Who We Are
The privacy, data protection, and AI governance firm built for enterprise-scale complexity.
DPOBOARD is a privacy services and regulatory compliance firm offering technical, legal, and operational expertise to organizations navigating the regulatory, technical, and reputational stakes of operating across multiple jurisdictions.
Our Story
From a technology and compliance startup to a firm built for enterprise complexity.
DPOBOARD was founded in 2016 as a technology and compliance firm. Over the years since, we've evolved into a regulatory compliance and technology consulting firm with artificial intelligence at our core — built to meet the expectations of multinational organizations and large corporations operating across jurisdictions, not just a single regulatory regime.
We offer technical, regulatory, legal, and operational design, tools, solutions, and support to companies across every industry. Our focus is baking privacy into the very fabric of an organization — its services, its products, its decisions — built around data lifecycle management from collection through deletion. We believe privacy should be part of any organization's DNA, and that privacy compliance is how organizations earn trust: by protecting the fundamental rights and freedoms of individuals, without regard to their status.
Trust isn't assumed — it's built. Organizations earn it by establishing real trust principles, being transparent about data collection practices, and giving individuals genuine, informed control over their own data.
Giving Back
We believe in giving back to our community in the most meaningful way possible, through a range of ongoing initiatives — because a firm built on trust and protecting individuals' rights has a responsibility that extends beyond client work.
How We Work
Methodology over improvisation.
Every engagement follows the same underlying discipline, regardless of which pillar it sits in: understand how data and AI systems actually move through your organization first, then design controls around that reality — not a template built for a different kind of company.
That means we document our reasoning at every stage. A risk assessment, a governance decision, a compliance determination — each produces an evidentiary trail your team can point to when a regulator, auditor, or client asks how a decision was made. Programs that can't explain themselves don't hold up under real scrutiny; programs we build are designed to.
Global Reach
Built for organizations that don't operate in just one jurisdiction.
Multinational organizations don't get to pick one regulatory regime to comply with — GDPR, CCPA/CPRA, LGPD, PIPEDA, POPIA, the EU AI Act, and a growing list of AI-specific rules all apply simultaneously, often with conflicting requirements. We built DPOBOARD's methodology around reconciling that complexity into one coherent program, not a jurisdiction-by-jurisdiction patchwork.
That cross-jurisdictional fluency runs through our leadership team and how we staff engagements — matching the regulatory breadth of the client, not the convenience of a single-market advisory model.
Grounded in practice
Our guidance reflects how regulators actually enforce today — not just how frameworks read on paper.
Built to be defensible
We design programs that produce a clear evidentiary trail: documented decisions, assessments, and controls.
Partnered, not outsourced
We work alongside your legal, engineering, and executive teams so the program survives beyond any single engagement.
Leadership
The people leading DPOBOARD.
Executive Leadership

Tobi Kofi Kano
Chief Executive Officer

Kotryna Vanagas
EVP, General Counsel

Bruce Johnson
EVP, Chief Operating Officer

Lubanzi Khumalo
EVP, Chief Technology Officer

Lydia Kene-Williams
EVP, Chief Human Resources Officer
Board of Directors

Jakub Prochazka
Board Member and Chair

Nicole Lee
Board Member

Sean Jang
Board Member
We work across data privacy, data protection, and AI governance as one connected discipline.
See how each pillar comes together on our Services page.