Lexagone: your tailor-made GDPR and AI consulting firm

How to ensure your GDPR compliance?

Lexagone, a consulting firm in personal data protection, is composed of experienced and senior lawyers, GDPR experts working as a team to guarantee you the best expertise and efficiency for your operational needs.

Your GDPR support is provided by a proven organization with our centers of expertise, our own software for maintaining processing records and GDPR governance.

“Thanks to their organization, their availability and their pedagogy, Lexagone consultants were able to successfully carry out all the missions entrusted to them, including the most complex ones such as the DPIA. I recommend them for your GDPR "projects". They will be able to adapt to your requirements while remaining compliant.”

DSI of a Hospital Center
travailler ensemble

Data protection consultancy provides support for GDPR compliance

Lexagone is a RGPD compliance consultancy on a human scale, convinced that data protection is essential to guarantee the security of your business and the confidence of your customers. This is why Lexagone's leitmotivs are ethics, expertise and pragmatism. Our DPO (Data Protection Officer) consultancy offers RGPD support tailored to your needs.

GDPR compliance audit

GDPR compliance audits allow you to create a register of processing activities or consolidate it if it has already been set up by your data protection officer.

Maturity audit

Maturity audits integrate the 8 typical activities defined by the CNIL. The maturity audit helps you study your issues in order to benefit from the best action plan specific to your organization.

Crisis management exercises

Lexagone also offers crisis management exercises to better protect your organization against cyberattacks and strengthen its cybersecurity.

External DPO

As a GDPR consulting firm, you can appoint Lexagone as your organization's external DPO with the CNIL. A team of Lexagone GDPR consultants then guarantees your GDPR compliance and your GDPR support.

Data Protection Impact Assessments

Our GDPR experts carry out your DPIA (Data Privacy Impact Assessment) for data processing that presents high risks for the data subjects (CCTV, processing integrating AI, etc.)

Lexagone is also a GDPR consulting firm specializing in health

At Lexagone we also have GDPR support from an outsourced Data Protection Officer for health and medico-social establishments, as well as strong expertise for DPIA of EHR.

External DPO Health

Our GDPR compliance consultancy firm has been renewed by the CAIH as the holder of the AMOA SSIDP contract – Project management assistance services related to information systems security and data protection for the period 2024-2028.

External EMS DPO

Major foundations and associations in the medical-social sector have entrusted their governance in terms of personal data protection to Lexagone.

Why entrust your compliance to Lexagone’s GDPR experts?

An experienced data protection consultancy firm

At Lexagone, our team of lawyers is made up of experienced (over 5 years) and senior (over 10 years) profiles who contribute to enriching our proven know-how for over 18 years.

01

GDPR compliance advice tailored to your needs

Whether you are a small business or a large group, a healthcare facility or an EMS, our GDPR experts adapt their data protection support to your organizational, technical and legal constraints.

Our GDPR compliance consulting approach is designed to minimize the operational impacts on your businesses while optimizing the implementation of best practices.

02

A pragmatic strategy with a collaborative solution

Beyond mapping your treatments, diagnosing and analyzing your registry in our DPM solution, our data protection consulting firm optimizes your processes related to the processing of personal data to make them a real lever for performance.

03

gestion de crise cyber min

Lexagone in a few words

Founded in 2007, Lexagone is a GDPR compliance consulting firm with our own software for maintaining the register of processing activities that allows us to centralize documentation (accountability) and the actions of our GDPR experts as part of our outsourced DPO missions.

Experts in their field, our GDPR consultants are both versatile and specialized in different areas of law (health, medico-social, local authorities, human resources, etc.).

Lexagone, as a GDPR consulting firm, has been selected as an exclusive partner by the ambassadors of Club Décision DSI: the leading independent French DSI Club dedicated to IT decision-makers.

The Lexagone team is also proud of its listing by several regional CSIRTs as a data protection consulting firm capable of intervening in incident responses requiring notification of a data breach to the supervisory authority (CNIL).

18
years of expertise
800
customer references
500
External DPO designations
98
customer satisfaction

OUR REFERENCES

Customer testimonials: our approach to external Group DPO missions is adapted to your organization

As DPO Group of La Redoute I selected Lexagone to lead my network of DPO relays within all European subsidiaries.
This choice was motivated by the consultants' experience in setting up and monitoring GDPR governance, particularly in terms of organization and reporting to management.
For several years, I had the pleasure of being supported by a team that was available, educational and bilingual, which facilitated the transnational management of the group's compliance.

Philippe HuyonDPO Group La Redoute

The work done with our DPO is transparent, fluid and professional. I appreciate the active listening and availability of the team who knows how to give us valuable advice while offering an expert vision in data protection practices.
Personally, it is always a pleasure to talk with Morgane and Julie.

GHT Ile de France SouthInformation System Management Department

La Mutuelle du Rempart and Cybèle Solidarité have chosen the Lexagone firm to carry out the external DPO mission.
With expertise and responsiveness, the Lexagone team supports us on a daily basis in our GDPR compliance efforts and in the implementation of our projects for our members.

Jean-Pierre PAILHOLGeneral Manager of the Mutuelle du Rempart

The Lexagone firm was able to offer the MFRs (430 Rural Family Homes), which cover 18 business sectors, a “tailor-made” offer adapted to our organization as a federation, at a time when the GDPR was being implemented and in the face of the concern generated by this change.

Christophe BERNARDCommunications Manager, National Union of MFRs

Frequently Asked Questions

The Register of processing activities: the DPO’s governance tool

The Data Protection Officer: meaning and issues

Data processing subject to DPIA

Article 35 of the GDPR provides that when processing is likely to generate a high risk for the rights and freedoms of natural persons, the data controller shall, before processing, carry out an analysis of the impact of the processing operations envisaged on the protection of personal data.

On the basis of this principle, the CNIL has established the list of processing operations for which it is mandatory to carry out a DPIA:

“Patient” files of a university hospital, hospital, clinic, etc.).
“Resident” files of a CCAS or EPHAD.
Medical decision taken by an algorithm (AI).
HR management of “high potentials”.
Recruitment with a selection algorithm.
So-called Data Loss Prevention devices.
Video surveillance of a warehouse.
Professional alert system.
Fight against money laundering and the financing of terrorism (LCB-FT).
Processing aimed at personalizing online advertising.
Mobile application for collecting users’ geolocation data.

Complete list of CNIL processing operations subject to DPIA.

GDPR & AI Governance: a sustainable and ethical approach

Let's talk about your compliance


Contact Information

Mail : contact@lexagone.fr
Phone : +33 (0)972 169 310

Lexagone is present at:

  • Biarritz
  • Bordeaux
  • Grenoble
  • Lille
  • Lyon
  • Marseille
  • Montpellier
  • Nantes
  • Paris
  • Toulon
lexagone logo

Our GDPR consulting firm offers external DPO services managed by teams of specialized legal experts to ensure controlled GDPR governance.

Member of

afcdp min
logo apssis h100 min
club decision dsi min

Referenced by

logo caih 400 copie 0 0 1 min
53a58cfd 2d9c 4a08 84ac f80456cd147b
logo csirt blue
logo footer@2x