Fractional General Counsel · EU Representative · Outsourced DPO

Legal and regulatory counsel across the Netherlands and South Africa.

For companies moving capital, operations or products between Europe and South Africa, and for the firms advising them. One lawyer who holds both ends, with EU data protection and cyber regulation as the specialism.

NL + SA

Admitted in South Africa, established in the Netherlands

One relationship

Across both jurisdictions, with a vetted specialist panel on call

Four regimes

GDPR, NIS2, AI Act and CRA all require an EU representative

11 years

In private practice, in-house and in digital regulation

Services

How I work

One senior relationship rather than a panel of firms. Fees are fixed and agreed before work starts, so you are never surprised by an invoice.

Ongoing

Fractional general counsel

Fixed monthly. Cancellable monthly.

Someone who already knows your business when the question arrives, so you stop carrying the legal layer yourself.

  • Commercial contracts and negotiation
  • Board and shareholder matters
  • Data protection and regulatory questions
  • IP and know-how
  • Employment and contractor arrangements

Statutory

EU representative and DPO

Annual appointment. Fixed fee.

If you sell into the EU without an establishment here, several of these appointments are not optional. I am established in the Netherlands, which is the part that cannot be outsourced from home.

  • GDPR Article 27, EU representative
  • NIS2 Article 26(3), Union representative
  • AI Act Article 22, authorised representative
  • CRA Article 18, authorised representative
  • Outsourced data protection officer

Project

Crossing the corridor

Fixed fee, quoted after a short diagnostic.

Setting up in Europe, or taking European capital and operations into South Africa. Both directions, one lawyer, no handover between two firms who have never met.

  • Dutch BV incorporation and structuring
  • Shareholders’ agreements and statuten
  • EU privacy and AI readiness
  • EU to South Africa data transfers, SCCs and transfer impact assessments
  • South African structuring and due diligence readiness
  • Loop structures and investment between markets

Approach

One lawyer, both sides

Most cross-border work is done by two firms who have never spoken. Each is competent at home and neither owns the join, which is where the cost and the delay live.

I am a South African attorney with a European career and network, established in Amsterdam. I hold both ends myself. Where something belongs to a Dutch advocaat, a civil-law notary or South African counsel, I say so and make the introduction rather than quietly having a go.

The legal bridge between the Netherlands and South Africa.

Velocity

No file handovers, no partner to brief, no month lost to two firms finding each other.

Precision

Named articles, dated deadlines, a view you can act on. Not a memo listing every possibility.

Continuity

The same person on the second matter as the first, still holding the context you paid to build.

Restraint

Authority without theatre. If a risk does not matter to your business, I will tell you that too.

Why now

The regulatory calendar

Four EU regimes are landing at once, and the reporting they demand starts before most companies have read them. Two dates below have already passed. One arrives this month. Companies outside the EU carry the same obligations as those inside it, and usually cannot discharge them from home.

NIS2

15 Aug 2026

Dutch Cyberbeveiligingswet in force. No transition period. Registration, duty of care and incident reporting all begin on day one.

Cyber Resilience Act

11 Sep 2026

Reporting obligations begin: 24-hour early warning, 72-hour notification. Main obligations follow on 11 December 2027.

EU AI Act

2 Aug 2026

Article 50 transparency obligations applied. High-risk obligations were deferred: Annex III to 2 December 2027, Annex I to 2 August 2028.

GDPR

€7.1bn

Cumulative fines since May 2018, per DLA Piper’s survey of January 2026. Enforcement is now sustained rather than sporadic.

Verified 12 August 2026. Dates in this area move: the AI Act high-risk obligations were pushed back by sixteen months in mid-2026, after most of the market had already planned around the original deadline.

Contact

Start the conversation

Tell me where you are and where you want to get to, and I will tell you whether I am the right person for it. If I am not, I will say so and point you at someone who is.

Twenty minutes, no charge, and a straight answer either way.
Amsterdam and Johannesburg · Reply within one working day.

Getting in touch does not create a lawyer-client relationship, so please keep anything confidential out of a first email until an engagement letter is signed. How your data is handled is set out in the privacy notice.

OneOneEleven B.V., trading as SIDEBAR Consult · Emmalaan 17D, 1075 AT Amsterdam · KvK 80263003 · BTW NL861608975B01

Privacy notice · Cookie notice · Legal notice · LinkedIn

Brendon Ambrose is an attorney admitted in South Africa, established in the Netherlands. He is not registered with the Nederlandse orde van advocaten. Nothing on this site is legal advice.