Who We Are

The firm that builds and governs privacy, data protection, and AI programs at enterprise scale.

DPOBOARD delivers the technical, regulatory, legal, and operational expertise multinational organizations and large corporations need to manage privacy, data protection, and AI risk — and, where the work calls for it, to build the AI systems that run those programs — across every jurisdiction they operate in.

Our Story

From a technology and compliance startup to a firm built for enterprise complexity.

DPOBOARD was founded in 2016 as a technology and compliance firm. Over the years since, we've evolved into a regulatory compliance and technology consulting firm with artificial intelligence at our core — built to meet the expectations of multinational organizations and large corporations operating across jurisdictions, not just a single regulatory regime.

We offer technical, regulatory, legal, and operational design, tools, solutions, and support to companies across every industry — and where an engagement calls for it, we design and build the AI systems and automated workflows that run those programs day to day. Our focus is baking privacy, data protection, and responsible AI governance into the fabric of an organization — its systems, its products, its decisions — built around how data and AI actually move through a business, from first collection to deletion, from a model's first design decision to its retirement. We believe that discipline should be part of any organization's DNA, and that getting it right is how organizations earn trust: by protecting the rights and interests of the people whose data and decisions are at stake, regardless of where they sit in the world.

Trust isn't assumed — it's built. Organizations earn it by establishing real trust principles, being transparent about data collection practices, and giving individuals genuine, informed control over their own data.

Giving Back

We believe in giving back to our community in the most meaningful way possible, through a range of ongoing initiatives — because a firm built on trust and protecting individuals' rights has a responsibility that extends beyond client work.

How We Work

Methodology over improvisation.

Every engagement follows the same underlying discipline, regardless of which pillar it sits in: understand how data and AI systems actually move through your organization first, then design controls around that reality — not a template built for a different kind of company.

That means we document our reasoning at every stage. A risk assessment, a governance decision, a compliance determination — each produces an evidentiary trail your team can point to when a regulator, auditor, or client asks how a decision was made. Programs that can't explain themselves don't hold up under real scrutiny; programs we build are designed to.

Global Reach

Built for organizations that don't operate in just one jurisdiction.

Multinational organizations don't get to pick one regulatory regime to comply with — GDPR, CCPA/CPRA, LGPD, PIPEDA, POPIA, the EU AI Act, and a growing list of country-specific AI rules all apply simultaneously, often with conflicting requirements. We built DPOBOARD's methodology around reconciling that complexity into one coherent program, not a jurisdiction-by-jurisdiction patchwork.

That complexity isn't only international. Inside the United States alone, privacy and AI regulation has become a genuine patchwork of its own — comprehensive privacy laws now in force in California, Virginia, Colorado, Connecticut, Utah, and a growing list of other states, each with its own thresholds and obligations, alongside a newer wave of state-level AI laws governing automated decision-making, algorithmic discrimination, and high-risk AI use cases. We track that state-by-state landscape with the same rigor we apply to GDPR or the EU AI Act, because for a client operating nationally, it's every bit as consequential.

That cross-jurisdictional fluency runs through our leadership team and how we staff engagements — matching the regulatory breadth of the client, not the convenience of a single-market advisory model.

DPOBOARD is a US-based firm, headquartered in Mount Prospect, IL. For engagements that reach beyond the US, we work through a network of partners in markets including Canada and the EU — grounding each region's obligations in real local expertise rather than a US-centric read of foreign law.

Grounded in practice

Our guidance reflects how regulators actually enforce today — not just how frameworks read on paper.

Built to be defensible

We design programs that produce a clear evidentiary trail: documented decisions, assessments, and controls.

Partnered, not outsourced

We work alongside your legal, engineering, and executive teams so the program survives beyond any single engagement.

Leadership

The people leading DPOBOARD.

Executive Leadership

Tobi Kofi Kano

Tobi Kofi Kano

Chief Executive Officer

Kotryna Vanagas

Kotryna Vanagas

EVP, General Counsel

Bruce Johnson

Bruce Johnson

EVP, Chief Operating Officer

Lubanzi Khumalo

Lubanzi Khumalo

EVP, Chief Technology Officer

Lydia Kene-Williams

Lydia Kene-Williams

EVP, Chief Human Resources Officer

Board of Directors

Jakub Prochazka

Jakub Prochazka

Board Member and Chair

Nicole Lee

Nicole Lee

Board Member

Sean Jang

Sean Jang

Board Member

We work across data privacy, data protection, AI governance, and AI solution development as one connected discipline.

See how each pillar comes together on our Services page.

We use cookies to run this site. Necessary cookies are always on; functional, analytics, and marketing cookies are off unless you choose to enable them. See our Privacy Statement for details.