You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Hugo SalardHS

Hugo Salard

External DPO | GDPR & AI Act Lawyer • 9 years

€900/day
1 project
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Hugo

Looking for aDPO**, do you have an **AI project**, a **GDPR audit**, an **AI Act complianceto carry out? You really need an expert pilot of the subject, not to be sold an 80-page report?

Lawyer at the Paris Bar, CIPP-E certified, I have spent 9 years assisting large groups with their GDPR and AI compliance issues:BNP Paribas, LVMH, AESIO Mutuelle(3,000 employees),Groupe Roullier, Les Echos–Le Parisien, etc.

Immediately available. Let's talk about it.

MY SKILLS

DPO & Governance
• External DPO (press, luxury, B2B SaaS)
• Structuring the DPO relay network
• Advice to the DPO

GDPR Audit and Compliance
• Flash or full audit, prioritized action plan
• Documentary framework (policies, procedures, notices, accountability)
• Data controller and processor registers
• Data retention framework
• Technical and organizational security measures

AI Act and AI Compliance
• Legal framework for AI use cases
• AI Act role and classification analysis
• Vendor AI review and GDPR x AI Act articulation

Impact Assessment (DPIA)
• CNIL and EDPB methodology

GDPR Operations
• Data Subject Access Requests (DSAR)
• Data breach management and notification
• International transfers (standard contractual clauses, TIA)
• Contractual analysis (DPA, Article 28 agreements)

Cookies, Consent, Marketing
• Consent Management Platform: tool selection and legal setup
• GDPR / ePrivacy / CNIL guidelines articulation
• Redesign of purposes and legal bases for prospecting

GDPR Tools
• DASTRA, OneTrust, Didomi

Training
• DPO and relays
• Employee awareness
• Sector-specific modules (marketing, retail, HR)


Sectors covered
Banking, mutual insurance, press, luxury, ad tech, mobile gaming, agri-food, event management, B2B SaaS.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km), Niort (up to 50km), Bordeaux (up to 50km), Lyon (up to 50km), Marseille (up to 50km)

Experience

  • AESIO MUTUELLE
    Expert GDPR Consultant - DASTRA Implementation Project Manager
    BANKING AND INSURANCE
    September 2025 - March 2026 (6 months)
    Niort, France
    Context: Structuring and industrializing GDPR compliance management for a mutual insurance group handling health data (Article 9 GDPR).

    • Piloted the tender for a GDPR management tool: drafted specifications, defined evaluation criteria, interviewed vendors, negotiated contracts, and selected DASTRA.
    • Designed the company-wide deployment project: steering committees (COPIL, COPROJ), project scope, multi-year roadmap, identification and onboarding of key stakeholders (DPO, CIO, business units, legal).
    • Implemented and deployed SSO in conjunction with the IT department: access architecture, role and authorization governance, compliance with group security requirements.
    • Managed and monitored the implementation of the three core modules (Record of Processing Activities, Data Subject Requests, Data Breaches): configuration, testing, user training, change management.

    Results:

    • Successful tool migration: over 30 employees impacted and trained (DPO, business privacy representatives, legal).
    • Over 250 data processing activities migrated and structured in the new record.
    • Industrialized processing of data subject requests and breaches: centralized management, auditable traceability, controlled timelines.
    • Overall optimization of GDPR compliance management: +30% efficiency (ROI).
    GDPR GDPR DPO GDPR Project Manager Archives
  • AESIO MUTUELLE
    Expert GDPR Consultant - "Consent" Project Manager
    BANKING AND INSURANCE
    April 2023 - August 2025 (2 years and 4 months)
    Paris, France
    Context: End-to-end redesign of the marketing consent system for a mutual insurance group, based on a massive multi-channel contact base, with strict alignment to CNIL guidelines on commercial prospecting.

    • Legal redesign of communication purposes: analysis of legal bases (Article 6 GDPR), redefinition of the multi-channel consent journey (email, SMS, push, mail), alignment with CNIL recommendations on consent and commercial prospecting.
    • Operational implementation at the IT level (CRM - API - Didomi): design of data flows between the group CRM, API layer, and Didomi CMP, management of consent proofs, traceability of user choices, and reversibility.
    • Change management: onboarding of marketing, compliance, and IT departments, arbitration of conflicts between legal requirements and operational business needs.
    • Operational deployment and team training: migration plan, functional testing, post-production support, training of marketing and CRM teams on new purposes.

    Results:

    • 8 new communication purposes structured, documented, and translated into the CMP.
    • Consent migration for over 10 million contact records, without service interruption.
    • Compliance of the commercial prospecting system with GDPR and CNIL guidelines.
    GDPR Compliance CNIL GDPR Audit GDPR Project Manager GDPR Expert GDPR Training
  • AESIO MUTUELLE
    Expert GDPR Consultant - Data Purge Project Manager
    BANKING AND INSURANCE
    February 2023 - June 2024 (1 year and 4 months)
    Niort, France
    Context: Management of the "paper archives" component of a vast personal data purge program (digital + paper) for AESIO Mutuelle, covering HR and finance departments, deployed across the entire group's property portfolio.

    • Design of the group's Archiving Policy: retention rules, purge procedures, destruction traceability, alignment with sectoral legal obligations (Mutual Insurance Code, labor law, accounting and tax obligations).
    • Update of the data retention framework: exhaustive review by document type, legal validation, formalization in an operational framework for business units.
    • Operational coordination of purging across 38 sites: planning, logistical organization, coordination with archiving and certified destruction service providers.
    • Project management and steering committees: monitoring of progress indicators, facilitation of steering and technical committees, reporting to the compliance department.

    Results:

    • 10 km of paper archives purged in accordance with the group's framework.
    • Archiving policy adopted and deployed across all HR and finance domains.
    • Updated and legally binding data retention framework for business units.
    • Reduced GDPR risks (Article 5.1.e, retention limitation) and physical archiving costs.
    GDPR Project Manager GDPR Compliance GDPR Expert CNIL GDPR Audit GDPR Training

Reviews

5.0

Out of 1 rating

J

Jérôme

easiware

Reviewed on 7/28/2021

Recommendations

FU
FU
FU
+8
Former user and 10 other people have recommended Hugo

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Certificate of Aptitude for the Legal Profession (CAPA)
    EFB
    2017
    Promotion 2016-2017 Ana Palacio & Guido Raimondi
  • Master 2 Multimedia and IT Law
    Université Panthéon Assas (Paris II)
    2014
    Mémoire : "Le projet de Règlement européen sur la protection des données personnelles"

Certifications

  • CIPP-E
    International Association of Privacy Professionals
    2018
    DPO GDPR GDPR
  • OneTrust Data Mapping Expert
    OneTrust
    2018
    Project Management OneTrust GDPR GDPR

Skill set

Categories