Les DPO de la Santé

Outsourced DPO · Digital health compliance

Your digital health compliance experts

Turn your obligations into opportunities with our digital health compliance specialists. Compliance rigour becomes the ally of your innovation — never an obstacle.

  • Free initial discussion
  • Response within 24 h
  • 100% dedicated to healthcare

The regulatory frameworks covered by our monitoring

  • GDPR
  • AI Act
  • EHDS
  • NIS2
  • DORA
  • HDS framework
  • CNIL recommendations
  • Medical confidentiality (French Public Health Code)
  • MDR / IVDR
  • ePrivacy
Projects brought into compliance
45
First-response time
< 24 h
Dedicated to the healthcare sector
100%
Areas of expertise
6
The DPO role

A DPO is much more than the GDPR

The GDPR creates the role: eight duties, defined in its Articles 38 and 39. But carrying them out in digital health draws on a far broader regulatory landscape — AI, cybersecurity, hosting, medical confidentiality. First the role, then its terrain.

The role — eight duties entrusted to the DPO

Inform & advise

Guide leadership and business teams on their obligations — GDPR, but also AI, cybersecurity and health data.

Monitor compliance

Audits, periodic reviews of processing activities, follow-up of action plans and gaps.

Steer DPIAs

Advise on data protection impact assessments, verify their execution and their updates.

CNIL point of contact

Contact point for the authority: requests, inspections, breach notifications.

Maintain documentation

Record of processing activities, breach register, demonstrable evidence of compliance.

Train the teams

Ongoing awareness of medical confidentiality, security and new regulations.

Oversee processors

Article 28 contracts (DPAs), safeguards, transfers outside the EU, the processing chain.

Handle incidents

Qualifying breaches, notifying the CNIL within 72 hours, informing individuals.

The terrain — where the DPO goes beyond the GDPR

All the digital health regulations, one single watch

Carrying out these eight duties in healthcare requires mastering far more than one regulation: our monitoring tracks every framework that applies — or will apply — to your activities, to anticipate their operational impact.

  • GDPR

    The foundation of data protection

  • AI Act

    AI systems in healthcare, often high-risk

  • EHDS

    The European Health Data Space

  • NIS2

    Cybersecurity of healthcare entities

  • DORA

    Digital resilience of the insurance sector

  • HDS

    Certification for health data hosting

  • French Public Health Code

    Medical confidentiality, care teams, telemedicine

  • French Data Protection Act

    The national framework, CNIL reference frameworks

  • CNIL reference methodologies

    Reference methodologies for research

  • MDR / IVDR

    Medical devices, including software

  • ePrivacy

    Cookies, direct marketing, communications

  • Data Act & DGA

    Data sharing and data altruism

We provide compliance and data protection consulting, within the scope of the DPO duties defined by the GDPR. Legal consultations, the drafting of legal instruments and litigation are the remit of independent lawyers, to whom we refer you whenever the situation requires.

Our conviction

Compliance is owned, not generated

Tools and artificial intelligence are transforming the profession — and we know them from the inside. Our conviction is simple: they augment the expert, they do not replace them.

Tools bring structure

Registers, workflows, dashboards: compliance platforms are useful, and we gladly work with the best of them. But software does not take on responsibility.

AI must itself be compliant

Applying generative AI to compliance raises questions of its own: probabilistic answers, uncertain traceability, sensitive data. A probability is not demonstrable evidence.

A human answers

The GDPR entrusts the role to a DPO: a human, independent, reachable function — a judgement accountable to the CNIL, patients and partners.

It is precisely this observation that led our founder to create NELSE, a deterministic regulatory infrastructure: making the law executable and provable within systems — proof, not probability.

In the field

Three situations we encounter — and what they become

Anonymised cases, representative of our engagements: the starting situation, our intervention, the outcome for the organisation.

Coordinated-care organisation

From scattered compliance to quarterly governance

Situation. Coordination tools deployed project after project, documents produced at different times, no consolidated record — and no one to say who decides.

Intervention. Mapping of processing activities and data flows, rebuilding of the record, review of processors, screening for the DPIAs required, roadmap approved by leadership.

Outcome. A workable record, responsibilities in writing, a committee that meets every quarter — and every new project now goes through an identified consultation channel.

Digital health software vendor

A compliance file that accelerates hospital sales

Situation. Increasingly demanding buyer questionnaires — hosting, roles, processors, security — and answers scattered between sales, technical and legal teams.

Intervention. Mapping of the architecture, qualification of GDPR roles, review of processors and of the HDS scope, assembly of a reusable answer file.

Outcome. Consistent answers from one questionnaire to the next, a file that can be mobilised in days rather than weeks, and a compliance checkpoint built into the product cycle.

Healthcare facility

Patient record access rights that can finally be demonstrated

Situation. Access to the patient record that evolved with the organisation, without formal rules or regular reviews — a classic blind spot in inspections.

Intervention. Role mapping with leadership, IT and business teams, access analysis, definition of a review cycle, documentation of priority measures.

Outcome. A validated access-rights matrix, a periodic review process, tracked indicators — and evidence ready to be produced if an authority requests it.

Express diagnostic

Where does your compliance stand?

10 questions, 2 minutes. Assess your maturity level and leave with concrete avenues for action.

1/10

Have you appointed a Data Protection Officer (DPO)?

0 answer of 10

Turn your obligations into opportunities.

A free, no-commitment initial discussion to review your compliance and identify your priorities.

Reply within 24 business hours · No commitment