Client Cases

Each of our clients is unique — operating in their own context, with their own constraints and ambitions. Compliance is always shaped by these characteristics, which is why our services are systematically tailored to the specific needs of each organisation we work with.

The following examples illustrate how we work with our clients.

photo-de-léah-et-nadia-trustem-agence-spécialisée-en-conformité-rgpd
Etoile Yale 7
Book a Meeting

Book a call with one of our team members to discuss your needs.

Managing and steering GDPR compliance for a startup as External DPO

Who is it for?

A startup of approximately 30 employees developing and marketing AI-based digital medical devices.

Needs & Constraints

The organisation needed long-term support from an expert capable of both steering day-to-day GDPR compliance and providing on-demand advice on complex questions arising from health R&D projects.

Given the nature of the organisation and its regulatory environment, the key expectations were: the ability to respond within tight timeframes, flexibility, and deep expertise in digital health and emerging technologies.

What We Put in Place

Trustem was officially designated as External DPO with the supervisory authority.

In this capacity, we proactively steer the organisation’s ongoing compliance while remaining available to address needs as they arise — such as reviewing contracts with new service providers.
These requests are typically channelled through the organisation’s internal point of contact, who serves as our primary interlocutor. Our work includes maintaining the records of processing activities via the Witik platform, raising staff awareness, and drafting internal procedures for personal data management.

We also support the operational teams in conducting the DPIAs required for health research projects. In addition, we assist senior management in negotiations with institutional and commercial partners, and in decision-making, by providing clarity on the compliance risks associated with planned projects.

Key Benefits & Outcomes

Supporting a group’s compliance through on-demand assistance to the legal department

Who is it for?

A large French franchisor operating across multiple countries.

Needs & Constraints

The legal department had been entrusted with managing the group’s data protection compliance.
It needed a qualified external partner capable of providing rapid, targeted guidance on specific compliance issues relating to internal projects, as well as ready-to-use templates to improve operational efficiency in implementing regulatory requirements.

What We Put in Place

The Trustem team intervenes at the request of the in-house legal team, who can contact us by email at any time. Where needed, email exchanges are supplemented by phone calls or video conferences. We agreed with our client on a retainer of advisory hours, which can be drawn upon as required.

For each new request, we agree on a response timeframe — typically ranging from 24 hours to 15 working days depending on the nature, urgency, and complexity of the matter.
We provide regular updates on hours consumed to allow timely renewal of the retainer.

Key Benefits & Outcomes

Assessing GDPR maturity to refine a compliance strategy

Who is it for?

A mid-sized company providing accounting and audit services.

Needs & Constraints

The company had begun its compliance programme in 2018. More than five years on, it wanted a clear picture of its maturity level in order to assess whether its compliance organisation and strategy needed strengthening, and to determine the scope of future external DPO support.

What We Put in Place

Trustem conducted a maturity audit. This involved interviews with key departments and a review of relevant documentation, including contracts with key partners.

The audit resulted in a diagnostic report structured around the 8 themes used by the French data protection authority to assess GDPR maturity. For each theme, we assigned a maturity score accompanied by concrete recommendations for improvement, and proposed a prioritised roadmap for implementation.

These deliverables, together with a proposal for Trustem to support the implementation of the roadmap, were presented to senior management at a debrief meeting.

Following the audit, Trustem was appointed as External DPO to steer the compliance strategy and support operational teams in implementing the identified actions.

Key Benefits & Outcomes

Framing the compliance of an application project prior to market launch

Who is it for?

A project owner seeking to develop a mobile and web application in the healthcare sector.

Needs & Constraints

The project owner needed to identify key data protection considerations under applicable regulations and receive tailored recommendations to ensure the application’s compliance — ahead of development and deployment.

Given the intended use of the application, in-depth knowledge of the regulatory requirements applicable to health data was both necessary and expected.

Work also needed to be completed within tight deadlines, given the already-fixed production launch date.

What We Put in Place

Several working sessions were held with the project owner and the development company to map the application’s planned features and the personal data processing activities that would result from them.

On this basis, the Trustem team produced a high-level compliance framework note covering all key aspects: allocation of responsibilities, transparency, lawfulness, data retention modalities and periods, and more. We formulated approximately twenty recommendations and proposed practical implementation arrangements.

The note was delivered within three weeks of receiving the information required for the analysis.

Following this scoping engagement, we proposed to support the project owner in drafting the required documentation — including the application’s privacy policy and information notices — on a fixed-fee basis.

Key Benefits & Outcomes

Conducting a DPIA for an innovative system deployed by a large local authority

Who is it for?

A large French city required to carry out a DPIA prior to implementing sensitive processing activities, and seeking to manage the associated project risks.

Needs & Constraints

The authority needed to rely entirely on our team to conduct the DPIA, as it lacked the necessary in-house resources. It also called on us to contribute to the selection of the service provider responsible for deploying the system.

The assessment required the ability to coordinate a large number of stakeholders, as well as a thorough understanding of the regulatory framework applicable to the public sector.

Finally, as the DPIA was conducted at a very early stage of the project, it needed to follow a privacy-by-design approach — serving as a genuine decision-support tool for the authority.

What We Put in Place

We began by reviewing the compliance credentials of the shortlisted service providers, advising the authority throughout the selection process.

Once the provider was selected, we facilitated several workshops with the technical and operational teams and reviewed the project documentation. On this basis, we drafted the full DPIA report, the findings of which were presented to management at a debrief meeting.

Following the assessment, the authority also asked us to implement certain actions identified as necessary, including contractual compliance updates and the drafting of information documents.

Key Benefits & Outcomes

Managing and steering GDPR compliance for a startup as External DPO

Who is it for?

A startup of approximately 30 employees developing and marketing AI-based digital medical devices.

Needs & Constraints

The organisation needed long-term support from an expert capable of both steering day-to-day GDPR compliance and providing on-demand advice on complex questions arising from health R&D projects.

Given the nature of the organisation and its regulatory environment, the key expectations were: the ability to respond within tight timeframes, flexibility, and deep expertise in digital health and emerging technologies.

What We Put in Place

Trustem was officially designated as External DPO with the supervisory authority.

In this capacity, we proactively steer the organisation’s ongoing compliance while remaining available to address needs as they arise — such as reviewing contracts with new service providers.
These requests are typically channelled through the organisation’s internal point of contact, who serves as our primary interlocutor. Our work includes maintaining the records of processing activities via the Witik platform, raising staff awareness, and drafting internal procedures for personal data management.

We also support the operational teams in conducting the DPIAs required for health research projects. In addition, we assist senior management in negotiations with institutional and commercial partners, and in decision-making, by providing clarity on the compliance risks associated with planned projects.

Key Benefits & Outcomes

Supporting a group’s compliance through on-demand assistance to the legal department

Who is it for?

A large French franchisor operating across multiple countries.

Needs & Constraints

The legal department had been entrusted with managing the group’s data protection compliance.
It needed a qualified external partner capable of providing rapid, targeted guidance on specific compliance issues relating to internal projects, as well as ready-to-use templates to improve operational efficiency in implementing regulatory requirements.

What We Put in Place

The Trustem team intervenes at the request of the in-house legal team, who can contact us by email at any time. Where needed, email exchanges are supplemented by phone calls or video conferences. We agreed with our client on a retainer of advisory hours, which can be drawn upon as required.

For each new request, we agree on a response timeframe — typically ranging from 24 hours to 15 working days depending on the nature, urgency, and complexity of the matter.
We provide regular updates on hours consumed to allow timely renewal of the retainer.

Key Benefits & Outcomes

Assessing GDPR maturity to refine a compliance strategy

Who is it for?

A mid-sized company providing accounting and audit services.

Needs & Constraints

The company had begun its compliance programme in 2018. More than five years on, it wanted a clear picture of its maturity level in order to assess whether its compliance organisation and strategy needed strengthening, and to determine the scope of future external DPO support.

What We Put in Place

Trustem conducted a maturity audit. This involved interviews with key departments and a review of relevant documentation, including contracts with key partners.

The audit resulted in a diagnostic report structured around the 8 themes used by the French data protection authority to assess GDPR maturity. For each theme, we assigned a maturity score accompanied by concrete recommendations for improvement, and proposed a prioritised roadmap for implementation.

These deliverables, together with a proposal for Trustem to support the implementation of the roadmap, were presented to senior management at a debrief meeting.

Following the audit, Trustem was appointed as External DPO to steer the compliance strategy and support operational teams in implementing the identified actions.

Key Benefits & Outcomes

Framing the compliance of an application project prior to market launch

Who is it for?

A project owner seeking to develop a mobile and web application in the healthcare sector.

Needs & Constraints

The project owner needed to identify key data protection considerations under applicable regulations and receive tailored recommendations to ensure the application’s compliance — ahead of development and deployment.

Given the intended use of the application, in-depth knowledge of the regulatory requirements applicable to health data was both necessary and expected.

Work also needed to be completed within tight deadlines, given the already-fixed production launch date.

What We Put in Place

Several working sessions were held with the project owner and the development company to map the application’s planned features and the personal data processing activities that would result from them.

On this basis, the Trustem team produced a high-level compliance framework note covering all key aspects: allocation of responsibilities, transparency, lawfulness, data retention modalities and periods, and more. We formulated approximately twenty recommendations and proposed practical implementation arrangements.

The note was delivered within three weeks of receiving the information required for the analysis.

Following this scoping engagement, we proposed to support the project owner in drafting the required documentation — including the application’s privacy policy and information notices — on a fixed-fee basis.

Key Benefits & Outcomes

Conducting a DPIA for an innovative system deployed by a large local authority

Who is it for?

A large French city required to carry out a DPIA prior to implementing sensitive processing activities, and seeking to manage the associated project risks.

Needs & Constraints

 The authority needed to rely entirely on our team to conduct the DPIA, as it lacked the necessary in-house resources. It also called on us to contribute to the selection of the service provider responsible for deploying the system.

The assessment required the ability to coordinate a large number of stakeholders, as well as a thorough understanding of the regulatory framework applicable to the public sector.

Finally, as the DPIA was conducted at a very early stage of the project, it needed to follow a privacy-by-design approach — serving as a genuine decision-support tool for the authority.

What We Put in Place

We began by reviewing the compliance credentials of the shortlisted service providers, advising the authority throughout the selection process.

Once the provider was selected, we facilitated several workshops with the technical and operational teams and reviewed the project documentation. On this basis, we drafted the full DPIA report, the findings of which were presented to management at a debrief meeting.

Following the assessment, the authority also asked us to implement certain actions identified as necessary, including contractual compliance updates and the drafting of information documents.

Key Benefits & Outcomes

Customers reviews