Our Services

At Trustem, we don’t believe in one-size-fits-all templates or generic approaches that burden your teams and deliver little real impact.

We focus on operational, hands-on engagements and ready-to-use deliverables — designed to save you time and produce tangible results. 

illustrations prestations trustem

GDPR Audits

A GDPR audit assesses how well your organisation complies with data protection requirements and establishes an action plan.
Two types of audit are available:

A maturity audit, snapshot and broad-scope
A compliance audit, in-depth and comprehensive

Tailored Advisory Support

Our tailored advisory support services provide operational assistance — on an ad hoc or ongoing basis. These are flexible, adaptable engagements designed to meet your specific needs.

External DPO

Do you need long-term support from an expert team capable of steering your GDPR compliance and advising you on the rules governing the personal data you process? We can take on the role of outsourced Data Protection Officer (DPO) on your behalf.

Once designated with the relevant supervisory authority, the DPO acts as the orchestrator of compliance within your organisation and becomes the primary point of contact with that authority.

GDPR Compliance Strategy & Advisory

Our team can help you make the right decisions for your GDPR compliance — whether that means defining your overall compliance strategy or clarifying the precise regulatory constraints of a specific project.

– Overall compliance strategy
– Project-level compliance strategy

Training & Awareness

GDPR requires organisations to raise their teams’ awareness of data protection on a regular basis. Beyond this baseline obligation, certain professionals need more in-depth training.

Our team, with extensive experience in training and education, can deliver awareness sessions or tailored training programmes adapted to your sector.

AI Compliance Advisory

The development or use of artificial intelligence systems is subject to both the GDPR and the EU AI Act.

Our team can help you understand and implement your obligations under these regulations.

Frequently Asked Questions

The GDPR applies very broadly. Regardless of your organisation’s sector, size, or legal form, you are subject to it. You process personal data in the course of managing your human resources and accounting, and most likely as part of the products and services you provide. That said, the extent of your obligations may vary depending on the sensitivity of your activities.

Beyond the risk of financial penalties from the supervisory authority — which can reach up to 4% of annual worldwide turnover or €20 million — non-compliance exposes you to reputational risk (loss of trust within your ecosystem following negative publicity) and economic risk (difficulties accessing certain markets, inability to meet the expectations of clients and partners, obstacles to fundraising rounds, time lost in backtracking on decisions, and so on). In addition, compliance failures can be used against you in a wide range of legal disputes — employment, commercial, and competition — and can serve as an entry point for cyberattacks.

Data protection regulations are complex to understand and to implement in practice. A serious and effective compliance programme requires a thorough command of the many applicable texts — the GDPR, the ePrivacy Directive, health data regulations, and others — as well as a sound understanding of how supervisory authorities apply them in practice across different sectors.

In addition, familiarity with sector-specific practices and risks is essential to defining the right compliance strategy. Engaging a team with a high level of expertise addresses these challenges and contributes to reassuring the regulator.

Furthermore, working with an external partner relieves the burden on your internal teams, while ensuring the flexibility needed to respond to the events and changes that mark the life of any organisation. 

The time required for an audit depends on the type of audit and the size and complexity of the organisation being audited.

A maturity audit typically takes one to two months, while a full compliance audit takes two to three months.
That said, if you are working to a tight deadline, please do let us know — we will do our best to accommodate your timescales. 

Yes — we can produce your compliance documentation in close collaboration with your internal teams. This typically includes records of processing activities, policies and procedures, information notices, and data protection impact assessments.

No. As specialists in the regulatory dimension of data protection, we are not cybersecurity experts and do not conduct information system security audits — each to their own area of expertise.

Where we identify a need for this type of audit, we draw on our network of partners who are equipped to provide it.

Yes — our partnership with Witik allows us to leverage a dedicated web platform to manage our clients’ compliance programmes.