Skip to Content

GDPR Compliance

The GDPR is eight years old. The main lines haven't changed, but how authorities verify compliance has. Statements of intent are no longer enough: CNIL wants proof. We help you build and maintain it.

BCIT Formation logo
BCIT Formation rated Excellent
4.7 · Trustpilot
+1000 learners trained

What changed in 2026

The regulation text hasn't been rewritten, but enforcement has toughened: in 2024, CNIL received 17,772 complaints, a record, and issued over €55 million in fines. CNIL and its European counterparts no longer just check that you have a register or privacy policy: they demand concrete proof that your measures work. Timestamped access logs, reports ofinternal audit, technical certificates for encryption, data purge traces: the principle of accountability now takes material form.

In parallel, the GDPR is no longer managed in silos. The application of theAI Act and Data Act creates regulatory convergence: a process based on artificial intelligence must comply with GDPR and the obligations of theAI Act. For CISO, DPO and legal teams, this means a unified mapping of obligations, not stacked compliances.

The proof you'll really be asked for

Live register

A processing register dated, up-to-date, reflecting real flows, not a static document written once for show.

Logs & Traceability

Timestamped access logs, traces of consent, proof of purge at the end of retention periods.

Technical certificates

Proof of encryption, of pseudonymization and access segregation, verifiable during an audit.

Documented PIA / DPIA

Data protection impact assessments conducted for high-risk processing, archived and reviewed.

Who is affected?

Any organization that processes personal data is affected, but proof requirements weigh particularly on three roles. The CISO, who must produce technical traces and demonstrate the effectiveness of security measures. The DPO, who manages the register, impact assessments and communication with the CNIL (a role you can keep in-house or entrust to an external DPO). And the legal team, who must align GDPR with new regulations (AI Act, Data Act, NIS2, DORA) without creating contradictions between obligations. Our support is designed for these three stakeholders and their coordination.

Our approach

We start from your reality, not a theoretical model. Useful GDPR compliance is what holds up during an audit: a register matching actual processing, retention periods applied not just written, impact assessments proportionate to risk. Our approach is pragmatic and documented: at each step, we produce the expected proof and equip your teams to maintain it over time. This proof logic aligns with an ISMS and naturally aligns with an approach to ISO 27001 or AI governance via ISO 42001.

Our compliance approach

1

Processing mapping

Identification of actual data flows, purposes and legal bases. Starting point for a reliable register.

2

Gap analysis

Comparison of current state to GDPR requirements and CNIL proof expectations, to measure remaining work.

3

Register & Retention Periods

Building or upgrading the processing register and effective application of retention periods.

4

PIA / DPIA

Conducting impact assessments on high-risk processing, integrating convergence with AI Act and Data Act.

5

Measures & Evidence

Implementation of technical and organizational measures, and collection of associated evidence: logs, certificates, procedures.

6

Audit preparation

Building the accountability file and training teams to respond to CNIL audits confidently.

7

Ongoing maintenance

Periodic review, team awareness and coordination with management of a data breach if it occurs.

8

DPO appointment

Support for appointing and deploying the DPO, internal or outsourced, cornerstone of your daily compliance.

9

Team training

Employee awareness sessions on GDPR best practices, to embed data protection in business processes.

Frequently asked questions

Is my company affected if it's small?

Yes: company size doesn't determine GDPR applicability, which applies whenever personal data is processed. But it does influence the expected rigor level and proportionality of measures. See also our guide Is my company affected by GDPR?

Is appointing a DPO mandatory?

It is in specific cases (public bodies, large-scale processing or regular monitoring of sensitive data). Outside these cases, it's strongly recommended when data volume or sensitivity justifies it. We help you decide based on your real situation, with a external DPO if needed.

How long does compliance implementation take?

It depends on the initial gap and the number of processing to map. Initial upgrading (register, retention periods, priority measures) typically takes a few months; ongoing maintenance is then continuous work, not a one-time project.

What's the real risk in an audit?

Risk depends on the severity of non-compliance found: warning, compliance order, or financial penalty in serious cases. Compliance work essentially consists of being able to demonstrate, with proof, that your measures are real and maintained—this is what makes the difference in an audit.

Why trust us with your GDPR compliance?

Field-certified experts

Cybersecurity and compliance specialists who produce verifiable evidence, not inert procedure manuals.

Unified regulatory view

GDPR, AI Act, Data Act, NIS2, DORA : we align your obligations instead of stacking them. One map, shared controls.

Lasting support

From gap analysis to maintenance, we equip your teams so compliance holds after we leave.

Estimate your certification price

Interactive calculator: company size, sector, additional compliances... get a price range in a few clicks.

Estimate your investment Quick mode

Standard (3-6 months) Fast Urgent

Additional compliances


€0
0 people
€0
0 people
€0

Price estimate

—, —€
approximately 0€, 0€ / month
Calculation breakdown
Implementer Training €0
Auditor Training €0
Chosen package Standard
Get your detailed estimate
Response within 24 business hours · No commitment · GDPR compliant
Full refund in case of failure on our part
If certification is not obtained due to our actions, we refund the entire amount paid.
* VAT will be added at the standard rate

Let's assess your GDPR compliance

Let's take 15 minutes to understand your processing, challenges and expected proof level in your sector. You'll leave with a clear vision of next steps, no commitment.