Blog
News, expert advice, best practices... It's all here! Explore our blog to decipher the key issues in personal data protection and keep abreast of the latest developments.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

GDPR compliance KPIs: the DPO reporting guide
GDPR compliance KPIs allow the DPO to demonstrate the effectiveness of their measures and engage with management using numbers rather than legal jargon. About fifteen indicators are sufficient, divided into four categories: maturity (registry completion, DPIA execution), risk and security (volume of breaches, notification time), operational and awareness (trained employees, response time for data subject requests), and efficiency (project validation time, vendor compliance). The dashboard must then be tailored to each stakeholder: a macro view for the Executive Committee, technical granularity for the CISO. An imperative driven by the accountability principle of Article 5.2 of the GDPR.

GDPR compliance and best practices
Compliance risk mapping: the DPO's guide
Compliance risk mapping involves identifying company data processing activities, evaluating each threat scenario by cross-referencing its severity and probability, and then prioritizing corrective actions based on their criticality. Inspired by risk management standards such as ISO/IEC 27005, the process relies on the record of processing activities, is materialized in a three-level GDPR risk matrix, and leads to a remediation plan aimed at achieving a tolerable residual risk. It allows you to move from reactive compliance to strategic management, justify budgets to the Executive Committee, and demonstrate your accountability to the CNIL. With the AI Act, it must now also incorporate algorithmic risks.
Articles

GDPR compliance and best practices
Synthetic data: the GDPR and AI Act compliance guide
Synthetic data consists of artificial datasets generated by algorithms that mimic the statistical properties of real data without being derived from it. While they allow for training AI models and testing without using real data, they are not automatically exempt from GDPR. In its guidelines dated July 7, 2026, the EDPB established three cumulative criteria—individualization, correlation, and inference—that a dataset must meet in its entirety to be classified as anonymous. It also strictly regulates web scraping used to train generative models. Here is a breakdown of the rules and a compliance checklist for DPOs.
Articles

GDPR compliance and best practices
CNIL inspection: anticipate, manage, and prove your daily compliance?
A CNIL inspection is not inevitable: the heaviest penalties affect companies unable to document their governance, not those that have made an isolated error. This guide details the four types of inspections, the triggering factors, the two major points of vigilance for inspectors (data breach notification within 72 hours, management of data retention periods), as well as the method for structuring your defense through a GDPR compliance audit and aligned AI Act governance. You will also find the 5 documents to produce in less than 30 minutes in case of an on-site inspection and the details of the GDPR penalties incurred.
Articles

News
Compliance updates june 2026: AI Act, court of auditors, and a shake-up in telemarketing
June 2026 marks a regulatory turning point for DPOs and legal professionals: the Court of Auditors delivers an uncompromising assessment of the CNIL, while the law of June 30, 2025, mandates a shift to strict opt-in for B2C cold calling from August 11, 2026. On the artificial intelligence front, the AI Office is finalizing its Codes of Conduct for GPAI model providers, with direct implications for auditing your AI subcontractors. Finally, the G7 Privacy meeting in Paris and Microsoft France's admission regarding the Cloud Act reignite the debate on digital sovereignty. Here's what you need to know to manage your GDPR and AI Act compliance this month.
Actualités

GDPR compliance and best practices
Recruitment and GDPR: safeguarding your decisions against CNIL inspections
Recruitment is among the CNIL's top inspection priorities. From automated screening and social media sourcing to CV retention, every step involves your responsibility. Retention limited to two years in an active database then five years in an archive, mandatory human oversight for AI decisions, informing candidates: these are the practical rules to secure your recruitment processes without hindering your sourcing efforts.
Articles

GDPR compliance and best practices
GDPR dashboard: essential KPIs for the executive committee
GDPR compliance is no longer a one-off project but a continuous and strategic process. For the DPO, Legal Director, or CISO, the GDPR dashboard becomes the central tool for centralizing, measuring, and managing this compliance daily. It helps identify bottlenecks, allocate resources where the risk is critical, and translate technical indicators into business value for the Executive Committee. This article details the essential KPIs (operational monitoring and risk management), the reporting method for the Executive Committee, and the upcoming convergence between GDPR and the AI Act.
Articles

GDPR compliance and best practices
Health data: what the CNIL's new MR-001 and MR-003 methodologies require
The CNIL is overhauling its reference methodologies MR-001 and MR-003, which govern health data research. This is a paradigm shift: moving from administrative compliance to verifiable operational security on the ground. For healthcare, biotech, and insurance stakeholders, this means mandatory automated data purges, multi-factor authentication to be deployed before January 1, 2027, then 2028, restructured frameworks with two binding appendices, and European alignment. The changes apply immediately to new research, with a one-year transition period for ongoing processing.
Articles

News
Software supply chain security: what NIS 2 and DORA now require
In mid-May 2026, automated attacks against GitHub, PyPI, RubyGems, and software vendor Instructure revealed a systemic flaw: an organization's security no longer depends on its perimeter, but on the integrity of its entire software supply chain. For CISOs, CIOs, and DPOs, contractual validation of suppliers has become obsolete. NIS 2 and DORA now mandate absolute technical traceability (continuous component inventories, dependency control, Zero Trust applied to development), which also serves to document Article 32 of the GDPR.
Articles

GDPR compliance and best practices
GDPR, DORA, NIS 2, and the AI Act: how to unify your European compliance
GDPR, DORA, NIS 2, AI Act: Faced with the accumulation of European regulations, many organizations prioritize one project at the expense of others. This is a strategic mistake. These texts actually share a common denominator: risk management. By meeting the requirements of one, you lay the groundwork for the others. Here's how to build unified governance, reduce redundancies, and turn multi-regulatory compliance into a performance driver rather than a source of exhaustion.
Articles
GDPR compliance and best practices
Tracking pixel regulation and GDPR: consent, trackers, and email compliance in 2026
Since spring 2026, CNIL has officially classified a user's inbox as a "terminal": any tracking pixel embedded in an email now requires prior and informed consent. This decision, based on Article 82 of the French Data Protection Act and the GDPR, compels companies to thoroughly review their collection of behavioral data. Pixel regulation, predictive AI, digital sovereignty, transactional emails: here's what this regulatory shift concretely changes for your organization — and the actions to take before the end of the grace period in summer 2026.
Articles

News
Compliance news may 2026: GDPR, cybersecurity, and resilience against cyber threats
May 2026 compliance news confirms a shift towards an active defense posture. On the agenda: the CNIL's annual report and the update of its health reference methodologies (deadline May 23, 2026), a wave of attacks targeting the software supply chain (GitHub, PyPI, RubyGems, Instructure/Canvas), the operational alignment between NIS 2, DORA, and Article 32 of the GDPR, and an international CNIL initiative for the protection of minors' data. A look at the concrete impacts for DPOs, CIOs, and CISOs.
Articles

Product
Adequacy 6.3 release notes: oroject module, AI governance, and media library
Adequacy 6.3 introduces three major advancements: a Project module to manage Privacy by Design, an AI governance module to track and secure decisions related to AI use cases, and a media library restructured by folders and collections. This version also enhances the public register, the Incidents and Breach module, and overall ergonomics.
Articles

GDPR compliance and best practices
Leading the network of GDPR and AI Act compliance officers: new challenges and key skills
The AI Act doesn't replace GDPR: it amplifies it. For the DPO, the challenge isn't to change roles, but to adapt their network of referents to a more complex reality. Shadow AI detection, skill hybridization, shared management tools, strengthened legitimacy with business units: here's how to transform this human network into a true strategic asset for compliance.
Articles

News
DPO and AI Act: what role under CNIL supervision?
As of 2026, CNIL is officially the supervisory authority for the AI Act in France. This decision repositions the DPO at the heart of AI governance: a strategic point of contact on executive committees, guarantor of the dual GDPR and AI Act framework, but often without additional resources. Caught between increased visibility and an overloaded scope, here's how DPOs can organize themselves, protect themselves legally, and gain influence without burning out.
Actualités

GDPR compliance and best practices
The digital afterlife: who protects the data of fetuses and the deceased?
The GDPR protects natural persons. But what happens to the data of those who are not yet — or are no longer — considered such? From prenatal genomic sequencing linked to the mother's medical record to medical data that continues to circulate after death, digital law reveals its blind spots. Recent leaks from UNSS and Cegedim Santé have highlighted the urgency of these issues. This is an overview of a grey area where ethics and GDPR compliance clash.
Articles

GDPR compliance and best practices
The ethics of connected health: between the promise of care and digital alienation
Connected health promises unprecedented prevention — but at what cost? By translating our bodies into data, connected devices and health algorithms raise fundamental ethical questions: truly free consent, the reduction of the individual to their biological constants, the risk of social division, and algorithmic bias. This article explores the tension between technological promise and respect for human dignity, at a time when the GDPR and the AI Act are redefining the rules of the game.
Articles

News
The Criteo shockwave: what's concretely changing for AdTech in 2026
The €40 million fine imposed on Criteo by the CNIL — confirmed by the Conseil d'État — sent a clear signal to the entire AdTech ecosystem: the grey areas are over. Pseudonymous data, consent responsibility, the right to be forgotten, Retail Media… this article breaks down what concretely changes for startups and scaleups operating in digital advertising, and the priority projects to undertake immediately.
Articles

GDPR compliance and best practices
Anonymization vs. pseudonymization: the implications of the CJEU's relative approach
Since the CJEU ruling of September 4, 2025, data can change its legal nature depending on the means actually available to re-identify it. This so-called "relative" approach redefines the boundary between anonymization and pseudonymization — with direct implications for GDPR compliance strategies, the health, research, and AI Act sectors. An overview of the technical, legal, and ethical challenges, and the precautions to take within a still-evolving legislative framework.
Articles

News
GDPR & AI Act updates: key takeaways from April 2026
April 2026 marks a busy month for compliance: the EDPB launches a coordinated action on processing transparency and adopts a harmonized DPIA model, the CNIL publishes its 2026 audit priorities and a final recommendation on tracking pixels in emails, Google deploys end-to-end encryption on Gmail under certain conditions, and the CJEU clarifies the limits of abusive access requests. Here are the key takeaways.
Actualités

GDPR compliance and best practices
Digital governance and privacy: why we need to treat the causes rather than the symptoms
Faced with the omnipresence of screens and AI, current regulations often simply treat symptoms rather than causes. For data professionals, the challenge goes beyond simple compliance with the GDPR: it is a question of restoring real attentional and decision-making sovereignty. This summary analyzes why systemic governance is essential to protect human balances and collective performance.
Articles

GDPR compliance and best practices
What does cookies mean: definition and advice to protect your browsing
Understanding what cookies mean is essential to protect your online privacy in 2026. A cookie is a digital memory placed by a site on your browser to remember your preferences or track your behavior. While they offer convenience (basket, language), they also ask the question of whether to accept cookies in the face of the risks of profiling. This guide gives you a clear cookie def and the method to clear Chrome cookies in one click.
Articles

GDPR compliance and best practices
AI and cybersecurity: how to anticipate compliance with the AI Act
The entry into force of the AI Act defines the new framework for European innovation, reconciling technology and the protection of fundamental rights. For DPOs and CISOs, this regulation imposes increased vigilance on the “red lines” of Article 5, such as cognitive manipulation or social scoring. The success of your compliance now depends on integrated governance, linking the requirements of the AI Act to the rigor of the GDPR to ensure a sovereign and secure growth trajectory.
Articles

News
Cegedim Santé data leak: when medical confidentiality is endangered
The e-health sector is going through a major crisis with the massive intrusion suffered by Cegedim Santé, jeopardizing the personal data of nearly 15 million French patients. While medical records have become the priority target of cybercriminals on the dark web, this flaw highlights the fragility of digital medical infrastructures. This analysis deciphers the mechanisms of the attack, the risks of the supply chain (supply chain risk) and the concrete protection measures to be deployed to restore trust between practitioners and patients.
Actualités

News
GDPR and IA Act compliance: summary of the major news of March 2026
The month of March 2026 marks a turning point in digital governance with the forced convergence between cybersecurity, data protection and the regulation of artificial intelligence. Between the historic condemnation of Meta, the adoption of the Resilience Law transposing NIS 2 and DORA, and the official designation of the CNIL as the supervisory authority for the IA Act, compliance officers must now unify their processes. This summary analyzes systemic threats and regulatory changes to transform your obligations into performance drivers.
Articles

Interviews
AI and GDPR compliance in health: feedback from Artic with Adequacy
Compliance with the GDPR and the AI Act is a major challenge for healthcare and clinical research stakeholders. In this discussion, Eve Lepicard and Sophie Malabous from the Artic association explain how using Adequacy compliance software enables them to structure their record of processing activities agilely. Thanks to an intuitive interface and the support of Calixte Descamps, they transform regulatory constraints into tangible operational deliverables.
Interview

GDPR compliance and best practices
AI in health: risks, AI Act compliance and GDPR challenges
The integration of AI in health imposes new compliance challenges related to the GDPR and the AI Act. While the ergonomics of the tools facilitate care, it should not lead to medical disempowerment. For DPOs and CISOs, the challenge is to guarantee effective human surveillance and data sovereignty in the face of legal and technical risks. Learn how to secure your AI deployments while respecting medical confidentiality.
Articles
.png)
Secteur de la santé
AI system and health: how to meet your information obligations? (GDPR, IA Act, CSP)
The use of artificial intelligence systems (AIS) in health imposes on professionals a triple obligation to provide information: the Public Health Code (CSP) for care, the GDPR for personal data, and the IA Act for the transparency of systems. To ensure their compliance, institutions must adopt graded (general, specific and comprehensive) and pedagogical communication. The objective is to guarantee transparency, to respect the right to explanation and to maintain patient-practitioner trust throughout the care journey.
Articles

Secteur de la santé
AI Act et RGPD en santé : comment concilier les deux réglementations avec Adequacy ?
L'entrée en vigueur de l'IA Act ne doit pas être vue comme une contrainte supplémentaire mais comme une extension naturelle du RGPD, particulièrement dans le secteur de la santé où les systèmes sont souvent classés à haut risque. La réussite de cette double mise en conformité repose sur l’AIPD, pivot central permettant d'intégrer la transparence et la supervision humaine. Grâce à Adequacy, cette interopérabilité réglementaire devient un levier d'innovation éthique et de gain de temps opérationnel.
Articles

GDPR compliance and best practices
UNSS and Cegedim Santé data leaks: how to regain control?
The news at the beginning of 2026 is marked by two major data breaches: the theft of 1.5 million photos of UNSS students and the intrusion at Cegedim Santé affecting 15 million patients. Faced with this “long-lasting” hemorrhage of data (health, identity of minors), RGPD compliance must evolve from simple administrative management to an active resilience system. For professionals, this means strict control of third party risks, the adoption of strong authentication (MFA) and a rigorous data purge policy.
Articles

Secteur de la santé
How to frame the reuse of health data: a look back at our webinar
Discover the questions asked during our webinar “How to frame the reuse of health data?”. Led by Calixte Descamps (Adequacy) and Valentine Chauveau (Aumans Avocats), it provides concrete answers on legality, health data warehouses (EDS) and the AI Act to ensure your GDPR compliance. The replay and the PPT support are available to deepen these issues.
Articles

GDPR compliance and best practices
UNSS data leak: the shock of 1.5 million student photos
The massive leak of 1.5 million photos of students from UNSS (National Union of School Sport) on BreachForums marks a turning point in educational cybersecurity. This digital vulnerability, exposing minors from middle school to high school, highlights the critical risk of dormant data. For data protection professionals, this incident requires an urgent review of retention policies, the minimization of collections, and the automation of purges in order to ensure real and protective GDPR compliance.
Articles

GDPR compliance and best practices
GDPR register: how to define the right level of granularity for your treatment sheets?
The register of processing activities is not a static archive, but a living governance lever. For many DPOs, the major challenge lies in the granularity of processing forms: how to be precise without unnecessarily multiplying documents? Based on a set of indicators (purposes, data categories, retention periods), it is possible to structure a coherent register. This guide details the golden rules for grouping or dividing your activities in order to ensure sustainable compliance and simplified management thanks to the appropriate SaaS tools.
Articles

GDPR compliance and best practices
Why do consulting and law firms have an interest in relying on a GDPR and IA Act compliance tool?
Faced with the increasing complexity of the GDPR and the arrival of the AI Act, consulting and law firms must transform compliance from a constraint into a strategic lever. The use of dedicated software makes it possible to centralize records, automate document production and guarantee total traceability, where traditional tools such as Excel reach their limits. By adopting a SaaS solution like Adequacy, professionals secure their deliverables, accelerate the execution of their missions and offer continuous management that retains their customers over the long term.
Articles

GDPR compliance and best practices
Cyberbullying and algorithmic surveillance: the urgency of digital ethics
In 2026, total digital immersion erased the boundaries between private and professional life, giving way to systemic cyberbullying fuelled by intrusive algorithms. Whether it's viral lynchings assisted by AI among adolescents or permanent micro-control via People Analytics in business, data has become a vector of psychological suffering. To counter this invisible epidemic, organizations must move from simple paper compliance to an ethics of responsibility including rigorous audits of their surveillance tools, the anonymization of performance data, and technical compliance with a right to digital darkness.
Articles

News
Privacy & IA: the big change of February 2026
February 2026 marked a turning point with the designation of the CNIL as the supervisory authority for the AI Act, the launch of the first NIS2 audits and a record sanctions record of 486 million euros. Between critical cyberattacks (UNSS, Cegedim) and new requirements on EHDS or the marking of content generated by AI, the convergence between cybersecurity and data protection is becoming an operational obligation. This analysis analyzes the 9 pillars that are redefining compliance for businesses and public organizations.
Actualités

Product
Adequacy V6.2: ensure that your compliance with the GDPR is maintained over time
Compliance with the GDPR is not a one-off project but a daily challenge to maintain it over time. Faced with the requirements of the CNIL, the new Adequacy V6.2 version offers a robust platform to facilitate the management of resources, strengthen risk control and improve the user experience. In particular, this update makes it possible to automate the life cycle of resources and to optimize the management of incidents and violations.
Articles

News
AI social networks and data protection: the new risks of manipulation
In 2026, autonomous AI social networks are turning data protection into an algorithmic security challenge. These spaces, where humans become spectators of exchanges between language models, mask major risks of cognitive manipulation, data poisoning and model reversal. Compliance can no longer be limited to the management of data flows, but must uncover the human intentions behind each interaction to ensure information sovereignty and compliance with the GDPR in the face of the AI Act.
Articles

GDPR compliance and best practices
Minors' Data and AI: Understanding Systemic Compliance Debt
By 2026, the exploitation of data derived from "sharenting" will no longer be just an ethical debate, but a major operational risk for organizations. The massive sharing of minors' data by third parties creates a systemic compliance debt. Between the technical impossibility of algorithmic unlearning and evolving regulations on the digital sovereignty of digital natives, companies face exposure to mass litigation. This briefing note analyzes why managing minors' digital identity is becoming a pillar of data governance and a critical issue of civil and administrative liability.
Articles

News
EU-US Data Privacy Framework: what are the implications for your compliance?
The Data Privacy Framework (DPF), adopted in July 2023, is the third attempt to secure data transfers between Europe and the United States. It establishes a level of protection deemed “substantially equivalent” through new redress mechanisms like the DPRC. However, this adequacy only applies to certified organizations and remains vulnerable to the US Cloud Act and future legal challenges from Max Schrems. To ensure lasting compliance, encryption and Standard Contractual Clauses (SCCs) remain the strongest technical and legal protections.
Articles

GDPR compliance and best practices
DPIA and AI Act: how to optimize AI compliance through threat automation
The entry into force of the AI Act requires an overhaul of data protection impact assessments (DPIA) to integrate systemic risks and algorithmic biases. In 2026, compliance is based on an integrated approach between the GDPR and the AI Act, where the automation of threat scenarios becomes essential. The Adequacy software industrializes this process via the EBIOS methodology, making it possible to generate accurate impact analyses directly from the treatment register to guarantee total control of risks related to artificial intelligence.
Articles

News
Wearable AI and third party consent: the challenges of the Friend.com necklace
Wearable AI, illustrated by devices like the Friend.com necklace, captures data from those around us continuously. This evolution poses the challenge of third party AI consent, as voice is personal data protected by the GDPR. Compliance is based here on transparency, respect for the right to object and rigorous management of data processed outside of any prior framework (Shadow AI).
Articles

GDPR compliance and best practices
Why is the “nothing to hide” argument a data protection error?
The expression “I have nothing to hide” is based on a major confusion between innocence and intimacy. Privacy is not a hiding place for the guilty, but the indispensable foundation of individual freedom and human dignity. Faced with algorithmic surveillance and AI, protecting personal data is an absolute necessity to avoid behavioral manipulation and preserve everyone's autonomy.
Articles
.avif)
GDPR compliance and best practices
Why and how to refuse third-party cookies to protect your privacy
Refusing advertising cookies is essential to protect your health data, your financial situation and your emotional balance in the face of algorithmic scoring. Unlike technical cookies necessary for navigation, third-party trackers transform your behavior into a product. Rigorous management via the “refuse all” button or dedicated tools allows you to regain control without degrading the web experience.
Articles

Secteur de la santé
How to frame the processing of health data for research: a compliance guide
The use of health data for research purposes is based on a complex regulatory framework, between the RGPD, the Data Protection Act (LIL) and the recommendations of the CNIL or the ANS. To secure your projects, it is imperative to correctly qualify the actors (data controller or subcontractor) and to choose the appropriate legal regime: internal studies, research subject to reference methodologies (MR) or constitution of a health data warehouse (EDS). This guide summarizes the compliance obligations to navigate peacefully in this ecosystem that is changing with the arrival of the EHDS.
Articles

Events
Meet Adequacy at the 20th AFCDP DPO University
On February 05 and 06, 2026, the Adequacy team invites you to the Maison de la Chimie in Paris for the unmissable event for data professionals.
Événements

GDPR compliance and best practices
Article 32 of the GDPR: why data security and accountability are the pillars of your compliance in 2026
In 2026, article 32 of the RGPD imposes a reinforced obligation of means, placing computer security at the heart of legal compliance. To ensure data protection, organizations must deploy technical and organizational measures that are proportionate to the risks (encryption, 2FA, resilience) while respecting the principle of Accountability. This responsibility requires proving the effectiveness of these devices in the face of tighter sanctions and the new requirements of the Digital Omnibus project.
Articles

GDPR compliance and best practices
Audit the GDPR compliance of your subcontractors: the guide to secure your liability
The compliance of a data controller depends directly on the rigor of its service providers. Under the GDPR, outsourcing does not exempt you from liability: you must ensure that your subcontractors offer sufficient guarantees in terms of security and confidentiality. This guide details vigilance obligations, contractual levers such as the Security Assurance Plan (PAS) and offers a checklist of 16 control points to industrialize your audits and prove your diligence (Accountability).
Articles

Secteur de la santé
Digital Omnibus and health data: impacts on the reuse of medical data
The Digital Omnibus project aims to harmonize the GDPR and the AI Act to simplify the reuse of health data and promote medical innovation in Europe. By clarifying the identifiability of pseudonymized data, this reform could transform research practices while requiring strengthened governance.
Articles

News
DPO, AI Act, and Digital Omnibus: compliance strategies for 2026
The role of the DPO is changing following the gradual entry into force of the Digital Omnibus (DSA, DMA, Data Act) and the AI Act. These texts require organizations to move from traditional GDPR compliance to a global data and AI governance strategy. The DPO is becoming a strategic player that must guarantee algorithmic transparency, data interoperability and the classification of AI systems according to their level of risk. The challenge for 2026 is the integration of compliance by design to prevent sanctions and transform these regulatory challenges into competitive advantage.
Articles

GDPR compliance and best practices
GDPR consent: strategic pillar for the protection of personal data
Consent is the most strategic legal basis under the GDPR for the processing of any personal data. It requires a positive, free, specific and informed action by the person concerned, in particular for the collection of cookies, newsletters and marketing treatments. Invalid consent exposes your organization to major sanctions (GDPR fines, loss of trust, suspension of campaigns). To ensure defensible compliance and secure your future treatments, including those involving AI and the AI Act, it is crucial to document each step, offer a fair choice (accept/refuse), and ensure full traceability of evidence.
Articles

Product
Adequacy NIS 2 pack: integrated GDPR and AI Act compliance
Since January 2023, the NIS 2 directive has strengthened cybersecurity obligations in Europe. This directive, combined with the GDPR and the AI Act (gradual application from 2026), makes the regulatory burden complex. Adequacy's NIS 2 Pack meets this challenge by offering a step-by-step approach and a unique and integrated SaaS tool. This solution supports DPOs, CIOs and CISOs towards sustainable compliance by covering these three regulations, thus avoiding redundancies, reducing costs and generating automatic proof of compliance for audits.
Articles

Secteur de la santé
Reuse of health data: the 8 prerequisites (RGPD, Public Health Code, CNIL doctrine and sectoral requirements)
The reuse of health data is a crucial innovation driver, especially for research, the improvement of care and the development of AI tools. However, this process is strictly regulated by the RGPD, the Public Health Code and the CNIL doctrine. Before any project, it is imperative to validate 8 essential prerequisites that condition the legality and conformity of subsequent processing. From the qualification of use (primary vs secondary) to HDS hosting and the requirements of the AI Act, a methodical and rigorous approach is the only guarantee of innovative, controlled and sustainable use.
Articles

News
Viral marketing: from the Intermarkt ad that's going viral... to the importance of protecting personal data
The recent viral advertising by InterMarché illustrates the power of emotion in digital marketing, but this success should not make us forget the major challenge of protecting personal data. Today, every digital interaction — from watching a commercial on social networks to browsing a site — involves the collection of information. For brands, consumer trust is no longer based solely on the quality of content, but also, and above all, on transparent and responsible management of their data, in line with the GDPR. Combining a strong message and respect for confidentiality is now the real guarantee of success in a hyper-connected world.
Articles

GDPR compliance and best practices
Compliance debt RGPD & AI Act: the silent risk that is already costing companies dearly
Compliance debt is the insidious accumulation of incomplete processes, obsolete documentation, and untracked data processing. This silent risk, generated by the proliferation of SaaS tools and requirements like RGPD and the AI Act, is no longer just a legal issue, but a genuine strategic and financial risk. Direct consequences include heavy fines, loss of productivity, and the blocking of AI or data-driven projects. To reduce it, companies must imperatively industrialize and centralize their compliance processes, equipping their DPOs with adapted, sovereign platforms.
Articles

Intelligence artificielle
AI Act: limited risk AI systems, transparency, and compliance
The category of limited-risk AI systems under the AI Act aims to govern innovation while protecting users. While these systems do not pose a critical threat to fundamental rights, their use is subject to strict transparency obligations. The article details how professionals (suppliers and deployers) must ensure traceability and user information, particularly through rigorous documentation and light monitoring, which are essential principles for AI Act compliance within organizations.
Articles

GDPR compliance and best practices
RGPD legitimate interest: secure your personal data processing
The GDPR legitimate interest is a key basis for the processing of personal data, but it imposes a rigorous legitimate interest test. To secure your transactions and avoid sanctions, you must ensure the need for processing, transparency and respect for the right to object. In this article, discover compliance requirements and best practices for mastering this pillar of the GDPR with appropriate tools.
Articles

Intelligence artificielle
High-risk AIs according to the AI Act: how to identify them?
Unlike prohibited systems, high-risk AIs defined by the AI Act (automated recruitment, public services, biometrics) are authorized, but subject to strict obligations. Identifying, documenting and securing each use case is now mandatory to build a robust compliance file.
Articles

Intelligence artificielle
AI ranking: French, European and global — Choosing a solution that complies with the GDPR and the AI Act
Artificial Intelligence is omnipresent, but behind innovation there is a major challenge of digital sovereignty and compliance with the GDPR and the recent AI Act. This article is intended for Legal, IT and Compliance departments to guide them in the ranking of AIs (French, European or global) and to help them structure the use of these technologies in a responsible and sustainable way.
Articles

News
Digital Omnibus: anticipate the impacts on GDPR and compliance
The Digital Omnibus, a European legislative project, aims to group and simplify digital texts, but could change pillars of the GDPR, the e-Privacy Directive and the AI Act, creating risks of weakening digital rights. For DPOs and Compliance Managers, it is crucial to anticipate these changes in the definition of personal data, legitimate interest and the processing of sensitive data in order to immediately strengthen governance and secure GDPR compliance.
Articles

Intelligence artificielle
AIs prohibited by the AI Act: when the use becomes risky and unacceptable
The European AI Act strictly prohibits uses of AI deemed to be at “unacceptable risk”, such as social scoring, cognitive manipulation (subliminal messages) or the exploitation of vulnerabilities. It is imperative for any organization to identify, block and document the absence of these prohibited practices.
Articles

Métier
RGPD and IA Act: what should DPOs prepare by 2025?
From 2025, DPOs will have to articulate RGPD and IA Act for all high-risk AI systems, by updating their DPIs, registers and internal procedures, and by guaranteeing traceability, transparency and human supervision to ensure integrated and secure compliance.
Articles

GDPR compliance and best practices
Measuring your company's GDPR maturity: preparing 2026 with the CNIL method
En 2026, la conformité ne suffit plus : la maturité RGPD devient un levier stratégique. Découvrez comment évaluer votre niveau de maturité et piloter efficacement votre conformité grâce à la méthode d’autoévaluation de la CNIL.
Articles

News
Shadow AI in Business: The Invisible Threat to AI Act and Performance
Shadow AI — the unauthorized use of artificial intelligence tools within an organization — poses a critical threat to compliance with both the GDPR and the EU AI Act. Identifying hidden AI usage, establishing clear governance, and promoting responsible innovation are essential steps to turn this invisible risk into a driver of secure, compliant, and controlled innovation.
Articles

Secteur de la santé
Health methodologies, guides and standards: apply the GDPR effectively
Entre référentiels CNIL, méthodologies de référence et guides pratiques, les professionnels de santé disposent de nombreux outils pour appliquer le RGPD efficacement — encore faut-il savoir lesquels suivre, comment les articuler et les adapter à leurs traitements de données sensibles.
Articles

News
Video Surveillance and AI: Ensuring GDPR Compliance to Protect Public Freedoms
La vidéosurveillance algorithmique associée à l’IA transforme le contrôle et la sécurité dans l’espace public et privé, mais sa conformité au RGPD et à l’IA Act est essentielle pour protéger les libertés publiques, encadrer les algorithmes, limiter la conservation des données et garantir transparence et traçabilité.
Articles

News
10 GDPR news to remember in September 2025
In September 2025, GDPR news was marked by record sanctions from the CNIL, the entry into force of the Data Act, the validation of the Data Privacy Framework and new obligations for companies in terms of data, AI and transparency.
Actualités

GDPR compliance and best practices
Write a privacy policy and information notices that comply with the GDPR, are clear, transparent and accessible to all
Writing a privacy policy in accordance with the GDPR is an essential step in inspiring trust and ensuring transparency in the processing of personal data. This practical guide explains how to design documents that are legible, accessible, and effective for your users.
Articles

GDPR compliance and best practices
GDPR and Human Resources: 5 mistakes that cost companies dearly
HR is on the front line of GDPR. Recruitment, payroll, training, and occupational health are just a few of the processes that expose employees' personal data. Excessive data retention, sending incorrect emails, and incomplete contracts are costly mistakes. Adopting the right reflexes allows HR to ensure compliance and strengthen employee trust.
Articles

Product
Adequacy V6.1: the GDPR software that integrates compliance with the AI Act
Adequacy V6.1 centralizes GDPR and AI Act compliance by offering DPOs, lawyers and compliance managers a modular solution to map, assess and manage their AI systems and models while automating European regulatory obligations.
Articles

Secteur de la santé
Health sector: master the RGPD in your EDS
Setting up a health data warehouse requires strict compliance with the RGPD and the CNIL standard, based on clear governance, comprehensive documentation and high security measures. The DPO is the guarantor, ensuring transparency and compliance at each stage of the project.
Articles

GDPR compliance and best practices
Cutting the GDPR budget: a risk for your business opportunities
The GDPR is a strategic investment: cutting your budget weakens the confidence of investors, limits access to financing and weakens the company's competitiveness on the market.
Articles

News
European AI regulation: a regulatory goose game?
Complying with the GDPR is a challenge for all businesses. A dedicated RGPD software allows you to automate your legal obligations, centralize the management of personal data and significantly reduce the risks of sanctions.
Articles

News
Geolocating your children: safety or surveillance? Legal, ethical and sociological issues to know
The geolocation of children is attracting more and more parents concerned about safety, but it also raises legal and ethical risks. Between protection and surveillance, the legal framework (RGPD, CNIL) and sociological issues make it possible to understand where to put the limit to protect without locking in.
Actualités

GDPR compliance and best practices
GDPR and Small Businesses (SMEs & Micro-Enterprises): A Requirement, but Above All an Opportunity
The GDPR also applies to small businesses: a client database, a newsletter, or HR data is enough to be concerned. Far from being a constraint, compliance helps reduce risks, build credibility, and transform data management into a competitive advantage.
Actualités

GDPR compliance and best practices
Digital Right to Be Forgotten Charter: Targeted Advertising, Collaborative Platforms, and Search Engines
Two charters adopted in 2010 established the foundations of the digital right to be forgotten, from targeted advertising to search engines. They foreshadowed GDPR and continue to remind businesses today of the importance of transparency, data control, and digital trust.
Articles

GDPR compliance and best practices
HR Engagement in Data Protection: A Strategic and Legal Imperative
On a daily basis, HR teams manage highly sensitive information and must comply with both labor law and the GDPR. Key risks include data breaches, unlawful retention, and loss of employee trust. With Adequacy, HR departments can secure their data processing, comply with statutory retention periods, and strengthen both trust and competitiveness.
Articles

Secteur de la santé
EHDS: what is the impact for DPOs in the health sector?
The European Health Data Space (EHDS) complements the GDPR by harmonizing access, exchange and reuse of health data at the EU level, in order to improve care and stimulate innovation. For DPOs, this means a strengthened role in governance, security, compliance and ethics, with new practical obligations (audits, AIPD, documentation, cooperation with authorities).
Articles

Secteur de la santé
How can you control the processing of your health data? Sensitive information! [DPO Notice]
Health data is one of the most sensitive types of data. Its processing requires a strict GDPR framework, solid legal bases, and rigorous governance. Read our article to discover the keys to staying compliant and securing your projects.
Articles

Secteur de la santé
Reference methodologies (MR) in healthcare: which ones to choose and how to use them?
Healthcare Reference Methodologies (MR): Master CNIL rules and secure your processing operations. Learn about the seven MRs and their conditions of use.
Articles

GDPR compliance and best practices
GDPR penalties: what to expect and how to avoid them
GDPR penalties, which can reach €20 million or 4% of a company's turnover, affect businesses, local authorities, banks, and subcontractors. These penalties are often the result of avoidable breaches, such as missing records, excessive data collection, and failure to meet deadlines. With Adequacy compliance software, however, you can structure your processes, secure your data, and reduce the risk of penalties, including those related to DORA compliance.
Articles

GDPR compliance and best practices
Is complying with the GDPR using Excel or dedicated software really an issue?
While Excel can help you get started with GDPR, only dedicated software can ensure long-term secure and collaborative compliance.
Articles

Intelligence artificielle
AI Act: Everything you need to know about the new European law on artificial intelligence
The AI Act is a historic turning point for Europe. It promises to strengthen trust in AI and force organizations to reconsider how they use it and ensure compliance.
Articles

GDPR compliance and best practices
GDPR Record of Processing Activities [DPO Insights]
A key GDPR tool, the Record of Processing Activities tracks the use of personal data and helps organizations ensure compliance while avoiding heavy penalties.
Articles

Events
GDPR and AI Act: Master your GDPR compliance today and prepare for the future
Join our webinar to simplify your GDPR compliance and prepare for the AI Act. Our all-in-one software is designed for DPOs and lawyers and includes mapping, registers, risk analysis, and unified governance.
Événements

Adequacy
Adequacy has announced its 2025 ambitions, citing its growth as a key factor in achieving these goals
Adequacy is strengthening its governance and developing innovative solutions to help companies comply with the RGPD and beyond; with over 600 customers in 80 countries, the company now aims to accelerate its international expansion.
Articles

News
NIS 2: what the directive changes for your business
The NIS 2 directive reinforces cybersecurity obligations in Europe. Find out who is affected, what is changing in practice and how to effectively prepare for it.
Actualités

News
Digital dependency: 3 factors in a predicted surge?
Europe's dependence on U.S. digital services costs €264 billion a year and undermines its sovereignty. With extraterritorial legal influence, industrial backwardness, and economic short-termism, building sustainable digital autonomy requires a leap of faith.
Actualités

Product
Discover what’s new with version 6.0!
This major update to ADEQUACY rethinks ergonomics, enhances RGPD functionalities, and paves the way for future developments in AI and security.
Articles

Adequacy
Adequacy appoints Fabrice de Salaberry as Chief Executive Officer
Adequacy appoints Fabrice de Salaberry, B2B SaaS expert, as CEO to accelerate the French regulatory compliance specialist's European growth. His arrival marks a new phase of development for Adequacy.
Articles

Adequacy
Adequacy obtains the EcoVadis gold medal: a recognition of our CSR commitment
The EcoVadis gold medal gives us a distinction that ranks us among the 5% of the most exemplary companies in terms of social responsibility. This reference label recognizes our concrete actions in favor of the environment, human rights and ethics, and confirms our desire to combine digital innovation, GDPR compliance and sustainable development.
Articles

Adequacy
Adequacy ranked best GDPR compliance software by Déciders Magazine
Adequacy a été classé numéro 1 des logiciels de conformité RGPD en 2024 par le Magazine Décideurs. Cette distinction récompense notre engagement à rendre la conformité accessible, sécurisée et souveraine, grâce à une solution complète adoptée par plus de 10 000 entités à travers le monde. Un gage de confiance pour toutes les organisations qui placent la protection des données au cœur de leur stratégie.
Articles

News
Data Privacy Framework: 3 factors of an inevitable shock
Alors que le Data Privacy Framework devait rétablir un cadre de confiance entre l’Europe et les États-Unis, sa stabilité est aujourd’hui remise en question. Des membres du Privacy and Civil Liberties Oversight Board, garant clé de ce dispositif, ont été poussés à la démission, fragilisant un accord déjà critiqué pour sa base juridique instable. À l’approche d’un potentiel bouleversement politique aux États-Unis, l’Europe peut-elle encore s’appuyer sur un système aussi précaire pour protéger les données de ses citoyens ?
Articles

Témoignage client
Interview with Dominique Pissoort, DPO of STIB
Dominique Pissoort, DPO de la STIB, nous raconte comment Adequacy a simplifié la gestion du RGPD et transformé la conformité des données dans cette grande entreprise publique.
Interview

Events
Adequacy at DPO Morning
On the occasion of the DPO Morning organized by Le Printemps des DPO, our experts spoke during a morning dedicated to the challenges of DPOs. Claire de la Fouchardière, Product Manager, and Alessandro Fiorentino, Product Owner, shared their expertise on a current topic: “The GDPR is no longer alone: what solution is there to ensure your compliance with other data protection regulations? ”. A rich exchange around strategies, tools and challenges related to global compliance to be discovered in replay.
Événements

Témoignage client
Interview with Camille Bradfer, HR Manager and GDPR representative at Ma Petite Mercerie
Discover how Ma Petite Mercerie, leader in online haberdashery sales in France, optimized its GDPR compliance with Adequacy. Camille Bradfer reveals to us the advantages of the solution, its impact on the internal organization and the development of teams' skills, while sharing her vision of the DPO of tomorrow.
Articles

Events
Adequacy & Phenix Privacy at the DPO Forum Lyon 2024!
At the DPO Forum Lyon 2024, Phenix Privacy and our team presented best practices for conducting effective impact assessments (AIPD), strengthening GDPR compliance and anticipating future regulations such as the AI Act.
Événements

Events
Adequacy was present at Printemps des DPO 2024
Present at the DPO Spring 2024, Alessandro Fiorentino led two masterclasses dedicated to data breaches and the collaboration between DPO, RSSI and DSI in the face of new regulations (NIS2, DORA, IA Act). An event rich in expertise, at the service of ever more operational and strategic compliance.
Événements

Témoignage client
DPO of Dassault Aviation Group: Philippe Ebert's feedback on Adequacy
Philippe Ebert, DPO for the Dassault Aviation Group, transitioned from a GDPR register managed in Excel to an industrial solution capable of coordinating around thirty correspondents, including its subsidiaries and international offices. He shares his experience with Adequacy: improved auditability, a higher quality register thanks to guided mode and consistency checks, traceability of modifications useful in case of a CNIL audit, and a strengthened transparency policy towards employees. He also provides his vision for the DPO of tomorrow, who will need to leverage their network of correspondents to address the AI Act and Data Act.
Articles

Events
Adequacy alongside the CCI France Belgium
During an event organized with CCI France Belgium, we brought together experts and companies around the intersecting challenges of the GDPR, NIS2, DORA and the IA Act. An opportunity to strengthen the synergies between DPO and CISO, and to present our compliance solution adapted to European requirements and the Belgian market.
Événements
Discover Adequacy
One of our experts introduces Adequacy to you in a real situation.