Client Cases
Each of our clients is unique — operating in their own context, with their own constraints and ambitions. Compliance is always shaped by these characteristics, which is why our services are systematically tailored to the specific needs of each organisation we work with.
The following examples illustrate how we work with our clients.
Book a call with one of our team members to discuss your needs.
Managing and steering GDPR compliance for a startup as External DPO
A startup of approximately 30 employees developing and marketing AI-based digital medical devices.
The organisation needed long-term support from an expert capable of both steering day-to-day GDPR compliance and providing on-demand advice on complex questions arising from health R&D projects.
Given the nature of the organisation and its regulatory environment, the key expectations were: the ability to respond within tight timeframes, flexibility, and deep expertise in digital health and emerging technologies.
Trustem was officially designated as External DPO with the supervisory authority.
In this capacity, we proactively steer the organisation’s ongoing compliance while remaining available to address needs as they arise — such as reviewing contracts with new service providers.
These requests are typically channelled through the organisation’s internal point of contact, who serves as our primary interlocutor. Our work includes maintaining the records of processing activities via the Witik platform, raising staff awareness, and drafting internal procedures for personal data management.
We also support the operational teams in conducting the DPIAs required for health research projects. In addition, we assist senior management in negotiations with institutional and commercial partners, and in decision-making, by providing clarity on the compliance risks associated with planned projects.
- Strong buy-in from both teams and management on the compliance strategy.
- More efficient negotiations and stronger relationships with industrial and scientific partners.
- Improved overall data governance, particularly in R&D activities.
- Full management of GDPR compliance and sector-specific health data obligations.
- Time savings in GDPR-related document management, thanks to our templates and compliance platform.
Supporting a group’s compliance through on-demand assistance to the legal department
A large French franchisor operating across multiple countries.
The legal department had been entrusted with managing the group’s data protection compliance.
It needed a qualified external partner capable of providing rapid, targeted guidance on specific compliance issues relating to internal projects, as well as ready-to-use templates to improve operational efficiency in implementing regulatory requirements.
The Trustem team intervenes at the request of the in-house legal team, who can contact us by email at any time. Where needed, email exchanges are supplemented by phone calls or video conferences. We agreed with our client on a retainer of advisory hours, which can be drawn upon as required.
For each new request, we agree on a response timeframe — typically ranging from 24 hours to 15 working days depending on the nature, urgency, and complexity of the matter.
We provide regular updates on hours consumed to allow timely renewal of the retainer.
- Time savings and reduced burden for the legal department, allowing it to focus on its core remit.
- Guaranteed rapid, precise, and well-documented responses, enabling issues to be addressed as they arise.
- Budget flexibility and predictability through a pre-defined retainer, adjustable at any time based on evolving needs.
Assessing GDPR maturity to refine a compliance strategy
A mid-sized company providing accounting and audit services.
The company had begun its compliance programme in 2018. More than five years on, it wanted a clear picture of its maturity level in order to assess whether its compliance organisation and strategy needed strengthening, and to determine the scope of future external DPO support.
Trustem conducted a maturity audit. This involved interviews with key departments and a review of relevant documentation, including contracts with key partners.
The audit resulted in a diagnostic report structured around the 8 themes used by the French data protection authority to assess GDPR maturity. For each theme, we assigned a maturity score accompanied by concrete recommendations for improvement, and proposed a prioritised roadmap for implementation.
These deliverables, together with a proposal for Trustem to support the implementation of the roadmap, were presented to senior management at a debrief meeting.
Following the audit, Trustem was appointed as External DPO to steer the compliance strategy and support operational teams in implementing the identified actions.
- A clear, comprehensive view of maturity level and risk exposure, enabling informed prioritisation decisions.
- Strong management buy-in for the proposed roadmap, underpinned by concrete objectives and measurable progress indicators.
- Rapid launch of the improvement programme, with Trustem appointed as External DPO to oversee implementation.
Framing the compliance of an application project prior to market launch
A project owner seeking to develop a mobile and web application in the healthcare sector.
The project owner needed to identify key data protection considerations under applicable regulations and receive tailored recommendations to ensure the application’s compliance — ahead of development and deployment.
Given the intended use of the application, in-depth knowledge of the regulatory requirements applicable to health data was both necessary and expected.
Work also needed to be completed within tight deadlines, given the already-fixed production launch date.
Several working sessions were held with the project owner and the development company to map the application’s planned features and the personal data processing activities that would result from them.
On this basis, the Trustem team produced a high-level compliance framework note covering all key aspects: allocation of responsibilities, transparency, lawfulness, data retention modalities and periods, and more. We formulated approximately twenty recommendations and proposed practical implementation arrangements.
The note was delivered within three weeks of receiving the information required for the analysis.
Following this scoping engagement, we proposed to support the project owner in drafting the required documentation — including the application’s privacy policy and information notices — on a fixed-fee basis.
- Early anticipation of data-related regulatory issues through a privacy-by-design approach.
- Concrete, actionable solutions to address the identified issues.
- Enhanced confidence through a reduced risk profile for the project owner and their ecosystem.
Conducting a DPIA for an innovative system deployed by a large local authority
A large French city required to carry out a DPIA prior to implementing sensitive processing activities, and seeking to manage the associated project risks.
The authority needed to rely entirely on our team to conduct the DPIA, as it lacked the necessary in-house resources. It also called on us to contribute to the selection of the service provider responsible for deploying the system.
The assessment required the ability to coordinate a large number of stakeholders, as well as a thorough understanding of the regulatory framework applicable to the public sector.
Finally, as the DPIA was conducted at a very early stage of the project, it needed to follow a privacy-by-design approach — serving as a genuine decision-support tool for the authority.
We began by reviewing the compliance credentials of the shortlisted service providers, advising the authority throughout the selection process.
Once the provider was selected, we facilitated several workshops with the technical and operational teams and reviewed the project documentation. On this basis, we drafted the full DPIA report, the findings of which were presented to management at a debrief meeting.
Following the assessment, the authority also asked us to implement certain actions identified as necessary, including contractual compliance updates and the drafting of information documents.
- Effective risk management through an operational action plan.
- Full management of a complex and time-consuming task, relieving operational teams and the in-house DPO.
- An external perspective enabling objective and reliable analysis.
- A collaborative methodology fostering data protection awareness across teams and management.
External DPO for a Medtech Startup
Managing and steering GDPR compliance for a startup as External DPO
A startup of approximately 30 employees developing and marketing AI-based digital medical devices.
The organisation needed long-term support from an expert capable of both steering day-to-day GDPR compliance and providing on-demand advice on complex questions arising from health R&D projects.
Given the nature of the organisation and its regulatory environment, the key expectations were: the ability to respond within tight timeframes, flexibility, and deep expertise in digital health and emerging technologies.
Trustem was officially designated as External DPO with the supervisory authority.
In this capacity, we proactively steer the organisation’s ongoing compliance while remaining available to address needs as they arise — such as reviewing contracts with new service providers.
These requests are typically channelled through the organisation’s internal point of contact, who serves as our primary interlocutor. Our work includes maintaining the records of processing activities via the Witik platform, raising staff awareness, and drafting internal procedures for personal data management.
We also support the operational teams in conducting the DPIAs required for health research projects. In addition, we assist senior management in negotiations with institutional and commercial partners, and in decision-making, by providing clarity on the compliance risks associated with planned projects.
- Strong buy-in from both teams and management on the compliance strategy.
- More efficient negotiations and stronger relationships with industrial and scientific partners.
- Improved overall data governance, particularly in R&D activities.
- Full management of GDPR compliance and sector-specific health data obligations.
- Time savings in GDPR-related document management, thanks to our templates and compliance platform.
Tailored Support for a Large Group
Supporting a group’s compliance through on-demand assistance to the legal department
A large French franchisor operating across multiple countries.
The legal department had been entrusted with managing the group’s data protection compliance.
It needed a qualified external partner capable of providing rapid, targeted guidance on specific compliance issues relating to internal projects, as well as ready-to-use templates to improve operational efficiency in implementing regulatory requirements.
The Trustem team intervenes at the request of the in-house legal team, who can contact us by email at any time. Where needed, email exchanges are supplemented by phone calls or video conferences. We agreed with our client on a retainer of advisory hours, which can be drawn upon as required.
For each new request, we agree on a response timeframe — typically ranging from 24 hours to 15 working days depending on the nature, urgency, and complexity of the matter.
We provide regular updates on hours consumed to allow timely renewal of the retainer.
- Time savings and reduced burden for the legal department, allowing it to focus on its core remit.
- Guaranteed rapid, precise, and well-documented responses, enabling issues to be addressed as they arise.
- Budget flexibility and predictability through a pre-defined retainer, adjustable at any time based on evolving needs.
SME Audit
Assessing GDPR maturity to refine a compliance strategy
A mid-sized company providing accounting and audit services.
The company had begun its compliance programme in 2018. More than five years on, it wanted a clear picture of its maturity level in order to assess whether its compliance organisation and strategy needed strengthening, and to determine the scope of future external DPO support.
Trustem conducted a maturity audit. This involved interviews with key departments and a review of relevant documentation, including contracts with key partners.
The audit resulted in a diagnostic report structured around the 8 themes used by the French data protection authority to assess GDPR maturity. For each theme, we assigned a maturity score accompanied by concrete recommendations for improvement, and proposed a prioritised roadmap for implementation.
These deliverables, together with a proposal for Trustem to support the implementation of the roadmap, were presented to senior management at a debrief meeting.
Following the audit, Trustem was appointed as External DPO to steer the compliance strategy and support operational teams in implementing the identified actions.
- A clear, comprehensive view of maturity level and risk exposure, enabling informed prioritisation decisions.
- Strong management buy-in for the proposed roadmap, underpinned by concrete objectives and measurable progress indicators.
- Rapid launch of the improvement programme, with Trustem appointed as External DPO to oversee implementation.
Application Compliance
Framing the compliance of an application project prior to market launch
A project owner seeking to develop a mobile and web application in the healthcare sector.
The project owner needed to identify key data protection considerations under applicable regulations and receive tailored recommendations to ensure the application’s compliance — ahead of development and deployment.
Given the intended use of the application, in-depth knowledge of the regulatory requirements applicable to health data was both necessary and expected.
Work also needed to be completed within tight deadlines, given the already-fixed production launch date.
Several working sessions were held with the project owner and the development company to map the application’s planned features and the personal data processing activities that would result from them.
On this basis, the Trustem team produced a high-level compliance framework note covering all key aspects: allocation of responsibilities, transparency, lawfulness, data retention modalities and periods, and more. We formulated approximately twenty recommendations and proposed practical implementation arrangements.
The note was delivered within three weeks of receiving the information required for the analysis.
Following this scoping engagement, we proposed to support the project owner in drafting the required documentation — including the application’s privacy policy and information notices — on a fixed-fee basis.
- Early anticipation of data-related regulatory issues through a privacy-by-design approach.
- Concrete, actionable solutions to address the identified issues.
- Enhanced confidence through a reduced risk profile for the project owner and their ecosystem.
Conducting a DPIA
Conducting a DPIA for an innovative system deployed by a large local authority
A large French city required to carry out a DPIA prior to implementing sensitive processing activities, and seeking to manage the associated project risks.
The authority needed to rely entirely on our team to conduct the DPIA, as it lacked the necessary in-house resources. It also called on us to contribute to the selection of the service provider responsible for deploying the system.
The assessment required the ability to coordinate a large number of stakeholders, as well as a thorough understanding of the regulatory framework applicable to the public sector.
Finally, as the DPIA was conducted at a very early stage of the project, it needed to follow a privacy-by-design approach — serving as a genuine decision-support tool for the authority.
We began by reviewing the compliance credentials of the shortlisted service providers, advising the authority throughout the selection process.
Once the provider was selected, we facilitated several workshops with the technical and operational teams and reviewed the project documentation. On this basis, we drafted the full DPIA report, the findings of which were presented to management at a debrief meeting.
Following the assessment, the authority also asked us to implement certain actions identified as necessary, including contractual compliance updates and the drafting of information documents.
- Effective risk management through an operational action plan.
- Full management of a complex and time-consuming task, relieving operational teams and the in-house DPO.
- An external perspective enabling objective and reliable analysis.
- A collaborative methodology fostering data protection awareness across teams and management.
Customers reviews
Dans le cadre d’une prestation d’accompagnement afin de réaliser une analyse d’impact relative à la protection des données (AIPD), le cabinet Trustem a fait preuve d’efficience, de professionnalisme et d’une grande réactivité. La méthodologie mise en place par l’équipe de Trustem a permis d’aboutir à une analyse complète et détaillée avec une forte implication et beaucoup d’efficacité dans la gestion de ce projet. Le CDG31 est très satisfait de cette collaboration.
Je me sens rassuré d’être accompagné sur ces sujets délicats, et très satisfait de notre relation avec Leah qui est toujours disponible et compétente.
Un peu perdu dans mes obligations RGPD, nous avons une activité sensible qui est le courtage en assurance, beaucoup de données sensibles. Lea et son équipe, ont rapidement pu cibler mes obligations puis m’éclairer et corriger les défauts de ma structures. Grand merci pour leur réactivité et leur sérieux.
A l’écoute des besoins exprimés par la Ville du Havre, Nadia Fort et Léah Pérez ont apporté une analyse et un accompagnement qualitatifs. Leur expertise a permis d’assurer une bonne réactivité sur la prestation attendue. De plus, leur implication et leur disponibilité ont été appréciées notamment pour répondre aux questions complémentaires.
L’équipe de Trustem a su nous accompagner avec beaucoup de réactivité et de professionalisme sur la durée en s’adaptant spécifiquement à notre taille et nos besoins. Dynamisme, sérieux et rigueur, je recommande pleinement Léah et Nadia ainsi que leurs équipes pour vous accompagner sur vos problématiques RGPD.
Nous sommes accompagnés maintenant depuis plus d’un an par l’équipe Trustem et notamment Leah Perez. Notre retour d’expérience: efficacité, réactivité, écoute… tout y est, le travail effectué est de tres grande qualité, nous continuons l’aventure pour longtemps encore on espère …
L’accompagnement de Trustem a été crucial pour le développement de notre activité logiciel et la conformité de nos services en ligne. Une rare combinaison d’expertise pointue, de dynamisme et de compréhension des enjeux métiers. Merci Nadia!
Les recommandations formulées par Trustem sont très qualitatives sur le plan juridique tout en restant pragmatiques et réalistes, ce qui en fait un véritable partenaire de confiance pour la prise de décision.
Très professionnelle , réactif.
Pour Capteo Tech, la protection des données de nos dispositifs médicaux est une priorité non négociable. L’expertise de Trustem et de Leah, nous assure une conformité et une sécurité à toute épreuve. C’est un partenaire stratégique qui nous apporte la sérénité indispensable pour nous concentrer sur notre coeur de métier : l’innovation.