Key contacts

Oyat avocats - Charlotte Barraco-David
Charlotte Barraco-David
Counsel
Oyat avocats - Marie-Hélène Tonnellier
Marie-Hélène Tonnelier
Partner
Practice

Data: Personal and public – cybersecurity

In a world where digital data plays a central role, its protection and compliant management have become essential for businesses, which are increasingly confronted with economic, ethical, and security challenges

Data permeates our daily lives, whether collected openly or through complex processes. In response, French and European regulations aim to protect citizens. Data management and cybersecurity have become critical challenges for businesses, often seen as tools for differentiation.

Whether personal or public, data are highly valuable strategic assets for public entities, businesses, and individuals. Their governance, though complex, presents economic, ethical, and security challenges. With the rise of cyber threats, citizens and consumers demand stronger protection for their information and complete transparency regarding its use.

At Oyat, we assist our clients in defining compliant and secure strategies that integrate both data management and cybersecurity law. Our lawyers stay informed on legislative changes and emerging practices to ensure the compliance of data processing activities, whether handling standard personal data or sensitive information such as health data.

Our team works closely with Data Protection Officers (DPOs) and cybersecurity leaders to secure systems, build stakeholder trust, and mitigate legal and operational risks related to cyberattacks. We turn data protection into a competitive advantage and a source of peace of mind in an increasingly complex digital landscape.

TYPES OF INTERVENTIONS
CYBERCRIME MATTERS AND IT SECURITY INCIDENTS
  • Drafting and filing complaints related to cybercrime (such as attacks on critical IT infrastructure, criminal offenses involving personal data processing, etc.)
  • Coordinating with relevant law enforcement agencies (BL2C, SDLC, etc.)
  • Reporting personal data breaches and security incidents to regulatory authorities (CNIL, ANSSI, etc.)
  • Managing communications and relationships with authorities
  • Drafting incident response policies
  • Conducting awareness programs and training for our clients’ teams
DATA INTERMEDIATION
  • Legal support for setting up data marketplaces, data hubs and data exchange platforms in compliance with applicable regulations (DGA, DA, RGPD, …)
  • Drafting of legal conditions for data use
  • Implementation of data governance policies for intermediation platforms
GDPR COMPLIANCE
  • Legal assistance in drafting and preparing Data Protection Impact Assessments (DPIAs), ensuring compliance with Privacy by Design principles during development, and proactively managing risks related to processing activities in support of DPOs
  • Support in implementing GDPR compliance programs and audits, ensuring adherence to legal obligations and securing personal data processing activities
  • Cross-functional support in implementing artificial intelligence systems utilizing personal data
  • Assistance in drafting documentation (privacy policies, cookie policies, processing activity registers, etc.)
DATA TRANSFER OUTSIDE THE EU
  • Assistance with the legal analysis of complex situations involving the transfer of personal data outside the European Economic Area (EEA)
  • Guidance in selecting and adapting standard contractual clauses to specific circumstances
  • Support in preparing binding corporate rules (BCR) files
MANAGEMENT OF SENSITIVE DATA
  • Assistance in establishing healthcare data frameworks for the processing of health data (health data warehouses, reference frameworks, standard methodologies, etc.)
  • Support in implementing sensitive data processing activities

“Oyat offers innovative solutions to complex problems thanks to an experienced and committed team that has developed extensive expertise in a wide range of activities. The firm has the ability to develop and propose successful legal strategies while tackling complex challenges. The firm’s flexibility and expertise, as well as its professionalism and customer-oriented approach, are outstanding and lead to genuine customer satisfaction. The team’s continual learning, growth and development ensure that the firm will continue to provide quality legal services.”

RANKINGS & AWARDS
LEADERS LEAGUE
  • Leaders League – Personal data (excellent)
BEST LAWYERS

Personal data

WHO'S WHO LEGAL

Personal data