Personal data protection and GDPR compliance in clinical research

Expertise: External DPO

Outsourced Data Protection Officer — GDPR compliance for clinical trials and businesses

External DPO — Personal Data

As an External Data Protection Officer, I am independent of your organization, operating under a service contract to ensure compliance with regulations covering all your personal data, including health data classified as sensitive.

My expertise

My interest in data protection began in 2006. I regularly keep my knowledge up to date through recognized training programs, CNIL MOOC, and webinars. I have specialized knowledge of national and European legislation, and an in-depth command of the GDPR and the French Data Protection Act (loi Informatique et Libertés).

When setting up clinical studies in young biotech companies, I managed the processing register and supported teams on data compliance. Since 2018, I have implemented GDPR compliance for clinical studies in several biotech organizations, with hands-on experience in register management, procedure drafting, Data Protection Impact Assessments (DPIA), and data breach handling.

Engagement terms

Any organisation processing personal data must ensure compliance with French and European regulations. I support you in implementing and maintaining your GDPR compliance, whether for a one-off assignment or an ongoing engagement, adapted to the size and needs of your organisation.

My activities

Inform and advise organisations, whether they are data processors or data controllers
Promote a culture of data protection within your teams and your organisation
Monitor compliance with regulations
Conduct GDPR compliance assessments
Establish and maintain the personal data register
Analyze the processing register data
Carry out a Data Protection Impact Assessment (DPIA) for high-risk processing
Implement security measures and raise awareness among employees
Draft the annual DPO activity report
React immediately in case of a data breach
Analysis of data subject rights requests and assistance in drafting responses
Facilitate relations with the CNIL, particularly during audits or complaint handling
Provide recommendations on data retention periods