GDPR and data protection lawyer
Every company processes personal data: that of its customers, employees, prospects and suppliers. The General Data Protection Regulation (GDPR) and the French Data Protection Act strictly govern these processing operations, under the supervision of the CNIL (French data protection authority), whose fines can reach 20 million euros or 4% of worldwide turnover.

MOSAIK assists companies of all sizes with their compliance and defends them in the event of an investigation or litigation. Our approach is pragmatic: useful compliance, proportionate to your actual processing operations and embedded in your business processes.
Auditing your processing operations and bringing them into compliance
The process starts with a full assessment. MOSAIK delivers:
- the mapping of your data processing operations and their purposes;
- the creation and maintenance of the record of processing activities;
- the identification of the legal basis for each processing operation;
- the definition of retention periods and deletion procedures;
- the drafting of privacy notices and the collection of consent;
- procedures for handling data subject rights: access, rectification, erasure, objection, portability.
Your contracts and your documentation
Compliance runs through contracts. The firm drafts and negotiates the documents that govern the flow of data:
- privacy and cookie policies;
- data processing agreements and processor clauses;
- joint controllership agreements;
- IT charters and the framework for employee data;
- standard contractual clauses for data transfers outside the European Union.
This last point is a particular strength of the firm: with offices in Paris, Hong Kong and Mexico City, MOSAIK has deep experience of international data transfers, an unavoidable issue for groups operating outside Europe.
Governance: DPO, impact assessments, privacy by design
MOSAIK advises your data protection officer or acts as outsourced DPO where your activity justifies it. The firm carries out data protection impact assessments (DPIAs) for high-risk processing and builds data protection into your projects from the design stage: a new website, a new application, a new HR or sales tool.
Data breaches: reacting within 72 hours
A leak, a hack, a lost device, an email sent in error: a data breach requires swift action. Notification to the CNIL must be made within 72 hours, and the individuals concerned must sometimes be informed. MOSAIK assists you under time pressure: classifying the incident, notification, communications, remediation plan, and handling any ensuing litigation.
CNIL investigations and litigation
In the event of an on-site, documentary or online investigation, the firm prepares and assists your teams, responds to the CNIL's requests and defends you throughout the sanction procedure, including before the Conseil d'Etat (French supreme administrative court). MOSAIK also acts in compensation claims brought by data subjects.
Specific situations we know well
- employee data: recruitment, video surveillance, geolocation, activity monitoring, in conjunction with our employment law team;
- direct marketing, in B2B and B2C alike, and the compliance of prospect databases;
- e-commerce websites and their trackers (see our e-commerce page);
- artificial intelligence projects and how the GDPR interacts with the new European regulations;
- compliance audits carried out for a fundraising round or an acquisition, where data protection has become a mandatory checkpoint.
Frequently asked questions
Does the GDPR also apply to small businesses?
Yes. The GDPR applies from the very first processing of personal data, whatever the size of the company. Obligations are proportionate, however: a very small business does not face the same constraints as a platform processing millions of accounts.
Am I required to appoint a DPO?
Appointment is mandatory only in certain cases: public authorities, regular and systematic large-scale monitoring, or large-scale processing of sensitive data. Outside these cases, it often remains advisable: an outsourced DPO is then a flexible solution.
What should I do if the CNIL opens an investigation?
Do not improvise. Contact your counsel immediately: the first responses shape the entire procedure. MOSAIK assists its clients from the letter announcing the investigation through to the closing of the file.
Is GDPR compliance a one-off project?
No. Compliance must be maintained: new processing operations, new tools, new providers, changes in the regulations and in the CNIL's doctrine. MOSAIK offers ongoing support to keep your documentation up to date.
Would you like to
contact us?