Since 25 May 2018, the General Data Protection Regulation (GDPR) has imposed rules on all entities collecting and processing personal data about EU citizens.
Data protection legislation is becoming more complex and risks are materializing at a rapid pace since 2018 with increasingly frequent and significant sanctions.
The legal risks can be of the following types (administrative: CNIL, up to 4% of turnover or 20 million Euros), civil or criminal law.
One of the main contributions of the General Data Regulation Protection (GDPR) is the creation of the Data Protection Officer (DPO).
As a personal data protection (PDP) expert, the DPO is responsible for steering the PDP management policy within a given organisation. The appointment of a DPO is mandatory for local authorities and organisations that handle personal data in great numbers, or for whose personal data processing is the core business.
Your DPO may be employed by your organisation. Or may be shared between several entities (e.g. in some local authorities) The DPO may also be external, a service provider who regularly intervenes on your behalf, without being your employee.
In all cases, the appointment of a DPO is made with the CNIL.
The appointment of a DPO also helps to reassure your clients and service providers, and in some cases it may even become a criterion of choice for responses to calls for tender.
The GDPR compliance is a project that requires a great deal of organisation, a perfect knowledge of the subject, as well as the allocation and animation of key resources.
Our DPO manages the GDPR compliance of your organisation. She puts her knowledge of the legal framework and her experience at your disposal.
→ If you already have a DPO and would like to provide him or her with the assistance of an RGPD expert, check out our RGPD Coaching offer.
The tasks of the DPO are at least laid down by the GDPR (Article 39 of the GDPR) and may be supplemented by national organisations such as the CNIL.
Our DPO will thus be responsible for :
« The external DPO from AlgoSecure ensures these 5 missions by providing the services allowing to ensure all these missions, so as to respect also the recommendations of the CNIL and by adding our added value AlgoSecure.»
In the CNIL’s DPO guide, recommendations leads to the creation of new sub-categories of obligations. By calling on our external DPO and by appointing us as your DPO with the CNIL, you ensure that AlgoSecure carries out these missions for your benefit.
Our External DPO will follow our adaptive method, alternating iteratively between workshops, isolated remote research and writing, and follow-up meetings.
Our DPO will get to know the context, your working environment, and meet your employees, thus facilitating future exchanges with them. The success of a GDPR project depends very much on the cooperation between the DPO and the various teams.
Once the roadmap has been validated, our DPO will work mainly remotely on compliance and on the specific needs you express.
This work will mainly consist of :
Once a month, our DPO will hold a follow-up meeting by video conference, and will inform you about the latest news related to the protection of personal data.
Once a quarter, our DPO will come to your premises to carry out planned interviews with your employees, a face-to-face follow-up meeting and to ensure a permanent presence for all non-urgent GDPR issues.
A summary activity report will be sent to you once every six months. An annual review of the GDPR activity, designed with the help of other consultants to provide a fresh perspective, will be carried out.
Throughout the service, our DPO will provide you with all the documents needed to trace the activities of our DPO and to justify your compliance. A verification of their completeness will be carried out at the end of these two years. This will be completed by a final annual review. Finally, depending on availability and needs, a transfer of skills may be organised with a new DPO.
Our DPOs are trained and certified by independent third parties and their knowledge is regularly checked internally. Monitoring personal data and cybersecurity law is an integral part of our business.
Our DPOs have been recruited following a comprehensive process, including a focus on the soft skills that make good consultants, such as listening skills, communication, conflict management and effective organisation.
All AlgoSecure DPOs have signed and respect our confidentiality commitment and our ethics charter. We are used to working in sensitive and complex contexts, which often require the consideration of particularly sensitive interests.
All our DPOs are absolutely passionate about data protection: this is the key to the success of their missions. Their pedagogical and benevolent approach allows for a constructive collaboration.
We accompany you on your RGPD issues.
We audit your personal data handling processes and list the points that are not compliant with the GDPR.
Nous vous proposons notre pack de service démarrage RGPD.
Specialists in information security and pentest in Lyon, Paris, Saint-Etienne and throughout France
You've enabled "Do Not Track" in your browser, we respect that choice and don't track your visit on our website.