Architect of data, compliance and AI governance.

One role, five pillars: data governance, privacy/DPO, AI, cybersecurity — proven in the most demanding sectors, including health. KDPO builds the system that makes data trustworthy, not just compliant.

Scoping diagnostic in 2 to 4 weeks.

Regulatory framework
  • RGPD
  • IA Act
  • NIS2
  • DORA
  • HDS

One profession

Governance, privacy, AI and cybersecurity are not four separate services. They are the faces of a single role — designing the system that makes data trustworthy. Health is where that system is proven under the highest demands.

Sensitive data environments become more complex, more exposed, more monitored

Organisations must be able to demonstrate their control before an audit, a partnership, a fundraising, a product launch or a sensitive decision.

Multiplied flows

The number of data flows grows with every partnership, platform, integration or product.

Documentary requirements

CNIL and EDPB now expect documented, dated, enforceable evidence — not principles.

Partner demands

Clients, investors and partners require a documented governance posture before signing.

AI Act and traceability

Algorithmic systems must justify their datasets, training basis and oversight loop.

NIS2, DORA and beyond

Security and resilience obligations extend their own evidence chain to maintain.

Proof beats principle

Auditability, governance and traceability decide outcomes — declarations alone do not.

Scoping diagnostic

The recommended entry point. In 2 to 4 weeks, KDPO produces an actionable picture of the sensitive data environment: scope, risks, priorities, trajectory.

The diagnostic is not a theoretical exercise. It is a decision tool.

The deliverables are tangible, enforceable and mobilisable in an audit, a partnership, a due diligence or a sensitive decision.

Request a diagnostic
Duration
2 to 4 weeks
Deliverables
  • Scoping note
  • Initial mapping of treatments
  • Risk matrix
  • Documented arbitrations
  • Prioritised action plan
  • Remediation trajectory
Method
Targeted interviews, document review, flow analysis, risk qualification
Client effort
Limited and framed

A progressive intervention trajectory

Three progressive intervention phases. The diagnostic produces the reading. Taking control produces the control framework. The continuous steering maintains its governance.

  1. 01

    Scoping diagnostic

    See the system

    Map the flows, identify risks, grey zones, missing documents and priority arbitrations.

  2. 02

    Taking control

    Document, arbitrate, secure

    Document, prioritise, secure, structure governance and produce the required evidence.

  3. 03

    Continuous steering

    Sustain governance

    Maintain governance, follow regulatory shifts, prepare audits, partners and sensitive decisions.

Concrete situations

01

Multi-entity group — Governance

Trigger
Data scattered across divisions. No shared definitions. No ownership. Uneven quality.
KDPO action
Governance diagnostic. Business dictionary, catalogue, ownership and stewardship, quality indicators.
Outcome
A managed data asset: shared definitions, clear owners, measured quality across the group.
02

Industrial SME — Cybersecurity

Trigger
NIS2 preparation. Unaudited subcontracting chain. No formalised security governance.
KDPO action
Scoping diagnostic. Security governance mapping. Vendor audit. Breach response procedure.
Outcome
Documented, enforceable security posture. Subcontractors audited and contractually realigned.
03

SaaS scale-up — DPO

Trigger
Investor due diligence on RGPD posture. No record of processing. No DPIA.
KDPO action
Outsourced DPO mandate. Minimum enforceable baseline: record, prioritised DPIA, vendor DPAs.
Outcome
Documented compliance posture ahead of fundraising. Governance designed to last.
04

Software editor — AI

Trigger
Scoring system to qualify under the AI Act. Training dataset lawfulness unclear.
KDPO action
Scoping diagnostic. AI Act obligations by risk level. Privacy by design on the training base.
Outcome
Prioritised compliance plan. Lawful, documented training base. Defensible AI lifecycle.
05

Medical device editor — Health

Trigger
CE marking preparation. AI Act qualification pending. Reimbursed remote-monitoring device.
KDPO action
Scoping diagnostic. RGPD × MDR × AI Act articulation. Security audit of the device.
Outcome
Integrated regulatory dossier. Documented device security. Defensible product lifecycle.

Illustrative situations built from patterns commonly encountered in sensitive data environments.

What KDPO produces

Demonstrable compliance

System documented, enforceable, auditable.

Trust

Credible framework for regulators, clients and partners.

Resilience

Incident response capacity, continuity maintained.

Innovation capacity

Controlled framework enabling robust innovation.

An expertise built at the intersection of data, risk and governance

KDPO was founded by Kouakou Mensah, a data protection and data governance consultant with over ten years of experience, specialised in designing information governance systems.

His background spans data and AI governance, security by design and impact assessments across the pharmaceutical industry, medical devices, insurance and regulated data environments — with a practice centred on mapping processing activities, building reference frameworks, and coordinating across management, IT, security, legal and business teams.

KDPO, active since 2018, extends this practice: turning scattered requirements into explicit responsibilities and mobilisable evidence — designing the organisation that durably protects data.

Get in touch

For a scoping diagnostic or a question on your exposure to sensitive data regulation.

contact@kdpo.fr
KDPO
42 cours Pierre Vasseur
91120 Palaiseau