Human-Centric GRC | Privacy Governance | Just Culture

SHELL-Privacy

MEDA-Privacy

Frameworks

"The human being at the center of the system."

Stop blaming people. Start fixing systems. The aviation-grade GRC framework for privacy governance and organisational resilience.

3
Frameworks
4
Languages
7
Certifications
AA
Anderson Andrade
MBA | DPO | CISO | GRC Leader
Applying SHELL-Privacy™ and MEDA-Privacy™ Frameworks
Available in
🇨🇦 EN🇫🇷 FR🇧🇷 PT🌎 ES

Compliance Without Culture Is Just Theatre

Most organisations have the policies. Few have the culture. When people hide mistakes instead of reporting them, no audit, firewall, or compliance checklist will save you.

The Old Way
  • Incidents are hidden out of fear of punishment
  • Root causes remain undiscovered and unaddressed
  • The same mistakes happen repeatedly across teams
  • Compliance fines and reputational damage keep increasing
Just Culture Way
  • Psychological safety encourages open reporting
  • Systemic root causes are identified and fixed
  • Organisations learn continuously and improve culture
  • Proactive governance reduces risk and regulatory exposure
0.07
Fatal accidents per million flights
Aviation's Just Culture
Now applied to Data Privacy
82%
Data breaches involve human error
Act I · The Incident

It starts with a single click.

A Monday morning. An employee opens an email that looks legitimate. One click. Ransomware spreads across the network. The company loses access to critical data.

📧
Employee clicks phishing link
Ransomware deployed across the network
🔥
Company fires the employee
"We found the culprit. Problem solved."
😶
Fear spreads through the team
Report rate drops from 70% to 30%
📈
Incidents increase 40%
The real vulnerability was never fixed

70% of security incidents involve human error — yet the standard response is to punish the human, not fix the system.

What if aviation had taken the same approach?

We would never have reached 99.999% safety.

Act II · The Frameworks

Aviation solved this 50 years ago.

Three frameworks, adapted from aerospace safety science, now applied to privacy governance and GRC. Each one answers a different question.

Retrospective Analysis

What in the SYSTEM failed?

Instead of asking "who failed?", SHELL forces us to map every contributing factor across 5 system interfaces. In a phishing case, 26 factors were identified — none of them were "the employee was careless."

73% reduction in incidents after SHELL implementation
S
Software40%

Applications, systems, tools — was the email filter updated?

H
Hardware15%

Devices, infrastructure — was the workstation patched?

E
Environment30%

Culture, policies — was there a reporting culture?

L
Liveware-Self10%

The individual — training, fatigue, cognitive load

L
Liveware-Others5%

Team, communication — was the threat shared?

Three frameworks. One methodology. One question remains:

What does this look like in the real world?

Act III · The Transformation

Select your industry

TechMed Solutions. 500 employees. 22 incidents per month.

story.act3.intro.healthcare

Before
22
incidents per month
Blame culture — employees hide mistakes
Only 30% of incidents reported
Root causes never identified
Same vulnerabilities exploited repeatedly
After 6 Months 6 Months
6
incidents per month
Just Culture — people report without fear
85% report rate — full visibility
Systemic root causes identified & fixed
179% ROI in the first year
0%
Reduction in security incidents
0%
Return on investment
0%
Employee report rate
0mo
Implementation timeline

TechMed is not unique. These results replicate across industries — healthcare, finance, retail, manufacturing, government. Anywhere humans interact with systems, Just Culture works.

The question is not whether it works. The question is: when does your organization start?

The Full Methodology

Everything you just read is in the book.

The SHELL-Privacy™ and MEDA-Privacy™ frameworks — with templates, decision trees, case studies, and step-by-step implementation guides — documented in full.

Aviation-Adapted Frameworks

GRC Built Around Human Behaviour, Not Just Checklists

The SHELL-Privacy™ and MEDA-Privacy™ frameworks bring aviation's Just Culture methodology into privacy governance — helping organisations move from reactive compliance to genuine accountability.

SHELL Framework — 5 Interfaces Diagram
Visual Reference

SHELL Framework — 5 Interfaces

shell.diagram.caption

S SoftwareH HardwareE EnvironmentL Liveware-SelfL Liveware-Org
Modelo do Queijo Suíço + NIST 800-53 — SHELL-Privacy™
Conceptual Foundation

Swiss Cheese Model + NIST 800-53

Each NIST 800-53 control family is a slice of Swiss cheese — with its own holes. An incident occurs only when the holes align across multiple layers. SHELL-Privacy™ investigates why those holes exist in the first place.

"NIST 800-53 maps the cheese. SHELL-Privacy™ investigates why the cheese has holes."

ACIAATSIIR

SHELL-Privacy™

Systemic Analysis

Analyze the 4 critical interfaces: Software, Hardware, Environment, and Liveware.

S
Software
H
Hardware
E
Environment
L
Liveware
L
Liveware (Org)

MEDA-Privacy™

Root Cause Investigation

A structured investigation process to find root causes, not scapegoats.

01
M
Maintenance Error
02
E
Error Type
03
D
Decision
04
A
Action

PEAR Model

Human Factors Model

Used in lectures, training & workshops

Contextualize every incident by analyzing People, Environment, Actions, and Resources — a human factors model adapted from aviation to privacy governance.

P
People

Who was involved? Training, experience, fatigue, cognitive biases, and human limitations that influenced the incident.

E
Environment

What was the context? Physical, organizational, regulatory, and cultural conditions surrounding the event.

A
Actions

What was done or omitted? The specific behaviors, decisions, and omissions that contributed to the incident.

R
Resources

What tools were available? Technology, time, information, and support that were present or absent during the incident.

Just Culture Approach

"Stop blaming people. Start fixing systems."

Inspired by aviation's proven safety culture — where incidents are learning opportunities, not punishments. Applied to privacy governance and GRC.

Applying SHELL-Privacy™ and MEDA-Privacy™ Frameworks
Prefaces by
Prof. Davis Alves, PhD.
President APDADOS
Dr. Aulus Eduardo Souz, PhD
DPO | Lead Auditor ISO 14001
The Book

Ready to Transform Your Security Culture?

Join hundreds of organizations adopting the Just Culture approach.

✈️
Aviation-Adapted
SHELL, MEDA & PEAR frameworks from aerospace safety
🌍
4 Languages
English, French, Portuguese, Spanish
📋
Practical Tools
Templates, checklists, and investigation guides
🎓
Expert Prefaces
Prof. Davis Alves, PhD & Dr. Aulus Eduardo Souz, PhD
Available on Amazon
The Person Behind the Frameworks
Anderson Andrade — GRC Consultant
Anderson Andrade
GRC Consultant
Canada
DPOGRCEXIN ×7PIPEDAGDPRLGPD

Anderson Andrade

For 14 years, Anderson practiced law. He drafted contracts, navigated regulations, and watched organizations invest millions in compliance — only to remain vulnerable.

The pattern was always the same: when something went wrong, someone got fired. The fear spread. People stopped reporting. The real vulnerabilities stayed hidden. And the incidents kept coming.

Then he found aviation. An industry that achieved 99.999% safety — not by punishing pilots, but by designing systems that learn from every error. That insight changed everything.

"Security and privacy are, at their core, human challenges — not technical ones."

— Anderson Andrade
14+ Years
Legal & Compliance Experience
5+ Years
Privacy GRC & Governance
7
EXIN Certifications
4
Books Published (EN/PT/FR/ES)
1,000+
Professionals Trained
Several
Companies Served as DPO as a Service
2010

Law Degree — UNIBH

Graduated in Law from Centro Universitário de Belo Horizonte. Beginning of a 14-year legal career focused on compliance and organizational protection.

2012

Postgraduate — Mining & Environmental Law

Specialized in Regime Jurídico dos Recursos Minerais e Hídricos at Faculdade Milton Campos. Deepened understanding of regulatory frameworks and systemic risk.

2018

Privacy Default Consulting — Founded

Founded Privacy Default Consulting to help organizations build privacy and security cultures that create competitive advantage through trust, not just regulatory compliance.

2019

DPO & LGPD Implementation — Clinicarx

Led full LGPD implementation at Clinicarx, training 100% of 50+ employees. Worked with major pharmaceutical industry players across Brazil on data protection contracts and negotiations.

2020

Vice-Coordinator — APDADOS/PR

Elected Vice-Coordinator of APDADOS (National Association of Data Privacy Professionals) in Paraná. Advocated for professionals, delivered courses, and established partnerships with SEBRAE/PR and major organizations.

2021

DPO as a Service — Multiple Sectors

As DPO as a Service at Brotto Campelo Advogados, implemented LGPD across medium and large organizations in healthcare, government, manufacturing, real estate, startups, retail, and hospitality — including Biotrop, SESI Paraná, and organizations in São Paulo and Santa Catarina. Trained 1,000+ employees.

2022

Co-author — Bill PL-4/2022

Co-authored Bill PL-4/2022 at APDADOS, proposing tax incentives for LGPD compliance investments. Submitted to the Brazilian Federal Senate — translating field experience into national policy.

2024

SHELL-Privacy™ & MEDA-Privacy™ — Publication

After years observing how blame culture undermined privacy governance, adapted aviation's Just Culture methodology to GRC. Published 4 books in EN/PT/FR/ES. The frameworks are now used in conferences, workshops, and consulting engagements worldwide.

2025

MBA — Information Security Management

Enrolled in MBA in Information Security Management at FACINT, deepening expertise in SOC analysis, ethical hacking, risk management, and PMBOK. Continuing to bridge legal, human, and technical dimensions of security.

INSIGHTS & RESEARCH

Evidence-Based Perspectives on Privacy Governance

Grounded in law, human factors research and 15+ years of GRC practice.

Privacy by Design
Privacy by Design12 min

Privacy by Design Is Not Philosophy — It Is Systems Engineering

Ann Cavoukian's 7 principles are now legal obligations in GDPR, LGPD, and PIPEDA. Most organisations treat them as intent. SHELL-Privacy™ maps each principle to a specific organisational interface with concrete, auditable actions.

Privacy by DesignSHELL-Privacy™GDPRLGPDPIPEDAAnn Cavoukian
DPO & Compliance
DPO & Compliance7 min

The DPO Who Doesn't Update Protects No One

Certifications expire in practice, not on paper. Since 2022, ANPD, EDPB, PIPEDA and Quebec's Law 25 have all shifted. Four critical gaps — incident management, RoPA, AI governance, SARs — and why accumulating badges solves none of them.

DPOLGPDGDPRPIPEDAContinuous LearningSHELL-Privacy™
Human Factors & GRC
Human Factors & GRC10 min

Human Factors in Cybersecurity & SHELL-Privacy™

Aviation achieved 99.999% safety not by punishing pilots, but by designing systems that learn from every error. SHELL-Privacy™ applies the same systemic logic to data privacy incidents.

Human FactorsSHELL-Privacy™Just CultureGRCCybersecurity
AI & GRC
AI & GRC8 min

The Human Gap in the AI Security Framework Landscape

NIST AI RMF, EU AI Act, ISO 42001 — none of them answer the question the regulator asks first: what did the human do, or fail to do? SHELL-Privacy™ and MEDA-Privacy™ fill the missing layer.

AI SecuritySHELL-Privacy™MEDA-Privacy™Human FactorNIST AI RMF
GRC & Compliance
GRC & Compliance12 min

LGPD and the SHELL-Privacy™, MEDA-Privacy™ and PEAR Frameworks: A Comparative Analysis

The LGPD defines what organisations must do. The SHELL-Privacy™, MEDA-Privacy™ and PEAR frameworks provide the how — mapping the human, systemic and investigative dimensions that the law demands but does not detail.

LGPDSHELL-Privacy™MEDA-Privacy™PEARANPD
AI & GRC
AI & GRC8 min

AI Governance Cannot Wait: Why Mature GRC Is the Foundation for Responsible AI

As AI systems make decisions faster than humans can review them, mature governance frameworks become the only sustainable path. The PEAR model offers a human-centred lens for AI risk classification.

AI GovernanceGRCHuman FactorsPEAR
Just Culture
Just Culture6 min

From Blame Culture to Just Culture: How MEDA-Privacy™ Transforms Privacy Incident Response

When employees hide mistakes for fear of punishment, no audit or firewall will save you. MEDA-Privacy™ replaces the punitive cycle with a structured investigative process that turns incidents into organisational learning.

Just CultureBlame CultureMEDA-Privacy™Privacy Governance
Human Risk
Human Risk10 min

Awareness Is Not Enough: The Structural Gap That Training Platforms Do Not Solve

Verizon DBIR 2024 shows 68% of breaches involve the human factor — yet security awareness spending grows every year. The problem is not the training. It is the question being asked. SHELL-Privacy™ investigates why the system failed, not just who clicked the wrong link.

ConscientizaçãoSHELL-Privacy™Fator HumanoGRCLGPD
OPSEC & SHELL
OPSEC & SHELL8 min

StravaLeaks: When a Running Watch Exposes a Nuclear Aircraft Carrier

A French Navy officer jogged 35 minutes on the deck of the Charles de Gaulle. His Strava profile was public. Within 24 hours, a newspaper located the carrier in near real-time. No hacker. No cyberattack. Just a habitual behavior in a system without proportional controls. SHELL-Privacy™ analysis across 5 interfaces.

OPSECSHELL-Privacy™Human RiskPrivacy by DesignSwiss Cheese

Want to go deeper?

The book covers all three frameworks in detail, with case studies, templates and implementation guides.

SHELL-Privacy™ on YouTube
SHELL-Privacy™
@SHELLPrivacy

Privacy, GRC & Just Culture — in plain language

Episodes on LGPD, GDPR, PIPEDA, cybersecurity incidents, and human-centric governance. Videos in Portuguese · Subtitles in EN · FR · ES.

"Be inspired and fly."

GET IN TOUCH

Contact

Interested in lectures, workshops, consulting or partnerships? Send a message.

Anderson Andrade

MBA | DPO | CISO | GRC Leader
Privacy Default Consulting

"The human being at the center of the system."
Topics
LecturesWorkshopsConsultingDPO ServicesGRCPartnerships
Cookie Settings

We use cookies to improve your experience and analyse site traffic. As a DPO-led platform, we take your privacy seriously — in compliance with LGPD, GDPR, and PIPEDA. Learn more

LGPD · GDPR · PIPEDA compliant · DPO: Anderson Andrade