Skip to content
Penby

Data protection and AI governance your team can run.

Embedded in your operations. Accountable for your compliance.

Who you'll work with

A practice of two

No juniors, no handovers, and the same two practitioners on your work from scoping to sign-off.

Principal

Andy Williamson MBCS

Founder & Principal Consultant

Thirty years advising regulated organisations, including investment banking, telecoms, and critical national infrastructure. BCS Practitioner Certificate in Data Protection. IAPP member.

Learn more about Andy
Andy Williamson, Founder of Penby
Ola Degteva, Marketing Analyst and Compliance Specialist
Principal

Ola Degteva MBCS

Marketing Analytics & Compliance

Ten years leading GDPR-compliant marketing analytics for regulated businesses. BCS Practitioner Certificate in Data Protection. MA in Teaching.

Learn more about Ola
What we do

Fractional DPO and AI governance

Engagements run in three stages:
Diagnose · Build · Transfer.

01.Core service

Fractional DPO

A DPO embedded in your operations, named to the ICO.

Your data protection obligations require an accountable practitioner. A fractional Data Protection Officer fills that role, embedded in your operations and named to the ICO where required. No escalation to a partner you'll never speak to. The practitioner who advises you is the practitioner of record.

Learn more
Editorial ink and wash illustration of a Georgian doorway — featured image for Fractional DPO services
Editorial ink and wash illustration of a modern glass building reflecting an older stone courthouse — featured image for AI Governance services
02.Core service

AI Governance

Governance for the AI systems your organisation uses.

AI systems that process personal data carry regulatory obligations. We work with you to build your governance frameworks, complete impact assessments, and document the decisions before a gap becomes an incident. Covering UK GDPR through to emerging AI regulation.

Learn more
Why Penby

How the engagement is structured

The build phase ends

Most fractional DPO engagements run as continuous custody, with the provider retained indefinitely. Penby is built around a finite build phase that ends with operational ownership inside your team.

One practitioner, throughout

The practitioner who scopes your engagement is the practitioner who signs off your DPIA. Nothing is relayed, re-briefed, or learned twice.

Begin with a conversation

An initial, no-commitment discussion of your obligations, your current exposure, and how Penby could support you.

Arrange a call