Nils Deschrijver

Data Protection Consultant | GDPR | DPIA | Data Breaches  •  Legal Engineer

Jurist and ethical hacker from 🇧🇪 (NL/ENG). DPO-certified and digital architecture expert. Former lawyer and security consultant. Now freelancing, but also open to in-house roles.

Tulpenlaan 15, 2180 Antwerpen, België
BTW: BE 0839.88.36.06
Nils Deschrijver

Projects

Project logo

Zelf-loodgieter.be: coded an e-commerce platform with integrated data analytics

Coded in Python using Flask-RESTX, SQLAlchemy, SendGrid, Mollie, and the Google Analytics Measurement Protocol. Deployed on a bare-metal VPS after configuring the system and setting up a database following star schema best practices.

Privacy by Design and by Default were central to this fully GDPR-compliant project. Web application and server security, as well as the drafting of legal compliance documentation, were handled in-house.

In collaboration with a Belgian building materials wholesaler and an Antwerp-based trade school.

Project logo

Confidential: Coordinated Vulnerability Disclosures

Regularly identify security vulnerabilities in the wild, and then report them to the CCB/CERT and the responsible parties, under whistleblower protection legislation ('Klokkenluiderswet'), helping controllers patch their systems and properly secure personal data.

One such vulnerability, which exposed database records from dozens of companies, earned me a place in the Belgian Centre for Cybersecurity (CCB) Hall of Fame for cybersecurity researchers::

Project logo

EP Votes: coded a mobile app to track plenary voting results

A light-weight but powerful office tool that searched for, read through and analysed scores of plenary voting results of the European Parliament. Coded in Python and Bash using regex, for usage in the EU bubble during COVID. The tool was able to source the voting results before they were officially published, using hacking enumeration techniques.

Education

Academy of European Law (ERA) | Certificates

2016 - 2016

Ghent University | Master of Laws

2009 - 2011

Ghent University | Bachelor of Laws

2006 - 2009

Work Experience

Self-employed | Legal Engineer

November 2024 - Present

As a DPO-certified jurist and ethical hacker whose contributions were recently recognised by the Belgian Centre for Cybersecurity (CCB), I deliver comprehensive GDPR expertise, combining deep technical proficiency with a strong background in data analytics and security:

  • Proactive advice on data protection requirements and related legal compliance paperwork
  • Tech-savy input for Data Protection Impact Assessments (DPIAs) to aid your IT and business teams in assessing and mitigating risks and avoiding fines
  • Guiding adherence to the Privacy by Design principle, providing early warning on GDPR implications of technical implementations avoiding a costly code refactor or system overhaul
  • Similarly, guiding adherence to the Privacy by Default principle for database and system administration configurations and access management policies
  • Managing data breach responses and any reputational fall-out, in addition to being your point-of-contact for authorities
My approach provides clients with a distinctive blend of compliance assurance, technical resilience, and advanced risk mitigation.

Johnson & Johnson | Security Consultant

February 2022 - Augustus 2024

Drafting security risk assessments on which the senior management relied to determine their (cyber)security posture in war zones or during crises. Bridged the gap between the legal, cybersecurity, and political affairs teams as the dedicated point-of-contact for the US headquarters.

In the lead for drafting and implementing JnJ's first global digital strategy, encompassing the creation of Python scripts and Power BI dashboards to collect, process, and visualise internal and external datasets, compliant with GDPR requirements.

Belgian Armed Forces | Security Consultant

September 2019 - September 2021

Drafting security risk assessments in tandem with ADIV, the Belgian military intelligence service. Held a BE, EU, and NATO SECRET security clearance.

Completed specialised training at NATO School and the Belgian Intelligence and Security School in open-source intelligence (OSINT) collection and analysis, encompassing methodologies relevant to digital forensics, think: digital reconnaissance and fingerprinting.

European Parliament | Legal Advisor

November 2014 - May 2019

Contributed to legislation within the Civil Liberties, Justice and Home Affairs Committee (LIBE), amending legislative texts and negotiating security-related files with the Commission, Parliament, and Council of Ministers during the period of GDPR legislative development, when data protection considerations were cemented in Europe's DNA.

Worked on a flagship project with emphasis on information exchange between European police and intelligence services.

Self-employed | Lawyer

September 2011 - November 2014

Advised businesses on IT law compliance, including drafting End-User License Agreements (EULAs) and Software-as-a-Service (SaaS) agreements. Managed data breaches and cyber extortion by black hat hackers, including issuing takedown notices. Provided legal counsel on data-related matters, pre-dating GDPR, and other business topics, and represented businesses in court.

Head back to the top