Protecting your creations and your data
GDPR and outsourced DPO
GDPR compliance, audits, outsourced DPO and technology contracts.

Are you affected, and in what capacity?
The GDPR (Regulation (EU) 2016/679, applicable since 25 May 2018) has no headcount threshold. As soon as an organisation processes the data of people located in the Union — customers, prospects, employees, job applicants — it applies. What varies from one business to another is not whether it applies: it is how heavy the obligations are.
In practice, we are called about one of these six triggers:
- a compliance questionnaire sent by a large customer or a public body before signing;
- due diligence on a fundraising round or a sale, where the data chapter has become an audit item in its own right;
- a subject access request (art. 15 GDPR) from an employee or a former employee, which has to be answered within one month (art. 12(3));
- a personal data breach to be notified to the CNIL, the French data protection authority, within 72 hours (art. 33);
- a letter from the CNIL, a documentary investigation or a complaint passed on;
- the launch of a product or a change of tool: a new website, a new CRM, a new SaaS component.
None of those six moments leaves time to build compliance from scratch. That is precisely why the audit is done beforehand.
The three cases where appointing a DPO is compulsory
Article 37(1) of the GDPR lists three situations, and only three:
- the processing is carried out by a public authority or body;
- the core activities consist of regular and systematic monitoring on a large scale of data subjects;
- the core activities consist of processing on a large scale of special categories of data (art. 9 — health, opinions, biometric data, and so on) or of data relating to criminal convictions (art. 10).
The text defines neither “core activities” nor “large scale”. The Article 29 Working Party guidelines on data protection officers (WP 243 rev. 01, adopted on 13 December 2016, revised on 5 April 2017 and endorsed by the European Data Protection Board) give the criteria for reading them: the number of data subjects, the volume of data, the duration, the geographical extent. That is where the classification is decided, and it is rarely obvious: a SaaS publisher with twenty employees may fall within it where an industrial company with two hundred does not.
Outside those three cases, appointing a DPO is voluntary — but it is not free of consequence: a voluntarily appointed DPO is subject to exactly the same regime as a compulsory one (arts. 38 and 39).
Controller or processor: the question that changes everything
Article 4(7) defines the controller as the one who determines the purposes and means; article 4(8) defines the processor as the one who processes on behalf of the controller. A software publisher, an agency, a hosting provider are in principle processors — but the classification follows from the facts, not from the heading on the contract, and one and the same company almost always wears both hats.
The consequences are not symmetrical:
- the record of processing under article 30 takes two distinct forms depending on the hat (paragraph 1 for the controller, paragraph 2 for the processor);
- the processing agreement under article 28(3) contains mandatory provisions whose absence is itself a breach;
- in the event of a breach, the processor notifies the controller (art. 33(2)), not the CNIL.
A word about the derogation in article 30(5), which is often relied on: it covers organisations with fewer than 250 employees, but falls away as soon as the processing is not occasional, poses a risk to people's rights, or concerns special categories of data. A payroll and a customer database are enough to defeat it. In practice, almost nobody benefits from it.
These two classifications govern everything else in the file. They are the first thing we establish, before we even look at your tools — and if you are unsure which is yours, a first conversation to classify your situation is usually enough to settle it. This page is part of our full range of areas of practice in business law.
What we do in data protection
GDPR compliance audit and compliance plan
We record the gap between what you do and what the Regulation requires, then turn it into a dated and prioritised plan. The detail of the scope and of the deliverables is set out below.
Outsourced DPO and long-term monitoring
We act as your data protection officer, under a service contract. Duties, rhythm and the mechanics of appointment: again, see below.
Record of processing, policies and privacy notices
The record of processing under article 30 is not a table to be filled in once: it is the document the CNIL asks for first during an investigation, and the one that has to reflect your actual processing on the day of that investigation. We build it with your operational teams, then we draft what follows from it — the privacy notices required by articles 13 and 14, the privacy policy, the retention policy, the procedure for handling requests from data subjects, the breach notification procedure. We also train the people who will have to use it: a record that nobody knows how to update is out of date within six months.
Technology contracts: processing, hosting, SaaS
Every supplier that touches your data calls for a processing agreement that complies with article 28(3). Where the servers or the support team are outside the Union, the safeguards in Chapter V are added — the Commission's standard contractual clauses and a transfer impact assessment. We audit your existing supplier contracts, we draft the ones you impose on your own customers, and we negotiate the schedules that the large publishers present as non-negotiable — they are so more often than people think. This work joins up with what we do on your terms and conditions and your services agreements, and, for the software asset itself, on protecting your code and your databases.
GDPR audit and outsourced DPO
The GDPR compliance audit: scope, duration, deliverables
No rule requires an audit. What the Regulation does require is article 5(2): you must be able to demonstrate your compliance. The audit is the shortest way of getting there — and the only one that produces dated evidence if the CNIL asks you questions.
Our audit covers eight blocks: the mapping of processing activities, the legal basis for each one (art. 6), retention periods, information given to data subjects (arts. 13 and 14), the exercise of rights (arts. 15 to 22), security (art. 32), the processing chain (art. 28) and transfers outside the Union (Chapter V). To that is added a review of the website: trackers and consent fall under article 82 of the French Data Protection Act (the loi Informatique et Libertés), which is distinct from the GDPR and is often the most visible point from the outside.
It runs in three stages: interviews with the operational leads — sales, HR, IT, marketing — a documentary and technical review, then the report-back. You come away with the record of processing filled in, the list of gaps ranked by risk rather than alphabetically, the dated action plan with an owner for each action, and the model documents to roll out.
The outsourced DPO: duties, rhythm, appointment
Article 37(6) expressly provides for it: the officer may be a member of staff orfulfil the tasks “on the basis of a service contract”. Outsourcing is therefore not a tolerated arrangement, it is a route written into the text.
The officer's duties are set by article 39: to inform and advise, to monitor compliance with the Regulation, to give advice on the data protection impact assessment (art. 35), to cooperate with the CNIL and to act as the point of contact. Article 38(3) protects that role: the officer receives no instructions regarding those tasks, cannot be penalised for performing them, and reports to the highest management level.
In concrete terms, the engagement takes the form of a recurring meeting, a watch on the decisions of the CNIL and of the European Data Protection Board, the handling of requests from data subjects as they come in, the running of impact assessments where a new processing activity calls for one, and an availability that proves its worth on the day an incident starts the 72-hour clock. Once appointed, the officer must be published and communicated to the CNIL (art. 37(7)).
Why a lawyer rather than a consultant
Two reasons, both legal and both verifiable.
Professional secrecy. Advice given by a lawyer to a client, and the correspondence exchanged with that client, are covered by article 66-5 of Act no. 71-1130 of 31 December 1971, breach of which is punishable under article 226-13 of the French Criminal Code. An audit report setting out your non-compliances in black and white is, in the hands of a consultant, a document like any other: disclosable, seizable, capable of being passed on. That is a difference in kind, not in degree — and it weighs at the exact moment the document becomes sensitive.
The absence of a conflict of interest.Article 38(6) prohibits the officer's other tasks from giving rise to a conflict of interest. The Court of Justice of the European Union spelled this out in its judgment of 9 February 2023 (X-FAB Dresden, C-453/21): the officer cannot be given duties that would lead them to determine the purposes and means of the processing. An internal DPO who is also the IT director, the general counsel or a company director is structurally exposed to that criticism. A lawyer outside the organisation chart is not — and that lawyer checks for conflicts before accepting the engagement in any event, article 4 of the profession's Règlement Intérieur National, the national rules of the French Bar, already requiring it.
How we work
Here we follow the four steps we follow on every file, applied to data protection.
- We listen to your situation. A first conversation, at the office or by video call, to establish your classifications — controller, processor, or both — and the real origin of the request: a customer, an investor, the CNIL, or an internal decision.
- We build a strategy that fits. You receive a written proposal: the scope of the audit, the options, the timescale, the agreed amount. Nothing starts without your agreement.
- We handle the file. Audit, record of processing, documentation, processing agreements, impact assessments, or acting as the data protection officer: your contact stays the same from start to finish.
- We stay available. Compliance has no end point: a new tool, a new country, a new offer reopens the file. That is what the outsourced DPO engagement covers on a continuous basis.
Our fees: a fixed fee for the audit, a retainer for the DPO
Our fees follow the three formats used by the firm, set out in detail with the amounts of our fixed fees and of our fee schedule: the monthly retainer for continuous support — that is the format used for the data protection officer engagement, whose workload is regular by nature; the fixed fee per assignment for the GDPR audit, whose scope can be defined before starting; the detailed fee agreement for litigation or enforcement proceedings before the CNIL.
The amount is stated and accepted before the work begins. That is a commitment from the firm, not a turn of phrase: you never discover the cost of a piece of work after the event.
Why Pujol Avocats on technology matters
The firm has described itself as a digital business law firm since long before compliance became a boardroom subject, and technology law is one of its long-standing areas of practice.
- The background.Me Jérôme Pujol was admitted to the Bar in 2000. ESSEC master's degree, a spell with Gide Loyrette Nouel in Bucharest, partner of the firm.
- Three offices.Paris, Perpignan and Barcelona — the last on registration on Liste E with the city's Bar.
- The startup ecosystem. Patron of the UPVD iN CUBE incubator, present at the Mobile World Congress in 2021: businesses whose product is the processing of data are not unfamiliar to us.
- Openness about fees, practised publicly by the firm for years — which is rare in the profession, and which can be checked.
One last point, which we prefer to make ourselves: this site records where your visits come from — campaign parameters, click identifiers, referrer — in order to know which communication activities work. That measurement does not fall within the consent exemptions provided for by article 82 of the French Data Protection Act. It is described in our own privacy policy. We rarely advise a business on a subject we do not apply to ourselves.
GDPR lawyer in Paris, Perpignan and Barcelona
The GDPR is a regulation: it applies in the same terms everywhere in the Union, and the French authority is national. Where the office is therefore changes nothing about the applicable law — it changes everything else: the ability to run interviews with operational teams on site, and the regular presence a data protection officer is expected to have.
From our office in the 7th arrondissement, we act for software publishers, groups and investors, for whom the data chapter most often arrives through due diligence or through a customer's questionnaire.
In Perpignan, the demand comes rather from the small, medium-sized and mid-cap businesses of Roussillon appointing their first officer, often after a contract with a large customer or a public body that requires it.
Our Catalan office handles French-Spanish flows. For a group established on both sides of the border, article 56 of the GDPR designates a lead supervisory authority according to the location of the main establishment: the one-stop-shop mechanism decides whether your counterpart is the CNIL or the Spanish AEPD. That question is settled when the structure is set up, not at the time of an investigation.
Frequent questions
No, no rule requires an audit to be carried out. Article 5(2) of the GDPR does, however, require you to be able to demonstrate your compliance, and article 24 to be able to prove it at any time. The audit is the most direct way of building that evidence. Some obligations are genuinely imposed: the record of processing activities (art. 30) and the impact assessment where the processing presents a high risk (art. 35).
In three stages. First, interviews with the sales, HR, IT and marketing leads, to record the processing that actually happens — not the processing the procedures describe. Then a documentary and technical review: processing agreements, privacy notices, website trackers, security measures. Finally the report-back, which gives you the completed record of processing, the gaps ranked by risk and a dated action plan.
The audit is billed as a fixed fee, set after a first conversation that defines the scope: the number of processing activities, the number of sites, whether or not there are transfers outside the Union. The amount is stated to you in writing and accepted before the work begins. The data protection officer engagement, whose workload is recurring, falls instead under the monthly retainer.
Article 37(6) allows both. The decisive test is not cost but conflict of interest: article 38(6) prohibits the officer's other duties from leading them to determine the purposes and means of the processing, which the Court of Justice confirmed on 9 February 2023 (X-FAB Dresden, C-453/21). Appointing your IT director or your company director therefore exposes you to a structural criticism. An external officer avoids that difficulty, and replacing them does not depend on someone leaving the company.
Yes. Article 37(7) requires the officer's contact details to be published and communicated to the supervisory authority: in France, the appointment is made online with the CNIL, the French data protection authority. A voluntarily appointed officer is declared in the same way and is then subject to the same regime as a compulsory one.
You are a controller where you determine the purposes and means (art. 4(7)), and a processor where you process on behalf of someone else (art. 4(8)). Most companies are both at once: controller for their payroll and their customer database, processor for the data their customers entrust to them. The classification follows from the facts, not from the heading on the contract, and it determines both the form of your record of processing and your obligations in the event of a breach.
First conversation
Tell us your situation and we will tell you what is possible
At our offices in Paris, Perpignan, Barcelona, or by video call.



