Privacy & AI Governance
Looking for an experienced DPO or specialist advice on GDPR and AI governance?
How We Can Help
From individual assessments to ongoing advisory and DPO support.
Outsourced DPO
We provide independent advice and compliance monitoring as your outsourced Data Protection Officer (DPO). We support your organisation with training and guidance on Data Protection Impact Assessments (DPIAs). We also act as a contact point for supervisory authorities and individuals exercising their data protection rights.
GDPR Compliance
We review how your organisation handles personal data and help implement the measures needed for compliance with the General Data Protection Regulation (GDPR). This includes legal bases, records of processing activities, internal policies and procedures aligned with your business processes.
GDPR Compliance Review
We assess your data protection practices, documentation and safeguards against GDPR requirements. You receive a report identifying gaps, priorities and recommended actions.
Gap AnalysisEU GDPR Representative
We act as an EU representative for organisations established outside the EU that require representation under Article 27 GDPR. We provide a contact point for supervisory authorities and individuals, handling enquiries and requests relating to personal data processing.
Article 27 GDPRPrivacy Training
We deliver training tailored to your organisation, using practical examples from everyday work. Sessions cover handling personal data, recognising privacy risks and responding to requests from individuals.
Specialist Privacy Advisory
DPIA · TIA · Data Processing Agreements · Privacy by Design
We advise on complex GDPR matters, including Data Protection Impact Assessments (DPIAs), international data transfers and Transfer Impact Assessments (TIAs). We also advise on Data Processing Agreements (DPAs) and the integration of data protection into the design of products and services.
AI Governance
We help organisations assess their use of AI, identify relevant requirements under the EU AI Act and GDPR, and develop internal policies. Our advice covers risk assessment and the lawful and responsible use of AI.
- Regulatory Requirements: Identifying the requirements relevant to your organisation’s use of AI.
- Risk Assessment: Assessing risks and recommending measures for responsible use.
- Internal Policies: Developing practical internal rules for the use of AI.

Krunoslav Smolčić
Founder · Privacy & AI Governance Consultant · Outsourced DPO
Krunoslav Smolčić is a privacy consultant, outsourced DPO and the founder of HYDRA CONSULTING. A law graduate of the Faculty of Law, University of Zagreb, he has 20 years of professional experience and advises public and private sector organisations on data protection.
His specialist experience includes GDPR compliance reviews and implementation, Data Protection Impact Assessments (DPIAs), international data transfers and Transfer Impact Assessments (TIAs). He also advises on Data Processing Agreements and privacy by design. He has worked with organisations across banking, technology and SaaS, healthcare and the public sector.
Professional Credentials
Professional qualifications in privacy, AI governance, information security and business continuity.
FIPFellow of Information Privacy · IAPP
CIPP/ECertified Information Privacy Professional/Europe · IAPP
CIPMCertified Information Privacy Manager · IAPP
CIPTCertified Information Privacy Technologist · IAPP
AIGPArtificial Intelligence Governance Professional · IAPP- ISO/IEC 27001 Lead AuditorInformation security management · TÜV NORD · CQI/IRCA
- ISO/IEC 42001 Lead AuditorAI management system · TÜV NORD
- ISO 22301 Lead AuditorBusiness continuity management · Bureau Veritas · CQI/IRCA
Let’s Discuss Your Project.
Whether you need ongoing DPO support or advice on a specific matter, contact us to discuss the scope and next steps.
- info@hydra-consulting.hr
- Phone
- +385 95 90 60 745
- Address
- Prve Poljanice 7
10040 Zagreb, Croatia