting as DPO as a Service (Data Protection Officer) and leading complex Risk Management projects (based on ISO 27005) and Change Management.

Jul 2018 — Oct 2018

CTC (Centro de Tecnologia Canavieira) — IT Business Partner

Leading data projects in the sugar-energy sector, using Artificial Intelligence and geolocation data.

Jan 2017 — Feb 2018

Boehringer Ingelheim — IT Senior Executive Manager (Brazil)

As a member of the Leadership Committee, leading the redesign and transition of the IT team following a major global merger and acquisition (M&A).

Feb 2012 — Sep 2014

Sanofi — Head of IT Office for Latin America and Executive PMO Latin America (M&A and Integration)

Responsible for project portfolio governance, security, and compliance across 5 group companies, holding an executive seat on Brazil's steering committee for 3 years. Led the systems integration between Merial and Sanofi, managing a program with over 200 resources and 23 vendors for SAP implementations.

Nov 1999 — Dec 2016

Merial — IT Executive Business Partner (LATAM), BI and Commercial Excellence Leader (LATAM), IT Executive Project Manager (Lyon, France), IT Relationship Manager and IT Application Leader

During the swap period (Sanofi-Boehringer), she was responsible for the Information Systems strategy and delivery models in Latin America, as a member of the Leadership Committee. She directed the Business Intelligence (BI) strategy, delivering practical analytical results to the regional sales force. In France, she managed a multicultural global team (USA, France, and India) on a Business Process Transformation project. She led Data Governance for ERP implementations and conducted budgeting and FDA validation projects (the US regulatory agency) in Latin America. She became IT leader for Brazil at the age of 24.

Apr 1997 — Oct 1999

Rhodia Mérieux — Senior Systems Analyst

Managing the Year 2000 (Y2K) program, leading 8 simultaneous projects, in addition to working on data modeling and business glossary development.

Jan 1994 — Apr 1997

Datasul / Pro-Ação — Datasul Systems Analyst

Working as a developer (SQL, Progress) specializing in the construction of complex Data Modeling.

Depth

The breadth of what was observed along the way.

Thirty years in complex corporate environments have included tenures at some of the world's largest companies, projects across seven countries, and hands-on mastery of dozens of frameworks, standards, and platforms. The foundation of this work today is the strategic integration of these layers.

Industries and Verticals

  • Agribusiness
  • Research Institute
  • Technology, Data and AI
  • Human Pharmaceuticals
  • Veterinary Pharmaceuticals
  • Pulp and Paper
  • Services

Geographies

  • Brazil
  • France (Lyon)
  • United States
  • Mexico
  • Argentina
  • Uruguay
  • Germany

Frameworks and Experience

  • PMBoK · PMI
  • COBIT · ITIL
  • Six Sigma · Scrum
  • Sarbanes-Oxley
  • FDA · ANVISA · MAPA
  • GAMP · RenovaBio
  • SAP · Oracle
  • Salesforce · OneTrust
Practice Areas

Four interconnected pillars.

01

Data Governance

Structuring data as an organizational asset. Modeling, quality, lifecycle, roles, and responsibilities. Work anchored in the DAMA-DMBOK2 framework, tailored to the specificities of the Brazilian market.

DAMA-DMBOK2 · ISO 8000
02

AI Governance

AI management systems based on international standards. Trustworthy AI principles applied to real-world cases: responsible, fair, privacy-by-design, robust, explainable, and transparent.

ISO/IEC 42001 · NIST AI RMF 1.0 · EU AI Act
03

Data protection and privacy

LGPD and GDPR compliance programs with an integrated technical-legal approach. DPO as a Service, data processing mapping, legal basis determination, safeguards, and internal auditing.

LGPD · GDPR · ISO/IEC 27701
04

Digital sovereignty

A critical analysis of the infrastructure underpinning the data of Brazilian citizens and businesses. Extraterritorial laws, dependency on hyperscalers, REDATA, the Government Cloud, and the limits of effective control over our own assets.

Cloud Act · FISA · Five Eyes · REDATA
Institutional Authority

Recognitions and credentials.

  • 2026 to 2028

    Ethical Data and AI Governance Advisor — DAMA Brazil

    Brazilian chapter of the Data Management Association International. Presidential mandate focused on national maturity in data governance and responsible AI.

  • 2021 to 2024

    Member — Privacy and Data Protection Commission, OAB-SP

    Project management and leadership at the intersection of legal and cybersecurity domains, featuring educational deliverables such as web series and webinars published by the Jornal da Advocacia.

  • Since 2020

    Co-founder — Privacidade+

    Specialized consultancy in LGPD and GDPR compliance programs, ISO/IEC 27001, risk management (ISO/IEC 27005), and personal data governance.

  • Since 2020

    Member — APDADOS

    National Association of Data Privacy Professionals, a member of the Brazilian privacy ecosystem.

  • Certifications

    Lead Auditor ISO/IEC 27001, 27701 and 42001

    Qualified to audit management systems for information security, information privacy, and artificial intelligence. Complementary certifications: Exin DPO, PDPF, PDPP, ISMP, ISO/IEC 27005:2019.

  • Professional Training & Certification

    Executive MBA — Fundação Dom Cabral

    Business Administration and Management. Postgraduate degree in Project Management from FGV. Bachelor’s degree in Systems Analysis from PUC-Campinas.

Certifications

Certifications.

Technical credentials underpinning the work in governance, privacy, and auditing.

  • Logo Exemplar Global, Inc.

    AI Compliance Manager

    Exemplar Global, Inc.
    Issued Nov 2025Credential ID 1042334335
  • Logo Exemplar Global, Inc.

    ISO/IEC 42001:2023 Lead Auditor, Artificial Intelligence Management System (AIMS)

    Exemplar Global, Inc.
    Issued Jun 2024Credential ID 104234-339
  • Logo Exemplar Global, Inc.

    ISO/IEC 27701:2022 Lead Auditor, Privacy Information Management System (PIMS)

    Exemplar Global, Inc.
    Issued Set 2023Credential ID 104234-294
  • Logo Exemplar Global, Inc.

    ISO/IEC 27001:2022 Lead Auditor, Information Security Management System (ISMS)

    Exemplar Global, Inc.
    Issued Jul 2023Credential ID 104234-293
  • Logo TIexames

    EU Artificial Intelligence Act e ISO/IEC 42001:2023

    TIexames
    Issued Abr 2024Credential ID 2676024
  • Logo TIexames

    ISO/IEC 27005:2019, Gestão de Riscos de Segurança da Informação

    TIexames
    Issued Abr 2021Credential ID 104234-215
  • Logo TIexames

    Green IT, com destaque para descarte de dados pessoais de forma segura

    TIexames
    Issued Fev 2021Credential ID 125138
  • Logo EXIN

    EXIN Certified Data Protection Officer

    EXIN
    Issued Nov 2020Credential ID 72319
  • Logo EXIN

    EXIN Information Security Officer

    EXIN
    Issued Nov 2020Credential ID 72319
  • Logo Informatica

    Informatica Data Quality Implementation Practitioner

    Informatica
    Issued Set 2023
  • Logo Alation

    Alation Professional Implementer

    Alation
    Issued Mar 2024Expires Mar 2028
  • Logo Opice Blum Academy

    Data Breach, Plano de resposta a incidentes de dados pessoais

    Opice Blum Academy
    Issued Ago 2021Credential ID 51ce8441-d657-4b3d-80ee-97e1ea7b92d6
Publications

Published books and articles.

Authored contributions to works on Digital Law and Governance.

  • 01

    GALANI, Consuelo Milani Rodrigues. Contexto Prático: Como empresas podem se preparar para Governança de Inteligência Artificial. In: LIMA, Ana Paula Canto de; CERQUEIRA, Milla; HACKEROTT, Nadia (coord.). Guia Prático do Direito Digital. São Paulo: Thomson Reuters, 2025. p. 117-130.

    The author explores the six pillars of Trustworthy AI, accountability, fairness, privacy, robustness, explainability, and transparency, and proposes a clear methodology that cross-references the tool's degree of autonomy with five levels of corporate and social risk. To operationalize this journey, the text translates major global frameworks, such as the ISO/IEC 42001 standard, the NIST AI RMF 1.0, and the European EU AI Act legislation, into practical implementation steps for companies.

  • 02

    GALANI, Consuelo Milani Rodrigues. Diálogo da LGPD com Governança de Dados, de acordo com o DAMA-DMBOK V2. In: LIMA, Ana Paula Canto de (Org.). Diálogos de Direito e Tecnologia. v. 2. Rio de Janeiro: Editora Império, 2025. p. 235-249.

Reference Library

The frameworks underpinning our work.

Legal frameworks, technical standards, and frameworks that guide practices in data governance, data protection, and AI governance. Open-source material for those entering the field and for those seeking to understand the references cited in the texts.

LGPD
Law 13.709/2018, Brazil
GDPR
EU Regulation 2016/679
EU AI Act
EU Regulation 2024/1689
Cloud Act
United States, 2018
FISA
Foreign Intelligence Surveillance Act
Marco Civil da Internet
Law 12.965/2014
ISO/IEC 27001
Information security
ISO/IEC 27701
Information privacy
ISO/IEC 27005
Risk management
ISO/IEC 42001
AI management system
ISO 8000
Data quality
DAMA-DMBOK2
Data Management Body of Knowledge
NIST AI RMF 1.0
AI Risk Management Framework
OECD AI Principles
OECD AI Principles
REDATA
Federal Government Data Network
Contact

Three paths, three stakeholders.

Press Office

For Journalists

Requests for interviews or expert commentary on data protection, AI, and digital sovereignty.

Consulting

For Enterprises

LGPD, ISO 27001, and ISO 42001 programs, DPO as a Service, data governance, and AI governance. Requests are routed via Privacidade+ or Keyrus, depending on the scope.

Events and Keynotes

For Data Stewards

Invitations for panels, keynotes, lectures, and board memberships. Privacy, data protection, AI governance, digital sovereignty.