Les DPO de la Santé
Anisse Chagraoui, founder of Les DPO de la Santé, at a conference
The founder

Legal expertise serving digital health

Anisse Chagraoui

Founder of Les DPO de la Santé

A lawyer specialised in health data protection, working at the intersection of law, sensitive data and digital health systems. In legal scholarship, the author of several novel concepts — including legal and regulatory interoperability and the digital body. He works as a network with hand-picked external DPOs, adjusting the expertise brought to each engagement without ever diluting the standard of rigour.

  • Doctoral candidate in law — Université Paris Dauphine–PSL
  • DPO certificate — Sciences Po Paris
  • Former legal director & DPO — biotechnology, then e-health

Degrees and certifications

  • Doctoral candidate in law — Université Paris Dauphine–PSL
  • DPO certificate — Sciences Po Paris
  • Master’s degree (Master 2) in public law — top of class, with highest honors
  • Master’s degree (Master 1) in public law — top of class

Background

  • Former legal director and DPO — biotechnology
  • Former head of legal — e-health
  • Former member of a French research ethics committee (comité de protection des personnes)
  • Founder of Les DPO de la Santé
  • Founder of NELSE — deeptech regulatory infrastructure
  • Founder of Bayanat — Data Law & AI Compliance (Africa and Middle East markets)
What this expertise changes for our clients

Compliance designed for the realities of healthcare

Health data protection cannot be approached as generalist compliance. It requires understanding, at one and the same time, the legal obligations, the care pathways, the information systems and the responsibilities specific to each stakeholder.

  • Precisely qualifying processing operations and responsibilities
  • Identifying the requirements applicable to each project
  • Securing the processing of sensitive data
  • Conducting impact assessments and documenting risks
  • Framing relationships with software vendors and processors
  • Building compliance that is understandable, workable and demonstrable
  • Anticipating regulatory developments affecting digital health and artificial intelligence
A specialized approach

From applicable law to its implementation

Our support rests on three complementary requirements.

01

Understand

Analyzing the organization, the processing operations, the data flows and the actual uses, so as to avoid purely paper-based compliance.

02

Structure

Defining responsibilities, prioritizing risks and putting in place the necessary procedures, contracts, records and assessments.

03

Demonstrate

Building a coherent, up-to-date body of documentation that justifies the decisions taken to partners, data subjects and supervisory authorities.

Areas of practice

Six fields, a single standard of rigor

Data governance

Records of processing, internal policies, procedures, responsibilities and steering of the compliance program.

Health data

Data qualification, professional secrecy, hosting, security and the framing of secondary uses.

Impact assessments

Assessing the necessity, proportionality and risks associated with sensitive processing operations.

Health research

Information and consent, clinical research, reference methodologies and allocation of responsibilities.

Artificial intelligence

Qualification of uses, data protection, governance, transparency and the articulation between the GDPR and the AI Act.

Contracts and processors

Data protection clauses, joint controllership agreements, HDS requirements and oversight of service providers.

Research & doctrine

Three concepts that ground his doctrine

A doctoral candidate at the Centre de recherche Droit Dauphine (Université Paris Dauphine–PSL), Anisse Chagraoui devotes his research to digital health law and the legal transformations brought about by the digitisation of the human body. His work is regularly cited in specialised journals.

The digital body

A clear legal definition of the digital body as an object in its own right, together with a regime of effectiveness founded on the principle of digital integrity of the body: protecting the digital projection of the human body as we protect its integrity in physical space.

A new definition of health data

A renewed, stabilised definition, freed from the sole criterion of declared purpose, embracing well-being, prevention and non-therapeutic monitoring — so that protection finally follows the data, not the staged use.

Legal and regulatory interoperability

A novel concept he developed: making legal requirements articulable with one another and executable within digital systems. The law must not stay in the texts — it must work inside the systems.

Main research areas

  • Digital body and bodily data
  • Health data and synthetic data
  • Digital integrity of the body
  • Digital consent (care, GDPR)
  • Patient–healthcare professional relationship
  • Legal and regulatory interoperability
  • Regulation of artificial intelligence in healthcare
Research and publications

Published work on novel legal issues

Our support methods are informed by research devoted to the transformations of data law, digital health and bioethics in the digital era. This work makes it possible to anticipate questions that existing legal frameworks still capture only imperfectly.

Cover — Corps numérique : essai sur un nouvel objet juridique
Doctoral research

Corps numérique : essai sur un nouvel objet juridique

Doctoral thesis in law, Université Paris Dauphine–PSL (CR2D). In French — “Digital body: an essay on a new legal object”.

Research devoted to building a legal regime capable of protecting the digital projection of the human body, including where the classical categories of person, personal data or health data no longer suffice.

Explore the research work
Cover — Corps numérique : l’objet juridique non identifié du XXIe siècle
Publication

Corps numérique : l’objet juridique non identifié du XXIe siècle

THIRD, no. 11, November 2025. In French — “Digital body: the unidentified legal object of the 21st century”.

The article proposes a qualification of the digital body structured around three layers: bodily data, synthetic data and the operative digital entity. It argues for the recognition of a principle of digital integrity of the body.

Read the article
Cover — Corps numérique : définition et effectivité d’un objet juridique non identifié
Publication

Corps numérique : définition et effectivité d’un objet juridique non identifié

Revue Lamy Droit de l’immatériel, no. 234, March 2026 — cover article. In French — “Digital body: definition and effectiveness of an unidentified legal object”.

This study proposes a legal definition of the digital body and examines the conditions of its effectiveness. It analyzes the limits of personal data law and bioethics when confronted with the digital manifestations of the body.

Get the journal — Lamy Liaisons
Expertise open to the international stage

An international reading of compliance

Anisse Chagraoui works on projects bringing together European actors, public institutions, technology companies and international partners. This experience makes it possible to approach compliance beyond the GDPR alone: international transfers, multi-jurisdictional projects, cooperation involving several authorities.

Frameworks and environments studied

  • European UnionGDPR, AI Act, EHDS
  • FranceCNIL, digital health, HDS and PGSSI-S
  • MoroccoLaw No. 09-08 and CNDP requirements
  • SwitzerlandRevised FADP (new LPD)
  • International projectsHIPAA, PIPL and institutional cooperation
Speaking engagements

Sharing knowledge and advancing practice

Anisse Chagraoui is regularly invited to share his expertise with professionals in healthcare, data protection and innovation — conferences, round tables, trade shows and specialized journals — making accessible the legal developments transforming their activities.

Proposed topics

  • The digital body as a new legal object
  • Health data and new forms of embodiment
  • Consent, information and proof
  • Legal and regulatory interoperability
  • Artificial intelligence and digital health
  • Making compliance executable and demonstrable

Conference, round table, training session or written contribution: every intervention is tailored to the audience and its challenges.

Propose a speaking engagement

Does your organization process health data?

Let’s talk about your processing operations, your risks and your priorities. This first meeting will identify the applicable obligations and determine the level of support suited to your organization.