You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Eric LachaudEL

Eric Lachaud

GDPR & AI Governance Compliance

€900/day
Paris, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Eric

Doctor of Personal Data Law
15 years of experience in CNIL/GDPR compliance
20 years in IT project management
Certified ISO 27001 and ISO 42001 lead implementer and ISO 27001 lead auditor
Certified AI Trust and Privacy Officer

- AI Governance and Ethics (Expertise ISO 42001, 42005 and 23894)
- Change Management and Training (AI Literacy)
- Impact and Risk Assessments (PIA, TIA, LIA, AI ACT)
- Risk Analysis in relation to the AI Act and GDPR
- Maturity Audit
- Gap Analysis
- Due Diligence
- Certification Audit (27001, 27701, 42001)
- Data Inventory and Updates to the Record of Processing Activities (Article 30)
- Remediation Plan
- Deployment and Management of AI Management Systems (ISO, NIST)
- Process Automation (Individual Rights Responses)
- Data Classification, Labeling, and Deletion/Anonymization
- Software Installation, Deployment, and Administration (OneTrust and Securiti Certified)
- IT Project Management
- AI Red Teaming/Testing
- Policy Design and Review
- Contract and Agreement Drafting and Review
- Interim DPO

PhD in Data Privacy Law
15 years in Privacy Compliance
20 years in IT Project Management
Certified ISO 27001 and ISO 42001 lead implementer and ISO 27001 lead auditor
Certified AI Trust and Privacy Officer
OneTrust, Securiti and Salesforce certified

• AI governance and ethics (expert ISO 42001, 42005 and 23894)
• Change management and training (AI literacy)
• Impact and risk assessments (PIA, TIA, LIA, AI ACT)
• Risk Analysis against AI Act and GDPR
• Maturity Audit
• Gap Analysis
• Due Diligence
• Certification Audit (27K, 42K)
• Data inventory and RoPA updates
• Remediation Plan
• Process Automation (DSR responses)
• Data classification, labeling and deletion
• Software setup, deployment and administration (OneTrust and Securiti certified)
• IT project management
• AI red teaming
• Policy design and review
• Contract and agreement drafting and review
• Interim DPO
  • French

    Native or bilingual

  • English

    Fluent

  • Spanish

    Conversational

Can work on-site
Paris (up to 50km), Lyon (up to 10km), Toulouse (up to 10km), Lille (up to 10km), Marseille (up to 10km)

Experience

  • Décathlon Digital
    Privacy and AI Governance Consultant
    E-COMMERCE
    June 2026 - Today (2 months)
    Paris, France
    - Support for Product and IT teams in deploying the Privacy By Design framework
    - Support for Product Owners in producing deliverables, participation in DPIAs in coordination with digital security managers, keeping the data processing register up-to-date.
    - Facilitation of Product Owner and Privacy/Compliance Manager communities
    - Production of awareness materials on Privacy and AI compliance, facilitation of awareness sessions.
    - Inventory of AI systems and assessment of their compliance level.
    - Creation and deployment of a framework for responsible and compliant AI and integration into the Compliance By Design framework
    - Harmonization of impact assessment methodologies across data regulations (GDPR, Data Act, etc.) and AI Act in collaboration with digital security managers.
    AI Governance AI Literacy GDPR Implementation GDPR Awareness GDPR Consulting
  • Groupe Agrica
    GDPR Consultant
    BANKING AND INSURANCE
    April 2026 - June 2026 (2 months)
    - Review and validation of the plan, questionnaires, and results of the internal GDPR audit
    - Analysis of the framework, evidence and documents to be collected, and interview questionnaires
    - Analysis of interview reports and provided documents
    - Review and validation of recommendations
    GDPR Audit GDPR Consultant GDPR Consulting Data Protection Officer
  • Luxembourg National Data Service
    AI Governance Consultant
    PUBLIC SECTOR
    October 2025 - March 2026 (5 months)
    Luxembourg, Luxembourg
    - Use of the ISO 42001 framework to develop AI governance
    - Inventory of AI uses and integration into the GDPR register
    - Risk analysis according to ISO 42001 based on ISO 23894 recommendations
    - Development of the AI Impact Assessment based on ISO 42005 recommendations
    - Drafting of the AI policy
    - Definition of the responsible AI training program
    AI Governance ISO 42001

Recommendations

Be the first to recommend Eric

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • PhD in Law
    Tilburg University
    2019
    Privacy law

Certifications

Skill set

Categories