GDPR Compliance
The GDPR is eight years old. The main lines haven't changed, but how authorities verify compliance has. Statements of intent are no longer enough: CNIL wants proof. We help you build and maintain it.
What changed in 2026
The regulation text hasn't been rewritten, but enforcement has toughened: in 2024, CNIL received 17,772 complaints, a record, and issued over €55 million in fines. CNIL and its European counterparts no longer just check that you have a register or privacy policy: they demand concrete proof that your measures work. Timestamped access logs, reports ofinternal audit, technical certificates for encryption, data purge traces: the principle of accountability now takes material form.
In parallel, the GDPR is no longer managed in silos. The application of theAI Act and Data Act creates regulatory convergence: a process based on artificial intelligence must comply with GDPR and the obligations of theAI Act. For CISO, DPO and legal teams, this means a unified mapping of obligations, not stacked compliances.
The proof you'll really be asked for
Live register
A processing register dated, up-to-date, reflecting real flows, not a static document written once for show.
Logs & traceability
Timestamped access logs, traces of consent, proof of purge at the end of retention periods.
Technical certificates
Proof of encryption, of pseudonymization and access segregation, verifiable during an audit.
Documented PIA / DPIA
Data protection impact assessments conducted for high-risk processing, archived and reviewed.
Who is affected?
Any organization that processes personal data is affected, but proof requirements weigh particularly on three roles. The CISO, who must produce technical traces and demonstrate the effectiveness of security measures. The DPO, who manages the register, impact assessments and communication with the CNIL (a role you can keep in-house or entrust to an external DPO). And the legal team, who must align GDPR with new regulations (AI Act, Data Act, NIS2, DORA) without creating contradictions between obligations. Our support is designed for these three stakeholders and their coordination.
Our approach
We start from your reality, not a theoretical model. Useful GDPR compliance is what holds up during an audit: a register matching actual processing, retention periods applied not just written, impact assessments proportionate to risk. Our approach is pragmatic and documented: at each step, we produce the expected proof and equip your teams to maintain it over time. This proof logic aligns with an ISMS and naturally aligns with an approach to ISO 27001 or AI governance via ISO 42001.
Our compliance approach
Processing mapping
Identification of actual data flows, purposes and legal bases. Starting point for a reliable register.
Gap analysis
Comparison of current state to GDPR requirements and CNIL proof expectations, to measure remaining work.
Register & retention periods
Building or upgrading the processing register and effective application of retention periods.
PIA / DPIA
Conducting impact assessments on high-risk processing, integrating convergence with AI Act and Data Act.
Measures & evidence
Implementation of technical and organizational measures, and collection of associated evidence: logs, certificates, procedures.
Audit preparation
Building the accountability file and training teams to respond to CNIL audits confidently.
Ongoing maintenance
Periodic review, team awareness and coordination with management of a data breach if it occurs.
DPO appointment
Support for appointing and deploying the DPO, internal or outsourced, cornerstone of your daily compliance.
Team training
Employee awareness sessions on GDPR best practices, to embed data protection in business processes.
Frequently asked questions
Is my company affected if it's small?
Yes: company size doesn't determine GDPR applicability, which applies whenever personal data is processed. But it does influence the expected rigor level and proportionality of measures. See also our guide Is my company affected by GDPR?
Is appointing a DPO mandatory?
It is in specific cases (public bodies, large-scale processing or regular monitoring of sensitive data). Outside these cases, it's strongly recommended when data volume or sensitivity justifies it. We help you decide based on your real situation, with a external DPO if needed.
How long does compliance implementation take?
It depends on the initial gap and the number of processing to map. Initial upgrading (register, retention periods, priority measures) typically takes a few months; ongoing maintenance is then continuous work, not a one-time project.
What's the real risk in an audit?
Risk depends on the severity of non-compliance found: warning, compliance order, or financial penalty in serious cases. Compliance work essentially consists of being able to demonstrate, with proof, that your measures are real and maintained—this is what makes the difference in an audit.
Why trust us with your GDPR compliance?
Field-certified experts
Cybersecurity and compliance specialists who produce verifiable evidence, not inert procedure manuals.
Unified regulatory view
GDPR, AI Act, Data Act, NIS2, DORA : we align your obligations instead of stacking them. One map, shared controls.
Lasting support
From gap analysis to maintenance, we equip your teams so compliance holds after we leave.
Estimate your certification price
Interactive calculator: company size, sector, additional compliances... get a price range in a few clicks.
Price estimate
If certification is not obtained due to our actions, we refund the entire amount paid.
Let's assess your GDPR compliance
Let's take 15 minutes to understand your processing, challenges and expected proof level in your sector. You'll leave with a clear vision of next steps, no commitment.
GDPR Compliance
The GDPR is eight years old. The main lines haven't changed, but how authorities verify compliance has. Statements of intent are no longer enough: CNIL wants proof. We help you build and maintain it.
What changed in 2026
The regulation text hasn't been rewritten, but enforcement has toughened: in 2024, CNIL received 17,772 complaints, a record, and issued over €55 million in fines. CNIL and its European counterparts no longer just check that you have a register or privacy policy: they demand concrete proof that your measures work. Timestamped access logs, reports ofinternal audit, technical certificates for encryption, data purge traces: the principle of accountability now takes material form.
In parallel, the GDPR is no longer managed in silos. The application of theAI Act and Data Act creates regulatory convergence: a process based on artificial intelligence must comply with GDPR and the obligations of theAI Act. For CISO, DPO and legal teams, this means a unified mapping of obligations, not stacked compliances.
The proof you'll really be asked for
Live register
A processing register dated, up-to-date, reflecting real flows, not a static document written once for show.
Logs & Traceability
Timestamped access logs, traces of consent, proof of purge at the end of retention periods.
Technical certificates
Proof of encryption, of pseudonymization and access segregation, verifiable during an audit.
Documented PIA / DPIA
Data protection impact assessments conducted for high-risk processing, archived and reviewed.
Who is affected?
Any organization that processes personal data is affected, but proof requirements weigh particularly on three roles. The CISO, who must produce technical traces and demonstrate the effectiveness of security measures. The DPO, who manages the register, impact assessments and communication with the CNIL (a role you can keep in-house or entrust to an external DPO). And the legal team, who must align GDPR with new regulations (AI Act, Data Act, NIS2, DORA) without creating contradictions between obligations. Our support is designed for these three stakeholders and their coordination.
Our approach
We start from your reality, not a theoretical model. Useful GDPR compliance is what holds up during an audit: a register matching actual processing, retention periods applied not just written, impact assessments proportionate to risk. Our approach is pragmatic and documented: at each step, we produce the expected proof and equip your teams to maintain it over time. This proof logic aligns with an ISMS and naturally aligns with an approach to ISO 27001 or AI governance via ISO 42001.
Our compliance approach
Processing mapping
Identification of actual data flows, purposes and legal bases. Starting point for a reliable register.
Gap analysis
Comparison of current state to GDPR requirements and CNIL proof expectations, to measure remaining work.
Register & Retention Periods
Building or upgrading the processing register and effective application of retention periods.
PIA / DPIA
Conducting impact assessments on high-risk processing, integrating convergence with AI Act and Data Act.
Measures & Evidence
Implementation of technical and organizational measures, and collection of associated evidence: logs, certificates, procedures.
Audit preparation
Building the accountability file and training teams to respond to CNIL audits confidently.
Ongoing maintenance
Periodic review, team awareness and coordination with management of a data breach if it occurs.
DPO appointment
Support for appointing and deploying the DPO, internal or outsourced, cornerstone of your daily compliance.
Team training
Employee awareness sessions on GDPR best practices, to embed data protection in business processes.
Frequently asked questions
Is my company affected if it's small?
Yes: company size doesn't determine GDPR applicability, which applies whenever personal data is processed. But it does influence the expected rigor level and proportionality of measures. See also our guide Is my company affected by GDPR?
Is appointing a DPO mandatory?
It is in specific cases (public bodies, large-scale processing or regular monitoring of sensitive data). Outside these cases, it's strongly recommended when data volume or sensitivity justifies it. We help you decide based on your real situation, with a external DPO if needed.
How long does compliance implementation take?
It depends on the initial gap and the number of processing to map. Initial upgrading (register, retention periods, priority measures) typically takes a few months; ongoing maintenance is then continuous work, not a one-time project.
What's the real risk in an audit?
Risk depends on the severity of non-compliance found: warning, compliance order, or financial penalty in serious cases. Compliance work essentially consists of being able to demonstrate, with proof, that your measures are real and maintained—this is what makes the difference in an audit.
Why trust us with your GDPR compliance?
Field-certified experts
Cybersecurity and compliance specialists who produce verifiable evidence, not inert procedure manuals.
Unified regulatory view
GDPR, AI Act, Data Act, NIS2, DORA : we align your obligations instead of stacking them. One map, shared controls.
Lasting support
From gap analysis to maintenance, we equip your teams so compliance holds after we leave.
Estimate your certification price
Interactive calculator: company size, sector, additional compliances... get a price range in a few clicks.
Price estimate
If certification is not obtained due to our actions, we refund the entire amount paid.
Let's assess your GDPR compliance
Let's take 15 minutes to understand your processing, challenges and expected proof level in your sector. You'll leave with a clear vision of next steps, no commitment.