Les DPO de la Santé
Pricing

Clear offers, defined capacity, no hidden “unlimited”

Cost depends on your actual complexity: entities, processing activities, projects, processors and the expected level of availability. Our starting rates let you situate yourself immediately; each proposal then specifies the included capacity, the deliverables and the exclusions.

Step 1 — lay the foundations

One-off engagements

A defined scope, deliverables, a fixed price — billed once, with no long-term commitment. This is the recommended entry point before any subscription.

One-off engagement — billed once

Health Compliance Diagnostic

Any organisation, before any commitment

Identify your priority risks and decide on next steps with full knowledge of the facts.

  • Scoping interview (90 min)
  • Targeted document review
  • Maturity score by domain
  • Your top 3 priorities and a roadmap
  • Findings presented by videoconference

Findings delivered within 10 business days

from €1,500 excl. VAT

Amount deducted in full from the Health Compliance Foundation if you engage it within 30 days of the findings presentation.

Request my diagnostic
One-off engagement — billed once

Health Compliance Foundation

CPTS, MSP, health centres, medico-social organisations

Move from scattered compliance to an organised, prioritised and demonstrable foundation.

Includes the Diagnostic’s baseline assessment — plus:

  • Mapping of processing activities and data flows
  • Initial record of processing activities
  • Review of processors and contracts to check
  • Screening of processing operations requiring a DPIA
  • 90-day and 12-month roadmap
  • Management debrief and initial awareness session

6 to 8 weeks

from €5,000 excl. VAT

Diagnostic already completed? It serves as the starting point — and its amount (€1,500 excl. VAT) is deducted from the Foundation if you engage it within 30 days of the findings presentation.

Request the Compliance Foundation
One-off engagement — billed once

Facility Compliance Foundation

EHPAD, clinics, groups and multi-site organisations

The full foundation, sized for the volumes, governance and multiple sites of a facility.

Includes everything in the Health Compliance Foundation — plus:

  • Multi-site mapping and group governance
  • Authorisation matrix and review of access to records
  • Internal control plan and identified relays per site
  • Presentation to the executive committee

8 to 12 weeks

from €9,900 excl. VAT

Diagnostic already completed? Its amount (€1,500 excl. VAT) is deducted if you engage the foundation within 30 days of the findings presentation.

Scope my facility foundation

Step 2 — establish the function over time

Outsourced DPO subscriptions

Monthly billing for reserved capacity, a DPO designated with the CNIL and a governance rhythm. Each tier includes everything in the previous tier. The most common path: Diagnostic, then Foundation, then subscription — each step can also be engaged on its own.

Internal or outsourced DPO? Read the decision guide

Subscription — monthly billing

Health DPO — Essential

Organisations with a simple, stable scope

A designated DPO, a governance rhythm and a defined intervention capacity.

  • DPO designation with the CNIL
  • Dedicated point of contact — first response within 24 business hours
  • Reserved intervention capacity every month, poolable per quarter — sized in the written proposal
  • Quarterly committee and annual report
  • Handling of data-subject requests and simple incidents
  • Regulatory watch applied to your scope

Initial 12-month commitment recommended

from €690 excl. VAT/month

Added to an onboarding fee quoted for your situation: taking over an existing set-up, or building the foundation (see Health Compliance Foundation).

Choose Health DPO — Essential
Subscription — monthly billing

Health DPO — Steering

Software vendors, medtechs, multi-project organisations

Embed compliance into your projects, your sales and your partner relationships.

Includes everything in the Essential tier — plus:

  • Reinforced monthly intervention capacity, adjusted to your actual scope
  • Monthly committee and review of new projects
  • Support with client questionnaires and due diligence
  • Review of processor documentation
  • Management dashboard

Initial 12-month commitment recommended

from €1,500 excl. VAT/month

Added to an onboarding fee quoted for your situation: taking over an existing set-up, or building the foundation (see Health Compliance Foundation).

Choose Health DPO — Steering
Subscription — monthly billing

Facility DPO

Clinics, groups, multi-site organisations

Reinforced governance for complex, high-volume environments.

Includes everything in the Steering tier — plus:

  • Intervention capacity sized for the facility — volume, sites and governance
  • Executive committee and reinforced monthly governance
  • Internal relays, control plan and multi-site monitoring
  • Structured management of projects and incidents
  • Executive reporting and annual evidence file

Perimeter defined after scoping

from €3,500 excl. VAT/month

The initial scoping defines the perimeter, the sites covered and the onboarding — quoted before any commitment.

Scope my facility needs

When every hour counts

Emergencies

An announced inspection or an ongoing breach cannot wait for a sales cycle: priority handling, a bounded scope, a price known in advance.

Emergency — priority response

CNIL Inspection Response

Inspection under way, announced, or CNIL letter received

Priority handling to organise the evidence, the responses and the teams — without improvisation.

  • Immediate scoping — activation within 4 business hours
  • Freezing and collection of evidence: record of processing, DPIAs, authorisations, contracts
  • Response plan and preparation of your spokespeople
  • Coordination of data-protection responses
  • Articulation with your lawyer where necessary

Activation within 4 business hours

from €5,900 excl. VAT

Legal representation and litigation are handled by your lawyer, with whom we coordinate.

Activate a priority response
Emergency — priority response

Health Data Breach Response

Security incident affecting health data

Qualify fast, notify right, document everything: the 72 hours after an incident decide what comes next.

  • Qualification of the breach and assessment of the risk to individuals
  • Notification to the CNIL within 72 hours where required
  • Information of the individuals concerned where applicable
  • Complete documentation in the breach register
  • Coordination of the technical investigation with the cybersecurity partner

Same-day qualification

from €3,500 excl. VAT

Excludes technical investigation — quoted separately by our cybersecurity partner, in coordination with us.

Qualify my incident

Depending on your projects

Specialised engagements

Expert missions, also one-off: scoped, quoted and billed per engagement — alongside a subscription or on a standalone basis.

One-off engagement — quoted after scoping

Health DPIA

Processing likely to result in a high risk

A framed, documented impact assessment your management can act on.

  • Scoping of the processing and stakeholders
  • Necessity and proportionality analysis
  • Risk scenarios and measures
  • Documentation of decisions and residual risks

3 to 8 weeks depending on the processing

from €3,000 excl. VAT

Scope my DPIA
One-off engagement — quoted after scoping

e-Health Product Compliance

Health SaaS, telemedicine, digital medical devices, AI

Prepare your product, your contracts and your evidence for buyers, partners and investors.

  • Data-flow mapping and role qualification
  • Privacy by design and DPIA screening
  • HDS scoping and processor governance
  • AI Act qualification where applicable
  • Response pack for buyer questionnaires

8 to 16 weeks

Priced after scoping

Assess my e-health product
One-off engagement — quoted after scoping

AI Compliance — AI Act

Providers and deployers of AI systems in healthcare

Qualify your AI systems, structure your obligations and train your teams — Article 4 of the AI Act already requires AI literacy for the staff concerned.

  • Qualification of your systems under the AI Act
  • Mapping of provider / deployer obligations
  • AI literacy programme for your teams (Article 4)
  • Articulation of the AI Act, GDPR and health data
  • Roadmap aligned with the regulatory timeline

Depending on the number and criticality of systems

Priced after scoping

Scope my AI compliance
One-off engagement — quoted after scoping

EHDS Preparation

Facilities, EHR software vendors, health data holders

The European Health Data Space will apply in stages: getting ahead turns a constraint into a market position.

  • Mapping of your data with regard to the EHDS (primary and secondary use)
  • Qualification of your obligations according to your role
  • Compliance trajectory aligned with the regulation’s deadlines
  • Articulation of the EHDS, GDPR and HDS certification
  • Dedicated watch on upcoming implementing acts

Multi-year programme, by milestones

Priced after scoping

Get ahead of the EHDS
One-off engagement — quoted after scoping

International Data Transfers

Groups, vendors with non-EU processors, French-speaking organisations across Europe

A US processor, a subsidiary outside the EU, an international research project: every outbound flow must rest on a valid transfer tool.

  • Mapping of data flows outside the EU / EEA
  • Qualification of the appropriate transfer tool for each flow (adequacy, standard contractual clauses, Article 49)
  • Documented transfer impact assessments (TIAs)
  • Review of processing chains and vendor documentation
  • Articulation with HDS hosting and localisation requirements
  • Support across French-speaking Europe: Belgium and Luxembourg (GDPR), Switzerland (nFADP), Monaco (Law No. 1.565)

Depending on the number of flows and destinations

Priced after scoping

Secure my transfers
One-off engagement — quoted after scoping

Research & Health Data

Sponsors, CROs, facilities, health data warehouses

Secure the framework, flows, responsibilities and evidence of a data project.

  • Qualification of roles and the applicable framework
  • Mapping of sources, flows and access
  • Information, rights and retention periods
  • DPIA where required, documentary governance

8 to 24 weeks

Priced after scoping

Scope my research project
One-off engagement — quoted after scoping

Health Training & Awareness

Up to 15 participants — management, care staff, administrative, technical

Health GDPR, security and AI training grounded in your real situations — and for AI, a legal obligation since February 2025 (Article 4 of the AI Act).

  • Programme tailored to your roles and your tools
  • Practical cases drawn from your context
  • Materials provided to participants
  • Retention quiz and summary for management
  • Certificate of participation

Half-day, remote or on site

from €1,500 excl. VAT

Six formats calibrated by audience — frontline staff, management, internal relays, product, AI (Article 4), crisis exercise — detailed on the Training page.

Train my teams

Starting rates excl. VAT, for a single, simple entity. Each written proposal details the scope, the included capacity, the deliverables, the timelines and the exclusions — no service is undertaken without prior agreement on its estimate.

The scope, without ambiguity

What our offers include — and what they don’t replace

Clarity of scope protects your organisation as much as ours: everyone knows who does what, and who we work with when a matter goes beyond the DPO’s remit.

Included in our engagements

  • Operational advice within the DPO’s remit
  • Advice on technical and organisational security measures (Article 32 GDPR)
  • Records, procedures, mappings and action plans
  • Impact assessments within the agreed scope
  • Support with qualifying and notifying breaches
  • Regulatory watch applied to your scope

Handled separately or by our partners

  • Legal consultations, drafting of legal instruments and litigation — handled by independent lawyers to whom we refer you
  • Technical audits, penetration tests and technical incident response — quoted separately by our cybersecurity partner
  • Time beyond the included capacity — estimated and approved before any work
  • Emergencies outside the service level — handled under the conditions set out in the contract
Frequently asked questions

Pricing: what we’re asked most often

Why an onboarding cost on top of the DPO subscription?

Onboarding covers taking over or building the foundation: interviews, mapping, record of processing, action plan and designation. The subscription then funds reserved capacity, a governance rhythm and a service level — not an initial catch-up diluted over time.

Is the Diagnostic wasted money if we continue with the Foundation?

No: if you engage the Health Compliance Foundation within 30 days of the Diagnostic’s findings presentation, its amount (€1,500 excl. VAT) is deducted in full from the price of the Foundation. The baseline assessment then serves directly as the starting point for scoping — you never pay twice for the same work.

Is the number of questions unlimited?

No, and that is deliberate: each plan specifies a monthly capacity and response times. This transparency protects the quality with which each request is handled — an “unlimited” promise is always paid for in quality or in delays.

Is a DPIA included in the subscriptions?

The subscriptions include the screening and scoping of processing operations likely to require an impact assessment. The full assessment is quoted separately after qualification, because its complexity depends on the processing, the actors and the risks.

Do you train our teams? Are we required to do so?

Yes, we train your teams — and in part it is now an obligation: Article 4 of the European AI regulation requires organisations deploying AI systems to ensure a sufficient level of AI literacy among their staff, and the GDPR makes awareness-raising one of the DPO’s tasks (Article 39). Our health GDPR, security and AI training courses are included or added depending on the plan.

Do you guarantee the absence of an inspection or a sanction?

No — no serious provider can guarantee that. Our work consists of organising your compliance, reducing your risks and building the evidence that enables you to respond. The final decision on each processing operation remains your organisation’s.

What makes the price vary from the starting rate?

Complexity, not just size: number of entities and sites, nature and volume of data, ongoing projects, critical processors, research activity, presence of AI, expected level of availability. Each proposal details the included capacity, the deliverables and the exclusions.

Unsure which tier fits your situation?

Describe your organisation and your trigger event: we recommend the matching offer — or tell you frankly if a lighter arrangement is enough.

Reply within 24 business hours · No commitment