You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Alain R.AR

Alain R.

Senior Operational DPO | Privacy Officer | Manager

€800/day
Lille, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Alain

Senior operational DPO and transition manager, with over 10 years of experience in data protection, GDPR compliance (General Data Protection Regulation), and privacy governance in group, international, and multi-business environments. I support organizations in controlling their compliance through maturity assessment, data processing mapping, ROPA maintenance (Record of Processing Activities), conducting DPIAs (Data Protection Impact Assessments), managing data subject rights, audit-ready documentation, and steering prioritized action plans. Accustomed to working with the CNIL (National Commission for Information Technology and Liberties), IT departments, legal teams, business units, and third parties, I work independently on high-stakes missions, with a strong requirement for documentary traceability, pragmatism, and governance transfer. My GRC (Governance, Risk & Compliance) and cybersecurity foundation complements this expertise on ISO 27001:2022, ISO 22301, DORA (Digital Operational Resilience Act), and NIS2 (Network and Information Security 2) frameworks.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Lille (up to 10km), Paris (up to 10km), Bruxelles (up to 10km)

Experience

  • New Immo Holding (nhood)
    TRANSITION MANAGER RGPD / GROUP DPO & AI GOVERNANCE
    REAL ESTATE
    February 2026 - Today (6 months)
    Villeneuve-d'Ascq, France
    •Stepped in urgently to fill a vacant position without handover in a real estate holding company to secure GDPR compliance and establish the regulatory minimum for an authority audit.
    •Flash GDPR maturity assessment conducted; critical non-compliance areas, security vulnerabilities, and remediation priorities identified across HR, sales, real estate, digital activities, and B2B/B2C data.
    •Data mapping revamped and Record of Processing Activities (ROPA) updated for complex flows; mapping of sub-processors, cross-border flows, and sensitive data.
    •Strategic 12-month roadmap built with quick wins and structural actions prioritized by urgency and risk impact; compliance milestones defined.
    •'Audit-ready' documentation produced: policies (data subject rights, retention, sub-processing), procedures, proof of compliance.
    •Strategic interface maintained between the Ethics & Compliance Department, IT, and business units to integrate Privacy by Design into industrial and digital processes.
    •AI GOVERNANCE: Member of the group's AI governance committee. Conducted Impact Assessments (PIA) for OpenAI and Anthropic deployments, evaluating data usage, model training risks, prompt injection vulnerabilities, and cross-border data flows. Established governance criteria for AI vendors and integration protocols.
    •Integrated AI risk management into the enterprise GRC framework, ensuring alignment between GDPR data protection requirements, DORA operational resilience standards, and the emerging obligations of the European AI Act.
    •Structured handover file prepared and sustainable governance model established for the future Privacy Compliance Officer, including recommendations on delegations of power and responsibility.
    Artificial Intelligence AI Chatbot RGPD Record of Processing Activities Data Privacy
  • BNP Paribas
    GRC CONSULTANT – DORA COMPLIANCE PROGRAM
    June 2023 - June 2025 (2 years)
    Paris, France
    • Business analysis conducted for the classification of critical ICT (Information and Communication Technology) assets, vital and non-vital, in accordance with Article 6 of the Digital Operational Resilience Act (DORA) across Group entities (15+ brands and international geographic areas).
    • Cross-functional coordination ensured between IT infrastructure teams, business units, and regulatory compliance departments; facilitated arbitration between technical constraints and regulatory deadlines.
    • Follow-up of remediations implemented via ServiceNow GRC (Risk Module, CMDB - Configuration Management Database) and JIRA; user stories and acceptance criteria developed, backlog reduction of 40%.
    • Risk reporting dashboards and KPIs (Key Performance Indicators) produced for monthly steering committees (COPIL) with subsidiary executive management.
    • RUN support provided: incident management and post-deployment hypercare to ensure business continuity during critical system transitions.
  • Euranet
    Auditor
    CONSULTING AND AUDITS
    April 2022 - November 2024 (2 years and 7 months)
    • Conducted security and compliance audits according to ISO 27001, ISO 22301, ISO 28000 standards. Formalized recommendations, audit reporting, organized and led business workshops, business continuity exercises.
    Audit ISO 27001 ISO 22301 BCP DRP

Recommendations

Be the first to recommend Alain

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • DU DPO, RGPD Data Protection
    Université Paris Dauphine
    2019
    DU DPO, RGPD Protection des Données
  • Master of Political Science
    Sciences Po Lille
    1996
    Master 2 (M2), Political Science

Certifications

  • ISO 22301
    PECB
    2022
    BCP/DRP
  • Prince2
    PeopleCert Education
    2021
    Project Management

Skill set

Categories