You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Hugo SalardHS

Hugo Salard

External DPO | GDPR & AI Act Consultant • 9 years

€900/day
1 project
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Hugo

Are you looking for aDPO**, do you have an **AI project**, a **GDPR audit**, an **AI Act complianceto carry out? Do you really need an expert pilot on the subject, not just an 80-page report?

With a legal background (CAPA, Paris Bar), CIPP-E certified, I have spent 9 years supporting large groups on their GDPR and AI Act compliance issues:BNP Paribas, LVMH, AESIO Mutuelle(3,000 employees),Groupe Roullier, Les Echos–Le Parisien, etc.

Available immediately. Let's talk.

MY SKILLS

DPO & Governance
• External DPO (press, luxury, B2B SaaS)
• Structuring the DPO relay network
• DPO consulting

GDPR Audit and Compliance
• Flash or full audit, prioritized action plan
• Documentary framework (policies, procedures, notices, accountability)
• Controller and processor registers
• Data retention framework
• Technical and organizational security measures

AI Act and AI Compliance
• Legal framework for AI use cases
• AI Act role and classification analysis
• Vendor AI review and GDPR x AI Act articulation

Impact Assessment (DPIA)
• CNIL and EDPB methodology

GDPR Operations
• Data Subject Access Requests (DSAR)
• Data breach management and notification
• International transfers (Standard Contractual Clauses, TIAs)
• Contractual analysis (DPAs, Article 28 agreements)

Cookies, Consent, Marketing
• Consent Management Platform: tool selection and legal setup
• GDPR / ePrivacy / CNIL guidelines articulation
• Redesign of prospecting purposes and legal bases

GDPR Tools
• DASTRA, OneTrust, Didomi

Training
• DPO and relays
• Employee awareness
• Sector-specific modules (marketing, retail, HR)

Sectors Covered
Banking, mutual insurance, press, luxury, ad tech, mobile gaming, agri-food, events, B2B SaaS.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km), Niort (up to 50km), Bordeaux (up to 50km), Lyon (up to 50km), Marseille (up to 50km)

Experience

  • AESIO MUTUELLE
    Expert GDPR Consultant - DASTRA Implementation Project Manager
    BANKING AND INSURANCE
    September 2025 - March 2026 (6 months)
    Niort, France
    Context: Structuring and industrializing GDPR compliance management for a mutual insurance group handling health data (GDPR Article 9).

    • Managed the GDPR data management tool tender: drafted specifications, defined evaluation criteria, interviewed vendors, negotiated contracts, and selected DASTRA.
    • Designed the company-wide deployment project: steering committees (COPIL, COPROJ), project scope, multi-year roadmap, identification and onboarding of key stakeholders (DPO, IT, business units, legal).
    • Implemented and deployed SSO in conjunction with the IT department: access architecture, roles and permissions governance, compliance with group security requirements.
    • Managed and monitored the implementation of the three core modules (Record of Processing Activities, Data Subject Requests, Data Breaches): configuration, testing, user training, change management.

    Results:

    • Successful tool migration: over 30 employees trained (DPOs, business privacy representatives, legal).
    • Over 250 data processing activities migrated and structured in the new record.
    • Industrialized processing of data subject requests and breaches: centralized management, auditable traceability, controlled deadlines.
    • Overall optimization of GDPR compliance management: +30% efficiency (ROI).
    GDPR GDPR DPO GDPR Project Manager Archives
  • AESIO MUTUELLE
    Expert GDPR Consultant - "Consent" Project Manager
    BANKING AND INSURANCE
    April 2023 - August 2025 (2 years and 4 months)
    Paris, France
    Context: End-to-end redesign of a mutual insurance group's marketing consent system, covering a large, multi-channel contact base, with strict alignment to CNIL guidelines on commercial prospecting.

    • Legal redesign of communication purposes: analysis of legal bases (GDPR Article 6), redefinition of the multi-channel consent process (email, SMS, push, mail), alignment with CNIL recommendations on consent and commercial prospecting.
    • Operational implementation within the IT system (CRM - API - Didomi): design of data flows between group CRM, API layer, and Didomi CMP, management of consent proofs, traceability of user choices and reversibility.
    • Change management: onboarding of marketing, compliance, and IT departments, arbitration of conflicts between legal requirements and operational business needs.
    • Operational deployment and team training: migration plan, functional testing, post-production support, training of marketing and CRM teams on new purposes.

    Results:

    • 8 new communication purposes structured, documented, and translated in the CMP.
    • Migration of consent for over 10 million contact records, without service interruption.
    • Compliance of the commercial prospecting system with GDPR and CNIL guidelines.
    GDPR Compliance CNIL GDPR Audit GDPR Project Manager GDPR Expert GDPR Training
  • AESIO MUTUELLE
    Expert GDPR Consultant - Data Purge Project Manager
    BANKING AND INSURANCE
    February 2023 - June 2024 (1 year and 4 months)
    Niort, France
    Context: Management of the "paper archives" component of a large personal data purge program (digital + paper) for AESIO Mutuelle, covering HR and finance departments, deployed across the group's entire real estate portfolio.

    • Design of the group's Archiving Policy: retention rules, purge procedures, destruction traceability, alignment with sectoral legal obligations (Mutual Insurance Code, labor law, accounting and tax obligations).
    • Update of the data retention framework: exhaustive review by document type, legal validation, formalization into an operational framework for business units.
    • Operational coordination of the purge across 38 sites: planning, logistical organization, coordination with archiving and certified destruction providers.
    • Project management and steering committees: tracking progress indicators, facilitating steering and technical committees, reporting to the compliance department.

    Results:

    • 10 km of paper archives purged in accordance with the group's framework.
    • Archiving policy adopted and deployed across all HR and finance departments.
    • Data retention framework updated and enforceable by business units.
    • Reduction of GDPR risks (Article 5.1.e, retention limitation) and physical archiving costs.
    GDPR Project Manager GDPR Compliance GDPR Expert CNIL GDPR Audit GDPR Training

Reviews

5.0

Out of 1 rating

J

Jérôme

easiware

Reviewed on 7/28/2021

Recommendations

JA
MC
FU
+8
Joseph Aubry and 10 other people have recommended Hugo

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Certificate of Aptitude for the Legal Profession (CAPA)
    EFB
    2017
    Promotion 2016-2017 Ana Palacio & Guido Raimondi
  • Master 2 Multimedia and IT Law
    Université Panthéon Assas (Paris II)
    2014
    Mémoire : "Le projet de Règlement européen sur la protection des données personnelles"

Certifications

  • CIPP-E
    International Association of Privacy Professionals
    2018
    DPO GDPR GDPR
  • OneTrust Data Mapping Expert
    OneTrust
    2018
    Project Management OneTrust GDPR GDPR

Skill set

Categories