Skip to content

    One team for the risks created by data, technology and AI.

    We are an independent Digital Compliance consultancy working with organisations of all sizes across Europe and the Gulf, from multinationals with complex needs to smaller companies with specialist requirements. Data protection, cybersecurity and resilience, AI governance, digital and AI transformation, and research and EU projects, delivered by the people you meet.

    Oslo 59.91°N · Copenhagen 55.68°N · Warsaw 52.23°N · Dubai 25.20°N34.7° of latitude, one practice
    § 01work we can talk about

    Engagements, with the outcome the client cleared us to publish.

    view case studies

    Telecommunications, Scandinavia

    Rebuilt a Scandinavian telecommunications operator's privacy programme after two years of fragmented internal effort.

    2 years

    of prior in-house effort reassessed and rebuilt into one roadmap

    Hospitality, retail and entertainment technology

    Provided a statutory, multi-jurisdictional DPO function without adding permanent specialist headcount.

    Multi-jurisdiction

    one privacy framework covering the client's global operations

    Telecommunications, Nordics

    Delivered independent security assurance and an ISO 27001 ISMS for a Nordic telecommunications provider.

    ISO 27001

    policy and ISMS delivered on the standard's structure

    § 02the live signal
    § 03trusted by leading organisations

    4

    offices

    Europe and the Gulf

    100+

    engagements

    delivered since 2018

    15+

    industries

    finance, telco, health, public

    17

    practitioners

    four of them partners

    § 04what we do

    Two regulatory worlds. One team.

    Most firms know Brussels or they know the Gulf. Clients operating in both end up translating between two sets of advisers. We do that translation as a matter of course.

    all services

    01

    Data protection

    Governance that survives contact with the business: maturity assessment, DPO as a service, transfers, and records that reconcile to reality.

    EuropeGDPR · ePrivacy · Digital Omnibus
    The GulfDIFC DP Law · ADGM Regs · UAE PDPL · Saudi PDPL
    02

    Cybersecurity & resilience

    Board-level risk framing, CISO as a service, third-party risk, and the evidence trail that makes an incident defensible rather than existential.

    EuropeNIS2 · DORA · CRA · ISO 27001
    The GulfUAE IA Standards · NCA ECC (KSA) · Qatar NIA
    03

    AI governance

    Inventory, classification, conformity and oversight for AI that is already in production, and a defensible answer for the systems still on the roadmap.

    EuropeAI Act · ISO/IEC 42001 · GPAI Code
    The GulfDIFC Regulation 10 · SDAIA AI Framework · UAE Charter
    04

    Digital & AI transformation

    AI enablement of GRC, legal, compliance and risk operations: assisted review, automated evidence and control mapping, agent-supported vendor due diligence, and the operating model that keeps it defensible.

    EuropeAI Act · ISO/IEC 42001 · EU Data Act
    The GulfDIFC Regulation 10 · SDAIA framework · UAE AI Strategy
    05

    Research & EU projects

    Horizon Europe consortium work on privacy-preserving technology, AI in the public sector, and mobility data spaces.

    EuropeHorizon Europe · EDPB guidance
    The GulfCross-border transfer research
    § 05who you work with

    The people you meet are the people who deliver the work.

    Engagements are led by partners, not routed to them. Lawyers, security specialists and engineers sit in one team, so the legal reading and the technical implementation come from the same table.

    meet the team

    MG
    Magdalena Góralczyk
    André Årnes
    FM
    Federico Marengo
    NP
    Nicholai Pfeiffer

    Partner

    Magdalena Góralczyk

    Head of Data Protection

    Former Global Lead Privacy Counsel at Nokia; PhD on anonymity and identity.

    linkedin

    Partner

    André Årnes

    Head of Cybersecurity

    Seven years as Global CSO of Telenor Group; Professor of information security at NTNU.

    linkedin

    Associate Partner

    Federico Marengo

    Head of AI Governance

    Built the AI governance framework at a FTSE 100 group; author of “Privacy and AI”.

    linkedin

    Managing Partner

    Nicholai Pfeiffer

    Europe and the Gulf

    Former Group Privacy Officer at Telenor Group; led one of Scandinavia's largest GDPR programmes.

    linkedin

    read full profiles

    § 06our platform
    Pritect

    Objective advice, with technology when implementation requires it.

    Our engagements do not depend on a particular platform, and Pritect is never a condition of working with us. Where a client needs to operationalise governance, evidence and recurring workflows, Pritect is the infrastructure that sustains what we build together: data protection, AI governance, cybersecurity and enterprise risk on one shared record.

    explore the platform

    Days

    time to value

    not quarters

    60 to 85%

    below legacy GRC cost

    per seat, per year

    17

    frameworks, one record

    mapped, not duplicated

    4

    modules

    DP, AI, cyber, ERM

    § 07the enforcement field

    Regulators in Europe and the Gulf are now writing the same sentence in two languages.

    Published decisions from EU supervisory authorities, shown next to the Gulf regimes now in force. Where an authority publishes no case register, as in most of the GCC, we state the statutory exposure rather than invent a fine.

    region

    sector

    period

    2016to 2025

    published fines in view

    €3.26bn

    Across 15 decisions in view, plus 9 regimes in force.

    largest in view

    Meta Platforms Ireland

    Transfers of EU user data to the US without adequate safeguards

    Data Protection Commission · Ireland · 2023 · Art. 46(1)

    cumulative, 2016 to date

    every published decision in view, rankedEUR, millions
    Gulf regimes in force, statutory exposuresources checked 2026-08-14

    Cross-border transfers out of the Kingdom

    Cross-sector
    Saudi Arabia · 2024
    SDAIA

    regime in force
    Administrative penalties under the PDPL; transfer risk assessment mandatory

    Controllers processing Saudi personal data

    Cross-sector
    Saudi Arabia · 2023
    SDAIA

    regime in force
    Up to SAR 5m, doubled on repeat; imprisonment for unlawful disclosure

    Operators of autonomous and semi-autonomous systems

    AI / technology
    UAE, DIFC · 2023
    DIFC Commissioner of Data Protection

    regime in force
    Enforcement under the DIFC DP Law fining schedule

    Omani controllers

    Cross-sector
    Oman · 2022
    Ministry of Transport, Communications and IT

    regime in force
    Up to OMR 500,000 (approx. EUR 1.2m)

    ADGM-licensed entities

    Financial services
    UAE, ADGM · 2021
    ADGM Office of Data Protection

    regime in force
    Up to USD 28m under the ADGM DP Regulations 2021 penalty schedule

    Federal-scope controllers

    Cross-sector
    UAE, Federal · 2021
    UAE Data Office

    regime in force
    Set by Cabinet Decision; executive regulations still pending

    DIFC-registered controllers and processors

    Cross-sector
    UAE, DIFC · 2020
    DIFC Commissioner of Data Protection

    regime in force
    Fines set in the DP Regulations schedule; unlimited general fining power

    Bahraini controllers

    Cross-sector
    Bahrain · 2018
    Personal Data Protection Authority

    regime in force
    Up to BHD 20,000 and imprisonment up to one year

    Qatari controllers

    Cross-sector
    Qatar · 2016
    National Cyber Security Agency

    regime in force
    Up to QAR 5m (approx. EUR 1.2m)

    § 08readiness diagnostic

    Eight questions. An honest score, given unconditionally.

    No email wall, no lead form in front of the result. Answer, see where you actually stand across four axes, and read what the weakest one costs you.

    § 09the session, recomposed
    § 10in their words

    Ready to protect your organisation?

    Leave us a note and we will get back to you. Our consultants are ready to discuss your data protection, cybersecurity and AI governance needs.

    get in touch

    newsletter

    Stay informed about our services, offerings and the latest developments in data protection, cybersecurity and AI.

    subscribe