Clear offers, defined capacity, no hidden “unlimited”
Cost depends on your actual complexity: entities, processing activities, projects, processors and the expected level of availability. Our starting rates let you situate yourself immediately; each proposal then specifies the included capacity, the deliverables and the exclusions.
Step 1 — lay the foundations
One-off engagements
A defined scope, deliverables, a fixed price — billed once, with no long-term commitment. This is the recommended entry point before any subscription.
Health Compliance Diagnostic
Any organisation, before any commitment
Identify your priority risks and decide on next steps with full knowledge of the facts.
- Scoping interview (90 min)
- Targeted document review
- Maturity score by domain
- Your top 3 priorities and a roadmap
- Findings presented by videoconference
Findings delivered within 10 business days
from €1,500 excl. VAT
Amount deducted in full from the Health Compliance Foundation if you engage it within 30 days of the findings presentation.
Request my diagnosticHealth Compliance Foundation
CPTS, MSP, health centres, medico-social organisations
Move from scattered compliance to an organised, prioritised and demonstrable foundation.
Includes the Diagnostic’s baseline assessment — plus:
- Mapping of processing activities and data flows
- Initial record of processing activities
- Review of processors and contracts to check
- Screening of processing operations requiring a DPIA
- 90-day and 12-month roadmap
- Management debrief and initial awareness session
6 to 8 weeks
from €5,000 excl. VAT
Diagnostic already completed? It serves as the starting point — and its amount (€1,500 excl. VAT) is deducted from the Foundation if you engage it within 30 days of the findings presentation.
Request the Compliance FoundationFacility Compliance Foundation
EHPAD, clinics, groups and multi-site organisations
The full foundation, sized for the volumes, governance and multiple sites of a facility.
Includes everything in the Health Compliance Foundation — plus:
- Multi-site mapping and group governance
- Authorisation matrix and review of access to records
- Internal control plan and identified relays per site
- Presentation to the executive committee
8 to 12 weeks
from €9,900 excl. VAT
Diagnostic already completed? Its amount (€1,500 excl. VAT) is deducted if you engage the foundation within 30 days of the findings presentation.
Scope my facility foundationStep 2 — establish the function over time
Outsourced DPO subscriptions
Monthly billing for reserved capacity, a DPO designated with the CNIL and a governance rhythm. Each tier includes everything in the previous tier. The most common path: Diagnostic, then Foundation, then subscription — each step can also be engaged on its own.
Health DPO — Essential
Organisations with a simple, stable scope
A designated DPO, a governance rhythm and a defined intervention capacity.
- DPO designation with the CNIL
- Dedicated point of contact — first response within 24 business hours
- Reserved intervention capacity every month, poolable per quarter — sized in the written proposal
- Quarterly committee and annual report
- Handling of data-subject requests and simple incidents
- Regulatory watch applied to your scope
Initial 12-month commitment recommended
from €690 excl. VAT/month
Added to an onboarding fee quoted for your situation: taking over an existing set-up, or building the foundation (see Health Compliance Foundation).
Choose Health DPO — EssentialHealth DPO — Steering
Software vendors, medtechs, multi-project organisations
Embed compliance into your projects, your sales and your partner relationships.
Includes everything in the Essential tier — plus:
- Reinforced monthly intervention capacity, adjusted to your actual scope
- Monthly committee and review of new projects
- Support with client questionnaires and due diligence
- Review of processor documentation
- Management dashboard
Initial 12-month commitment recommended
from €1,500 excl. VAT/month
Added to an onboarding fee quoted for your situation: taking over an existing set-up, or building the foundation (see Health Compliance Foundation).
Choose Health DPO — SteeringFacility DPO
Clinics, groups, multi-site organisations
Reinforced governance for complex, high-volume environments.
Includes everything in the Steering tier — plus:
- Intervention capacity sized for the facility — volume, sites and governance
- Executive committee and reinforced monthly governance
- Internal relays, control plan and multi-site monitoring
- Structured management of projects and incidents
- Executive reporting and annual evidence file
Perimeter defined after scoping
from €3,500 excl. VAT/month
The initial scoping defines the perimeter, the sites covered and the onboarding — quoted before any commitment.
Scope my facility needsWhen every hour counts
Emergencies
An announced inspection or an ongoing breach cannot wait for a sales cycle: priority handling, a bounded scope, a price known in advance.
CNIL Inspection Response
Inspection under way, announced, or CNIL letter received
Priority handling to organise the evidence, the responses and the teams — without improvisation.
- Immediate scoping — activation within 4 business hours
- Freezing and collection of evidence: record of processing, DPIAs, authorisations, contracts
- Response plan and preparation of your spokespeople
- Coordination of data-protection responses
- Articulation with your lawyer where necessary
Activation within 4 business hours
from €5,900 excl. VAT
Legal representation and litigation are handled by your lawyer, with whom we coordinate.
Activate a priority responseHealth Data Breach Response
Security incident affecting health data
Qualify fast, notify right, document everything: the 72 hours after an incident decide what comes next.
- Qualification of the breach and assessment of the risk to individuals
- Notification to the CNIL within 72 hours where required
- Information of the individuals concerned where applicable
- Complete documentation in the breach register
- Coordination of the technical investigation with the cybersecurity partner
Same-day qualification
from €3,500 excl. VAT
Excludes technical investigation — quoted separately by our cybersecurity partner, in coordination with us.
Qualify my incidentDepending on your projects
Specialised engagements
Expert missions, also one-off: scoped, quoted and billed per engagement — alongside a subscription or on a standalone basis.
Health DPIA
Processing likely to result in a high risk
A framed, documented impact assessment your management can act on.
- Scoping of the processing and stakeholders
- Necessity and proportionality analysis
- Risk scenarios and measures
- Documentation of decisions and residual risks
3 to 8 weeks depending on the processing
from €3,000 excl. VAT
e-Health Product Compliance
Health SaaS, telemedicine, digital medical devices, AI
Prepare your product, your contracts and your evidence for buyers, partners and investors.
- Data-flow mapping and role qualification
- Privacy by design and DPIA screening
- HDS scoping and processor governance
- AI Act qualification where applicable
- Response pack for buyer questionnaires
8 to 16 weeks
Priced after scoping
AI Compliance — AI Act
Providers and deployers of AI systems in healthcare
Qualify your AI systems, structure your obligations and train your teams — Article 4 of the AI Act already requires AI literacy for the staff concerned.
- Qualification of your systems under the AI Act
- Mapping of provider / deployer obligations
- AI literacy programme for your teams (Article 4)
- Articulation of the AI Act, GDPR and health data
- Roadmap aligned with the regulatory timeline
Depending on the number and criticality of systems
Priced after scoping
EHDS Preparation
Facilities, EHR software vendors, health data holders
The European Health Data Space will apply in stages: getting ahead turns a constraint into a market position.
- Mapping of your data with regard to the EHDS (primary and secondary use)
- Qualification of your obligations according to your role
- Compliance trajectory aligned with the regulation’s deadlines
- Articulation of the EHDS, GDPR and HDS certification
- Dedicated watch on upcoming implementing acts
Multi-year programme, by milestones
Priced after scoping
International Data Transfers
Groups, vendors with non-EU processors, French-speaking organisations across Europe
A US processor, a subsidiary outside the EU, an international research project: every outbound flow must rest on a valid transfer tool.
- Mapping of data flows outside the EU / EEA
- Qualification of the appropriate transfer tool for each flow (adequacy, standard contractual clauses, Article 49)
- Documented transfer impact assessments (TIAs)
- Review of processing chains and vendor documentation
- Articulation with HDS hosting and localisation requirements
- Support across French-speaking Europe: Belgium and Luxembourg (GDPR), Switzerland (nFADP), Monaco (Law No. 1.565)
Depending on the number of flows and destinations
Priced after scoping
Research & Health Data
Sponsors, CROs, facilities, health data warehouses
Secure the framework, flows, responsibilities and evidence of a data project.
- Qualification of roles and the applicable framework
- Mapping of sources, flows and access
- Information, rights and retention periods
- DPIA where required, documentary governance
8 to 24 weeks
Priced after scoping
Health Training & Awareness
Up to 15 participants — management, care staff, administrative, technical
Health GDPR, security and AI training grounded in your real situations — and for AI, a legal obligation since February 2025 (Article 4 of the AI Act).
- Programme tailored to your roles and your tools
- Practical cases drawn from your context
- Materials provided to participants
- Retention quiz and summary for management
- Certificate of participation
Half-day, remote or on site
from €1,500 excl. VAT
Six formats calibrated by audience — frontline staff, management, internal relays, product, AI (Article 4), crisis exercise — detailed on the Training page.
Train my teamsStarting rates excl. VAT, for a single, simple entity. Each written proposal details the scope, the included capacity, the deliverables, the timelines and the exclusions — no service is undertaken without prior agreement on its estimate.
What our offers include — and what they don’t replace
Clarity of scope protects your organisation as much as ours: everyone knows who does what, and who we work with when a matter goes beyond the DPO’s remit.
Included in our engagements
- Operational advice within the DPO’s remit
- Advice on technical and organisational security measures (Article 32 GDPR)
- Records, procedures, mappings and action plans
- Impact assessments within the agreed scope
- Support with qualifying and notifying breaches
- Regulatory watch applied to your scope
Handled separately or by our partners
- Legal consultations, drafting of legal instruments and litigation — handled by independent lawyers to whom we refer you
- Technical audits, penetration tests and technical incident response — quoted separately by our cybersecurity partner
- Time beyond the included capacity — estimated and approved before any work
- Emergencies outside the service level — handled under the conditions set out in the contract
Pricing: what we’re asked most often
Why an onboarding cost on top of the DPO subscription?
Onboarding covers taking over or building the foundation: interviews, mapping, record of processing, action plan and designation. The subscription then funds reserved capacity, a governance rhythm and a service level — not an initial catch-up diluted over time.
Is the Diagnostic wasted money if we continue with the Foundation?
No: if you engage the Health Compliance Foundation within 30 days of the Diagnostic’s findings presentation, its amount (€1,500 excl. VAT) is deducted in full from the price of the Foundation. The baseline assessment then serves directly as the starting point for scoping — you never pay twice for the same work.
Is the number of questions unlimited?
No, and that is deliberate: each plan specifies a monthly capacity and response times. This transparency protects the quality with which each request is handled — an “unlimited” promise is always paid for in quality or in delays.
Is a DPIA included in the subscriptions?
The subscriptions include the screening and scoping of processing operations likely to require an impact assessment. The full assessment is quoted separately after qualification, because its complexity depends on the processing, the actors and the risks.
Do you train our teams? Are we required to do so?
Yes, we train your teams — and in part it is now an obligation: Article 4 of the European AI regulation requires organisations deploying AI systems to ensure a sufficient level of AI literacy among their staff, and the GDPR makes awareness-raising one of the DPO’s tasks (Article 39). Our health GDPR, security and AI training courses are included or added depending on the plan.
Do you guarantee the absence of an inspection or a sanction?
No — no serious provider can guarantee that. Our work consists of organising your compliance, reducing your risks and building the evidence that enables you to respond. The final decision on each processing operation remains your organisation’s.
What makes the price vary from the starting rate?
Complexity, not just size: number of entities and sites, nature and volume of data, ongoing projects, critical processors, research activity, presence of AI, expected level of availability. Each proposal details the included capacity, the deliverables and the exclusions.
Unsure which tier fits your situation?
Describe your organisation and your trigger event: we recommend the matching offer — or tell you frankly if a lighter arrangement is enough.
Reply within 24 business hours · No commitment
