Compliance that creates value, not overhead.
GDPR and the AI Act only feel bureaucratic when you run them as a separate process alongside the business. Built as a system of the processes you already have, how you scope a product, pick a vendor or ship a release, they stop being overhead and start paying back: cleaner data, clear ownership, and answers ready before a customer or auditor asks.

Taavi Klooren
A data protection leader with a decade in law and privacy — building trustworthy data and AI practices across European financial services. Four years as Data Protection Officer at SEB, now Group Head of Privacy at ESTO, with a legal foundation from the University of Tartu.
What we do
Two practices, one standard of rigour — data protection and AI governance, delivered hands-on.
Data protection
Data processing mapping, DPIAs, documentation, an outsourced DPO, risk management and data security, and training — built to last and maintained as your organisation changes.
GDPR services →AI governance
Assessment and risk classification, high-risk readiness for providers and deployers, governance and operating model, vendor and contract work, and training.
AI Act services →