NORMYA NORMYA
FR EN
Get in touch

NORMYA · Nantes & western France

Know to foresee,foresee to act.

A digital compliance consultancy: GDPR readiness, outsourced Data Protection Officer, risk management, NIS 2 compliance and data governance.

Public and private companies, local authorities and associations — we work across every sector in western France.

An elephant sitting on a thin branch above the desert — the NORMYA brand image, standing for the risk you never see coming

Digital compliance · from Nantes, France

The firm

Compliance that holds up in real life.

Security for security's sake, treating acceptable risks while ignoring the pressing ones, disregarding how your people actually work: none of it makes sense.

Since we started, we have supported our partners in their digital compliance while keeping a constant eye on the rules, the standards — and on how they play out in practice. Our engagements have one purpose: your satisfaction, and measures you can genuinely apply.

NORMYA helps you know and foresee, so that you can carry out your work with peace of mind.

KnowUnderstand your data, your processing activities and your real exposure.
ForeseeAssess, prioritise and document before the incident, not after.
ActMove confidently, with the right tools and the right reflexes.
Yellow NORMYA folding ruler reading « Mesurez vos risques » — measure your risks — lying on a wooden floor

What we do

Three disciplines, one standard of pragmatism.

From a one-off audit to full delegation of the DPO role, we shape the engagement around your maturity and your means.

« RGPD Trust by NORMYA » seal — ethical compliance

GDPR compliance

From staff awareness to full delegation of the Data Protection Officer role, NORMYA takes your GDPR compliance from end to end.

Read more
A small house perched on an isolated rock in the water — an image of resilience

Risk management & NIS 2

Protecting yourself and building real resilience starts with knowing every one of your risks, assessing them and keeping them under control.

Read more
A mask evoking the anonymous cyber threat

Data governance

Governing your data means owning it, and owning your future with it. Our advice on information system management and cybersecurity is where that starts.

Read more
RGPD Trust by NORMYA seal

Service 01

GDPR compliance

From the audit through to outsourcing the Data Protection Officer role.

The TRUST GDPR audit by NORMYA

Our in-house audit framework is developed and continually updated to meet the requirements of the General Data Protection Regulation — across its technical, organisational, legal, environmental and documentary dimensions.

  • More than 300 questions to establish your organisation's GDPR maturity
  • A baseline score, then a measured view of how it evolves over time
  • A prioritised action plan, not a list of failings

The outsourced DPO

The Data Protection Officer drives, carries and monitors everything an organisation does to comply with the GDPR. Appointing one is mandatory in certain cases and recommended in all others: the DPO is the regulator's point of contact. Appointing internally is often difficult, because the role is tightly framed by law.

By appointing NORMYA as your DPO, you gain both peace of mind and assurance that the law is being followed — capability, competence and constant regulatory watch.

NORMYA is a member of the AFCDP, the French association of data protection officers.

An isolated house on a rock, illustrating resilience in the face of incidents

Service 02

Risk management & NIS 2 compliance

Look ahead with confidence, and prepare for the incidents that are likely — whether they come from inside or outside.

Assessing and managing your risks

  • Identification and assessment of your information system risks
  • A risk management process built on ISO 27005
  • An information security management system aligned with ISO 27001
  • A complementary reading through the NIST Cybersecurity Framework 2.0

Measuring your practice against the law

NORMYA assesses how your organisation actually works and measures it against the applicable legislation — the NIS 2 directive in particular — against current case law, and against the state of the art in the field concerned.

The right tools, then the right documents

Managing risk means using the right method with the right tools: we favour solutions recognised on the market and, wherever possible, certified by ANSSI, the French national cybersecurity agency, or recommended by the CNIL.

  • Resilience, business continuity and disaster recovery plans
  • Internal rules, acceptable use policy, terms and conditions, specific contractual clauses
  • Information security policies, crisis management framework, thematic policies

This documentary groundwork lets executives allocate responsibility clearly and coordinate in a way that reduces both the likelihood and the impact of incidents.

Illustration of data protection: padlock, documents and GDPR references

Service 03

Data governance

Personal, strategic, technical, commercial: your data is your essential capital. You should not be facing its governance alone.

Good governance means, above all, securing the data — guaranteeing its availability, its integrity, its confidentiality and its traceability.

What we put in place

  • Security solutions: access management (in partnership with Keeper), security suites, architecture
  • Vulnerability scanning across networks and websites
  • Redesign of network structure and the access rights that go with it
  • Information system management consulting
  • Cybersecurity training and awareness programmes
  • Response testing: phishing simulations, password compromise
  • Drafting of founding documents: security policies, acceptable use policy

NORMYA maintains an active regulatory watch and continuous training on these subjects, so that our advice reflects the current state of the art.

Our references

References across a wide range of sectors.

  • Healthcare & personal services
  • IT
  • Transport
  • Retail
  • Industry & energy
  • Finance
  • Social sector
  • Security
  • Marketing, communications, media
  • Training
  • Tourism…

These references are not incidental. Knowing your sector lets us be effective from day one and propose an engagement that actually fits. For you, that means timelines and costs stay under control.

Your sector is not on the list? No problem — we are curious, and we will adapt.

A warm thank you to our loyal partners

“The GDPR and the risks to our data no longer intimidate us.”

“We have been working with NORMYA for almost four years now. What stays with me is the undeniable expertise they bring in their fields.

Even when the subjects are complex from where we sit, the answers and the support have always been quick, relevant and, above all, tailored to each situation. NORMYA has guided us very pragmatically, and has known how to meet us at our level.

After an initial audit, we started a long way from compliance, and since then we have been making progress efficiently and very realistically. We call on NORMYA at the slightest doubt, and that is genuinely reassuring for us.”

Frédéric J., IT DirectorPublic urban transport company

Frequently asked questions

What clients ask us most often.

When is appointing a Data Protection Officer mandatory?

Article 37 of the GDPR sets out three cases in which appointing a DPO is mandatory: where the processing is carried out by a public authority or body; where the core activity consists of regular and systematic monitoring of individuals on a large scale; and where it consists of large-scale processing of special categories of data or of data relating to criminal convictions. Outside those cases, appointment remains strongly recommended by the texts, and many clients now require it contractually.

Can the DPO role be outsourced?

Yes. The GDPR expressly allows an external DPO to be appointed. For a mid-sized organisation this is often the most realistic option: the role is tightly framed and calls for legal, technical and organisational expertise together with a permanent regulatory watch — a combination that is hard to sustain in a part-time internal post. Appointing NORMYA gives you that expertise and that watch without carrying them in-house.

What is the NIS 2 directive, and does it apply to me?

NIS 2 is the European directive on the security of network and information systems, which entered into force in December 2022. It considerably widens the range of entities subject to cybersecurity and incident-notification obligations, distinguishing “essential” from “important” entities according to sector and size. Many organisations that fell outside NIS 1 are now in scope, often without realising it. The first step is to establish where you stand.

How does a TRUST GDPR audit work?

The audit rests on a framework of more than 300 questions covering the technical, organisational, legal, environmental and documentary dimensions of the regulation. It produces a measured maturity level and then a prioritised action plan. Because the framework is continually updated, the exercise can be repeated to track how your compliance progresses over time.

Which standards do you work from for risk management?

Principally ISO 27005 for risk management and ISO 27001 for the information security management system, complemented by the NIST Cybersecurity Framework 2.0. We favour tools recognised on the market and, wherever possible, certified by ANSSI or recommended by the CNIL, the French data protection authority.

Where do you operate?

From Nantes, across the whole of western metropolitan France. We work with public and private companies, local authorities and associations, in every sector of activity.

Contact

A doubt, a project, a deadline?

One conversation is usually enough to see clearly. Tell us where you stand, and we will tell you what actually comes first.

Phone +33 7 79 82 47 99 Email contact@normya.fr
Address 46 rue de la Duchesse
44100 Nantes, France
Illustration of a secure digital communications network