GDPR Lawyer, Data Protection and Outsourced DPO in Paris

Maître Zied El Air, a lawyer at the Paris Bar, supports companies and organisations in bringing their personal data processing into compliance with the General Data Protection Regulation (GDPR), carries out outsourced DPO assignments (data protection officer) and advises on data flows between France, the European Union and Tunisia. The firm, located Place Saint-Michel in the 5th arrondissement of Paris, provides advice, operational support and assistance in the event of an inspection or dispute.

Data protection and GDPR compliance

GDPR compliance is not a one-off formality but a continuous process, documented and proportionate to the risks. The firm advises in particular on:

  • Compliance audit: review of processing operations, documents and practices against the GDPR and the French Data Protection Act (Loi Informatique et Libertés);
  • Data mapping: identification of data flows, purposes, retention periods and recipients;
  • Record of processing activities and compliance documentation (accountability);
  • Internal policies and procedures: data protection policy, procedures for managing rights and incidents, charters;
  • Information to individuals: information notices, privacy policies, cookie and consent management;
  • Contracts and processing: data protection clauses, processing agreements (Article 28 GDPR), relationships between joint controllers;
  • Privacy by design and by default: building data protection into products, services and applications from the design stage;
  • Data Protection Impact Assessments (DPIA) for processing likely to result in a high risk;
  • Management of individuals’ rights: access, rectification, erasure, restriction, objection, portability;
  • Personal data breaches: classification of the incident, notification to the supervisory authority and information to individuals where the regulations require it.

Outsourced DPO

The firm may be appointed as external data protection officer (outsourced DPO) for organisations subject to the GDPR, whether they are required to appoint one (Articles 37 to 39 GDPR) or choose a voluntary appointment. The outsourced DPO assignment includes in particular:

  • informing and advising the controller, the processor and their teams;
  • monitoring compliance with the GDPR and internal data protection rules;
  • supporting impact assessments (DPIA) and monitoring their implementation;
  • raising awareness and training staff;
  • maintaining and updating compliance documentation;
  • acting as the contact point for the competent supervisory authority;
  • supporting requests from data subjects to exercise their rights;
  • compliance governance: committees, action plans, indicators.

The DPO performs the assignment with full independence, without conflict of interest, with appropriate access to processing operations and teams. The firm provides compliance support: responsibility for complying with the GDPR remains with the controller or the processor, and the DPO does not replace them.

Outsourced DPO and data protection in France and Tunisia

The firm supports French and European companies with activities, service providers or subsidiaries in Tunisia, as well as Tunisian organisations processing data of individuals located in the European Union. Two situations must be distinguished.

Where the GDPR applies

For organisations subject to the GDPR, the firm may act as outsourced DPO, subject to the independence of the function, the absence of conflict of interest, the contractual definition of the assignment, appropriate access to processing operations and the relationship with the supervisory authority concerned. The DPO does not assume the legal responsibility of the controller.

For organisations mainly subject to Tunisian law

For organisations established in Tunisia or whose processing falls under Tunisian law, the firm may also support the setting up of data protection governance and provide, depending on the applicable legal framework, an assignment as outsourced DPO, delegate or data protection referent. This assignment may cover in particular data mapping, formalities with the INPDP, documentary compliance, management of rights, relationships with processors, international transfers and monitoring of security measures. Where the GDPR also applies to the organisation or to some of its activities, the assignment is organised in accordance with the applicable European requirements for the DPO.

Compliance of data processing in Tunisia

In Tunisia, the protection of personal data is governed by Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data, under the supervision of the National Authority for the Protection of Personal Data (INPDP). This framework provides in particular for a system of prior declaration of processing and for authorisations for certain categories of processing. The location of data in Tunisia and the existence of an international transfer are two separate questions, each requiring its own analysis.

The firm’s support may cover in particular:

  • the classification of processing operations and the identification of the controller and processors;
  • data mapping;
  • prior formalities: declarations to the INPDP and authorisation requests where required;
  • processing involving special categories of data;
  • security and confidentiality measures;
  • contracts with processors;
  • international data transfers;
  • individuals’ rights and retention periods.

For transactions relating more specifically to Tunisian data protection and cybersecurity law, see also our support in Tunisia on the website of the firm Elair & Partenaires.

Data transfers between Europe and Tunisia

Flows from the European Union to Tunisia

A transfer of personal data from the European Union to Tunisia is analysed under Chapter V of the GDPR: identification of the legal transfer mechanism (in particular the European Commission’s Standard Contractual Clauses where relevant), assessment and implementation of supplementary measures, classification of the roles of controller and processor, verification of the actual location of the data and of access from third countries.

Flows from Tunisia to other countries

Tunisian law also regulates transfers of personal data abroad, with the involvement of the INPDP. The European Standard Contractual Clauses are not, on their own, sufficient to automatically satisfy Tunisian formalities: the two frameworks must be dealt with in a coordinated manner.

Data protection and cybersecurity compliance

The firm acts as a lawyer on the legal obligations and governance of cybersecurity, in coordination with the competent technical providers. It is not a technical cybersecurity provider. Areas of support include in particular:

  • legal governance of cybersecurity and analysis of the applicable regulatory obligations;
  • cybersecurity clauses in contracts, in particular cloud, SaaS and hosting contracts;
  • internal policies and the organisation of incident management;
  • contractual responsibilities and relationships between controller and processor;
  • personal data security obligations (Article 32 GDPR) and coordination between data protection and cybersecurity;
  • legal support for incidents and notification to the authorities where the regulations require it;
  • legal support for technical audits carried out by the competent professionals.

Cybersecurity compliance for companies in Tunisia

In Tunisia, Decree-Law No. 2023-17 of 11 March 2023 on cybersecurity and the National Cybersecurity Agency (ANCS) form the reference framework. For organisations falling within the scope of the relevant provisions, the firm can provide legal support on:

  • determining whether the organisation belongs to a category subject to the specific obligations of the Decree-Law;
  • analysing the obligations applicable to its information system and those relating to periodic audits;
  • the legal organisation of cybersecurity governance and follow-up of auditors’ recommendations;
  • the contractual framework for relationships with cybersecurity providers, SaaS and cloud suppliers and hosting providers;
  • preparing incident management procedures and verifying reporting obligations;
  • coordination between data protection and information systems security.

The specific obligations of this framework do not apply indiscriminately to all companies: a prior analysis of the scope of application is necessary.

Data protection and cybersecurity: two related but distinct disciplines

Personal data protection concerns purposes, lawfulness, information to individuals, their rights, retention, processing by service providers and transfers. Cybersecurity concerns access, confidentiality, integrity, availability, logging, backups, incident management and the resilience of systems. Both the GDPR and Tunisian data protection law contain obligations relating to the security of processing, but cybersecurity is not merely a subdivision of data protection: the firm’s support combines the two approaches.

Inspections, data breaches and disputes

  • Data breach response plan: organising the response to a security incident involving personal data, notification to the competent authority (CNIL in France, INPDP in Tunisia) and information to the individuals concerned where the regulations require it;
  • Support during inspections by the CNIL or the INPDP: preparation, replies to requests and to orders to comply, corrective action plans;
  • Defence in the event of a sanction: representation in proceedings relating to breaches of the GDPR or Tunisian data protection legislation;
  • Awareness and training of teams on regulatory obligations and good practice, adapted to the Franco-Tunisian context;
  • Regulated sectors (health, finance, e-commerce): taking into account the sector-specific regulations applicable in France and Tunisia.

The firm also advises on digital law and new technologies (IT contracts, SaaS, cloud, e-commerce) and intellectual property. For any question about GDPR compliance, the appointment of an outsourced DPO or data transfers between France and Tunisia, contact the firm.