Skip to content

    Europe · Copenhagen, Oslo, Warsaw

    One governance, risk and compliance team for the European rulebook.

    European regulation now reaches every part of how an organisation uses data, technology and AI. We help groups operating across the EU and the UK turn GDPR, NIS2, DORA and the EU AI Act into one set of controls, run by people who have held the roles themselves.

    discuss an engagement →

    § 01The rules we cover

    Law by law.

    The regulations overlap more than they differ. We map them once, build shared controls, and show where each one asks for something genuinely new.

    01

    GDPR and UK GDPR

    Records, legal bases, DPIAs, international transfers, data subject rights and the DPO role
    02

    NIS2

    Risk management measures, incident reporting, management body accountability and national transpositions
    03

    DORA

    ICT risk management, incident classification, resilience testing and third-party ICT risk for financial entities
    04

    EU AI Act

    AI inventories, risk classification, prohibited practices, high-risk obligations and general-purpose AI
    05

    Data Act

    Data access and sharing obligations for connected products and cloud switching
    06

    Cyber Resilience Act

    Security requirements and vulnerability handling for products with digital elements
    07

    Digital Services Act

    Transparency, notice and action, and risk assessment obligations for online services
    § 03Who leads it
    01
    Nicholai Pfeiffer, Managing Partner, White Label Consultancy

    Managing Partner

    Nicholai Pfeiffer

    Managing Partner

    Nicholai has 20+ years of experience across governance, risk and compliance in the technology and telecommunications industries, spanning legal operations, regulatory affairs, procurement and compliance. He has served as Compliance Officer in previous roles and acts as interim Compliance Officer for WLC clients. At Telenor Denmark he was Legal Director and Chief Procurement Officer, leading the regulatory and legal stream of the network-sharing agreement with Telia and two spectrum auctions, after earlier roles as Head of Legal and Regulatory and Regulatory Affairs Manager. He then served 5 years as SVP, Chief Privacy Officer of Telenor Group, where he led one of the largest GDPR programmes in Scandinavia and advised executive management. Nicholai holds a Master of Law degree from the University of Copenhagen and the CIPM certification.

    02
    Magdalena Góralczyk, Partner, Head of Governance, Compliance and Data Protection, White Label Consultancy

    Partner

    Magdalena Góralczyk

    Partner, Head of Governance, Compliance and Data Protection

    Before joining WLC, Magdalena served as the Global Lead Privacy Counsel for Nokia. Prior to that she was Vice President for Privacy in a global telecom. She has advised international organisations on legal developments globally, including implementation of privacy controls for ad tech, vendor management efforts, and free data flow regulations. Her data protection experience is rooted in her PhD on the concept of anonymity and identity.

    03
    André Årnes, Partner, Head of Cybersecurity, Resilience and Risk, White Label Consultancy

    Partner

    André Årnes

    Partner, Head of Cybersecurity, Resilience and Risk

    André joined WLC as a Partner in January 2022, after having served 7 years as the Global CSO of Telenor Group. He has 20+ years of experience within security leadership, cybersecurity, and digital forensics. André is also a part-time Professor at the Norwegian Technical University (NTNU) Department of Information Security and Communication Technology.

    04
    Federico Marengo, Associate Partner, Head of AI and Transformation, White Label Consultancy

    Associate Partner

    Federico Marengo

    Associate Partner, Head of AI and Transformation

    Federico is a leading expert in the intersection of AI, privacy, and regulatory compliance. Before joining WLC, he led the development and implementation of the AI governance framework at Informa Plc, a FTSE 100 company. Federico is a lawyer with an LLM from the University of Manchester and a Ph.D. in Privacy and AI from Bocconi University. He is the author of "Privacy and AI" (2023) and "GDPR in Charts" (2021).

    European work is led by Nicholai Pfeiffer from our offices in Copenhagen, Oslo and Warsaw. See office addresses and phone numbers, or meet the full team.