
Legal expertise serving digital health
Anisse Chagraoui
Founder of Les DPO de la Santé
A lawyer specialised in health data protection, working at the intersection of law, sensitive data and digital health systems. In legal scholarship, the author of several novel concepts — including legal and regulatory interoperability and the digital body. He works as a network with hand-picked external DPOs, adjusting the expertise brought to each engagement without ever diluting the standard of rigour.
- Doctoral candidate in law — Université Paris Dauphine–PSL
- DPO certificate — Sciences Po Paris
- Former legal director & DPO — biotechnology, then e-health
Degrees and certifications
- Doctoral candidate in law — Université Paris Dauphine–PSL
- DPO certificate — Sciences Po Paris
- Master’s degree (Master 2) in public law — top of class, with highest honors
- Master’s degree (Master 1) in public law — top of class
Background
- Former legal director and DPO — biotechnology
- Former head of legal — e-health
- Former member of a French research ethics committee (comité de protection des personnes)
- Founder of Les DPO de la Santé
- Founder of NELSE — deeptech regulatory infrastructure
- Founder of Bayanat — Data Law & AI Compliance (Africa and Middle East markets)
Compliance designed for the realities of healthcare
Health data protection cannot be approached as generalist compliance. It requires understanding, at one and the same time, the legal obligations, the care pathways, the information systems and the responsibilities specific to each stakeholder.
- Precisely qualifying processing operations and responsibilities
- Identifying the requirements applicable to each project
- Securing the processing of sensitive data
- Conducting impact assessments and documenting risks
- Framing relationships with software vendors and processors
- Building compliance that is understandable, workable and demonstrable
- Anticipating regulatory developments affecting digital health and artificial intelligence
From applicable law to its implementation
Our support rests on three complementary requirements.
Understand
Analyzing the organization, the processing operations, the data flows and the actual uses, so as to avoid purely paper-based compliance.
Structure
Defining responsibilities, prioritizing risks and putting in place the necessary procedures, contracts, records and assessments.
Demonstrate
Building a coherent, up-to-date body of documentation that justifies the decisions taken to partners, data subjects and supervisory authorities.
Six fields, a single standard of rigor
Data governance
Records of processing, internal policies, procedures, responsibilities and steering of the compliance program.
Health data
Data qualification, professional secrecy, hosting, security and the framing of secondary uses.
Impact assessments
Assessing the necessity, proportionality and risks associated with sensitive processing operations.
Health research
Information and consent, clinical research, reference methodologies and allocation of responsibilities.
Artificial intelligence
Qualification of uses, data protection, governance, transparency and the articulation between the GDPR and the AI Act.
Contracts and processors
Data protection clauses, joint controllership agreements, HDS requirements and oversight of service providers.
Three concepts that ground his doctrine
A doctoral candidate at the Centre de recherche Droit Dauphine (Université Paris Dauphine–PSL), Anisse Chagraoui devotes his research to digital health law and the legal transformations brought about by the digitisation of the human body. His work is regularly cited in specialised journals.
The digital body
A clear legal definition of the digital body as an object in its own right, together with a regime of effectiveness founded on the principle of digital integrity of the body: protecting the digital projection of the human body as we protect its integrity in physical space.
A new definition of health data
A renewed, stabilised definition, freed from the sole criterion of declared purpose, embracing well-being, prevention and non-therapeutic monitoring — so that protection finally follows the data, not the staged use.
Legal and regulatory interoperability
A novel concept he developed: making legal requirements articulable with one another and executable within digital systems. The law must not stay in the texts — it must work inside the systems.
Main research areas
- Digital body and bodily data
- Health data and synthetic data
- Digital integrity of the body
- Digital consent (care, GDPR)
- Patient–healthcare professional relationship
- Legal and regulatory interoperability
- Regulation of artificial intelligence in healthcare
Published work on novel legal issues
Our support methods are informed by research devoted to the transformations of data law, digital health and bioethics in the digital era. This work makes it possible to anticipate questions that existing legal frameworks still capture only imperfectly.
An international reading of compliance
Anisse Chagraoui works on projects bringing together European actors, public institutions, technology companies and international partners. This experience makes it possible to approach compliance beyond the GDPR alone: international transfers, multi-jurisdictional projects, cooperation involving several authorities.
Frameworks and environments studied
- European UnionGDPR, AI Act, EHDS
- FranceCNIL, digital health, HDS and PGSSI-S
- MoroccoLaw No. 09-08 and CNDP requirements
- SwitzerlandRevised FADP (new LPD)
- International projectsHIPAA, PIPL and institutional cooperation
Sharing knowledge and advancing practice
Anisse Chagraoui is regularly invited to share his expertise with professionals in healthcare, data protection and innovation — conferences, round tables, trade shows and specialized journals — making accessible the legal developments transforming their activities.
Proposed topics
- The digital body as a new legal object
- Health data and new forms of embodiment
- Consent, information and proof
- Legal and regulatory interoperability
- Artificial intelligence and digital health
- Making compliance executable and demonstrable
Conference, round table, training session or written contribution: every intervention is tailored to the audience and its challenges.
Propose a speaking engagementDoes your organization process health data?
Let’s talk about your processing operations, your risks and your priorities. This first meeting will identify the applicable obligations and determine the level of support suited to your organization.










