You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Quentin MouilhaudQM

Quentin Mouilhaud

Legal Ops & GRC Consultant | Tech Lawyer

€380/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Quentin

A graduate of the Sorbonne in Business Law and holder of a Master's in Hotel Management, I offer a rare dual expertise: legal rigor combined with concrete technical mastery.

Unlike traditional consultants, I don't just write regulations; I understand the technical architecture that supports them. Recently certified eJPT (Junior Penetration Tester) and passionate about automation, I build the necessary bridges between your legal and technical departments.
  • French

    Native or bilingual

  • English

    Native or bilingual

  • Spanish

    Native or bilingual

  • German

    Conversational

  • Chinese

    Fluent

  • Thai

    Basic

Remote only
Primarily works remotely

Experience

  • [Redacted]
    "Privacy by Design" Conception of a Health E-Platform (GDPR & DPA)
    SOFTWARE PUBLISHING
    January 2024 - January 2026 (2 years)
    Technical development and complete legal compliance of a patient management platform for a medical practice operating internationally (France/Philippines).

    The Challenge: Create a technical architecture for handling sensitive data (health) while adhering to a strict dual regulatory constraint: GDPR (Europe) and the Data Privacy Act of 2012 (Philippines).

    Legal Ops & Tech Achievements:

    "Privacy by Design" Architecture: Translating legal obligations directly into the database architecture (segregation of identity and medical data).

    Security & Encryption: Technical implementation of data encryption at rest and in transit (SSL/TLS, AES) to ensure doctor-patient confidentiality.

    Consent Management (CMP): Development of the granular consent collection module (opt-in) required for health data processing.

    Cross-border Compliance: Mapping data flows and selecting compliant hosting providers according to data sovereignty standards to prevent illicit transfers outside secure zones.

    Audit Trail (Audit Logs): Coding an unalterable logging system to track who accesses which patient file (major legal requirement).
    GDPR Implementation Cybersecurity Strategy GRC Cybersecurity Project Management
  • [Redacted]
    Technical Due Diligence Audit & GDPR Compliance for a SaaS Project
    SOFTWARE PUBLISHING
    April 2023 - April 2025 (2 years)
    A client (Tech/Digital sector) wished to integrate a critical third-party solution (API/SaaS) for their business. Before signing the contract and the DPA (Data Processing Agreement), the client needed to verify if the security guarantees provided by the vendor matched the technical reality.

    My Achievements
    I acted as the technical trusted third party between the Legal Department and the IT Department to validate the security of the future partner.

    Black Box Security Audit: Preliminary analysis of the vendor's API and web application exposure (Search for OWASP Top 10 vulnerabilities, misconfigured headers, sensitive data exposure).

    Verification of DPA Reality: Confronting contractual security clauses (encryption, location, access) with the observed technical reality. Example: Detection of unencrypted data flows while the contract guaranteed strict HTTPS.

    Data Flow Mapping: Precise identification of data entry and exit points to validate compliance with data transfer requirements (GDPR/Schrems II).

    Decision Support Report: Drafting a hybrid report (legal/technical) recommending specific clauses to be added to the contract to cover the identified technical risks.

    Results
    Identification of 3 critical security flaws before signing.

    Renegotiation of the supplier contract with reinforced security clauses.

    Validation of the technical "Go/No-Go" for General Management.
    GDPR Implementation Cybersecurity Strategy Cybersecurity Digital Visibility Project Management
  • LPP
    Legal Ops & GRC Consultant | Tech Lawyer (Sorbonne) & Certified eJPT | Automation & AI
    January 2016 - Today (10 years and 5 months)
    At the intersection of Business Law, Cybersecurity, and Operations.

    A graduate of the Sorbonne in Business Law and holder of a Master's in Hotel Management, I offer a rare dual expertise: legal rigor combined with concrete technical mastery.

    Unlike traditional consultants, I don't just write regulations; I understand the technical architecture that supports them. Recently certified eJPT (Junior Penetration Tester) and passionate about automation, I build the necessary bridges between your legal and technical departments.

Recommendations

Be the first to recommend Quentin

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master II
    EHG
    2016
    master en management H.
  • Business Law
    Sorbonnes Universite
    Droit des Affaires

Certifications

  • EJPT
    INE
    2025
    Cybersecurity Strategy Professional Ethics Cybersecurity Audit Cybersecurity Cybersecurity Governance Web Pentest PenTest Pentesting

Skill set

Categories