GDPR compliance
From staff awareness to full delegation of the Data Protection Officer role, NORMYA takes your GDPR compliance from end to end.
Read moreNORMYA · Nantes & western France
A digital compliance consultancy: GDPR readiness, outsourced Data Protection Officer, risk management, NIS 2 compliance and data governance.
Public and private companies, local authorities and associations — we work across every sector in western France.
Digital compliance · from Nantes, France
The firm
Security for security's sake, treating acceptable risks while ignoring the pressing ones, disregarding how your people actually work: none of it makes sense.
Since we started, we have supported our partners in their digital compliance while keeping a constant eye on the rules, the standards — and on how they play out in practice. Our engagements have one purpose: your satisfaction, and measures you can genuinely apply.
NORMYA helps you know and foresee, so that you can carry out your work with peace of mind.
What we do
From a one-off audit to full delegation of the DPO role, we shape the engagement around your maturity and your means.
From staff awareness to full delegation of the Data Protection Officer role, NORMYA takes your GDPR compliance from end to end.
Read moreProtecting yourself and building real resilience starts with knowing every one of your risks, assessing them and keeping them under control.
Read moreGoverning your data means owning it, and owning your future with it. Our advice on information system management and cybersecurity is where that starts.
Read moreService 01
From the audit through to outsourcing the Data Protection Officer role.
Our in-house audit framework is developed and continually updated to meet the requirements of the General Data Protection Regulation — across its technical, organisational, legal, environmental and documentary dimensions.
The Data Protection Officer drives, carries and monitors everything an organisation does to comply with the GDPR. Appointing one is mandatory in certain cases and recommended in all others: the DPO is the regulator's point of contact. Appointing internally is often difficult, because the role is tightly framed by law.
By appointing NORMYA as your DPO, you gain both peace of mind and assurance that the law is being followed — capability, competence and constant regulatory watch.
NORMYA is a member of the AFCDP, the French association of data protection officers.
Service 02
Look ahead with confidence, and prepare for the incidents that are likely — whether they come from inside or outside.
NORMYA assesses how your organisation actually works and measures it against the applicable legislation — the NIS 2 directive in particular — against current case law, and against the state of the art in the field concerned.
Managing risk means using the right method with the right tools: we favour solutions recognised on the market and, wherever possible, certified by ANSSI, the French national cybersecurity agency, or recommended by the CNIL.
This documentary groundwork lets executives allocate responsibility clearly and coordinate in a way that reduces both the likelihood and the impact of incidents.
Service 03
Personal, strategic, technical, commercial: your data is your essential capital. You should not be facing its governance alone.
Good governance means, above all, securing the data — guaranteeing its availability, its integrity, its confidentiality and its traceability.
NORMYA maintains an active regulatory watch and continuous training on these subjects, so that our advice reflects the current state of the art.
Our references
These references are not incidental. Knowing your sector lets us be effective from day one and propose an engagement that actually fits. For you, that means timelines and costs stay under control.
Your sector is not on the list? No problem — we are curious, and we will adapt.
A warm thank you to our loyal partners
“The GDPR and the risks to our data no longer intimidate us.”
“We have been working with NORMYA for almost four years now. What stays with me is the undeniable expertise they bring in their fields.
Even when the subjects are complex from where we sit, the answers and the support have always been quick, relevant and, above all, tailored to each situation. NORMYA has guided us very pragmatically, and has known how to meet us at our level.
After an initial audit, we started a long way from compliance, and since then we have been making progress efficiently and very realistically. We call on NORMYA at the slightest doubt, and that is genuinely reassuring for us.”
Frédéric J., IT DirectorPublic urban transport company
Frequently asked questions
Article 37 of the GDPR sets out three cases in which appointing a DPO is mandatory: where the processing is carried out by a public authority or body; where the core activity consists of regular and systematic monitoring of individuals on a large scale; and where it consists of large-scale processing of special categories of data or of data relating to criminal convictions. Outside those cases, appointment remains strongly recommended by the texts, and many clients now require it contractually.
Yes. The GDPR expressly allows an external DPO to be appointed. For a mid-sized organisation this is often the most realistic option: the role is tightly framed and calls for legal, technical and organisational expertise together with a permanent regulatory watch — a combination that is hard to sustain in a part-time internal post. Appointing NORMYA gives you that expertise and that watch without carrying them in-house.
NIS 2 is the European directive on the security of network and information systems, which entered into force in December 2022. It considerably widens the range of entities subject to cybersecurity and incident-notification obligations, distinguishing “essential” from “important” entities according to sector and size. Many organisations that fell outside NIS 1 are now in scope, often without realising it. The first step is to establish where you stand.
The audit rests on a framework of more than 300 questions covering the technical, organisational, legal, environmental and documentary dimensions of the regulation. It produces a measured maturity level and then a prioritised action plan. Because the framework is continually updated, the exercise can be repeated to track how your compliance progresses over time.
Principally ISO 27005 for risk management and ISO 27001 for the information security management system, complemented by the NIST Cybersecurity Framework 2.0. We favour tools recognised on the market and, wherever possible, certified by ANSSI or recommended by the CNIL, the French data protection authority.
From Nantes, across the whole of western metropolitan France. We work with public and private companies, local authorities and associations, in every sector of activity.
Contact
One conversation is usually enough to see clearly. Tell us where you stand, and we will tell you what actually comes first.