
GDPR lawyer in Strasbourg
Launching a new service, upgrading your digital tools, negotiating a contract involving personal data or having to react to an incident? Our GDPR law firm in Strasbourg advises companies on their GDPR compliance, their projects involving personal data and their dealings with supervisory authorities, in particular the CNIL.
Cabinet Bouchara & Avocats works with directors, legal departments, DPOs, IT departments and companies in Strasbourg, across the Eurométropole and more widely in the Grand Est region.
We act both upstream of a project and in the event of a data breach, a complaint or an inspection.
GDPR lawyer in Strasbourg: our practice areas
The GDPR now touches much of a company’s day-to-day activity: customer and prospect files, HR data, SaaS tools, applications, video surveillance, IT providers, marketing campaigns and projects using sensitive data.
Specialising in intellectual property law, Cabinet Bouchara & Avocats also handles digital law and data protection matters.
We check the rules applicable to your processing of personal data and their practical consequences for your practices, your contracts and your documentation.
GDPR audit and compliance
A change of tool, an acquisition, the launch of a platform or a change in the business may call for an update of your GDPR compliance.
Our lawyers audit your organisation, your websites and your applications, then define with your teams the actions to be taken as a priority.
Our support may cover:
- mapping the processing activities and updating the record;
- the legal bases for the processing;
- information notices and privacy policies;
- data retention periods;
- access rules and authorisations;
- internal procedures relating to personal data;
- data protection by design and by default;
- the compliance of websites and applications, in particular as regards cookies, trackers and marketing.
The record of processing activities, provided for in article 30 of the GDPR, helps document the organisation’s compliance and serves as a management tool for personal data protection.
IT contracts, GDPR and relations with your providers
Your company entrusts data to a host, an IT provider, a SaaS publisher, an agency or another partner.
The legal role of each party must first be determined: controller, joint controller or processor. The clauses to be included in the contracts depend on that classification.
The firm drafts, reviews and negotiates in particular:
- data processing agreements (DPAs);
- processor clauses provided for in article 28 of the GDPR;
- agreements organising joint controllership;
- clauses relating to security, incidents and audits;
- binding corporate rules (BCRs);
- contractual arrangements framing transfers to third countries;
- codes of conduct relating to data protection.
These matters often draw on our digital law expertise in Strasbourg.
Outsourced DPO, governance and team training
Some companies must appoint a data protection officer. Others choose to appoint one to steer their compliance and support their projects.
Cabinet Bouchara & Avocats acts as outsourced DPO for controllers and processors.
In that capacity, our lawyers support the organisation in monitoring its compliance and its new projects, advise its teams and handle dealings with the CNIL or the other supervisory authorities concerned.
The firm also provides training and awareness sessions on personal data protection.
Exercise of rights and complaints
An access request made by an employee or a former colleague may cover large volumes of emails and documents. An erasure or objection request may also require checking the retention obligations that apply to the company.
Our lawyers assist companies in analysing and handling data subject rights requests: access, rectification, erasure, objection, restriction, portability, as well as directives on what happens to data after death.
We also act where the response has to take account of third-party rights or of legal retention obligations.
DPIA, sensitive data and new projects
Where processing is likely to result in a high risk to the rights and freedoms of individuals, a specific analysis may be required before it is implemented.
The firm assists companies in carrying out data protection impact assessments (DPIAs) and, where the conditions set out in the GDPR are met, in prior consultations with the supervisory authority.
We act in particular on applications, platforms, artificial intelligence projects and services involving the processing of health data or other special categories of data within the meaning of the GDPR.
The firm also assists you with certification procedures or with adherence to a code of conduct on data protection.
International data transfers
Using a cloud provider, a business software package or an international provider, or the organisation of a group operating in several countries, may involve data transfers to countries outside the European Economic Area.
Our lawyers check where the data is accessible and what safeguards must be put in place.
The firm acts in particular on standard contractual clauses, binding corporate rules (BCRs) and the other mechanisms provided for by the GDPR to frame international data transfers.
Personal data breaches
A data breach does not only result from a cyberattack. It may also come from an email sent to the wrong recipient, a document made accessible without authorisation, the loss of a device or an incident at a provider.
The firm acts to characterise the incident, identify the data and the individuals concerned, assess the risks and determine the steps to be taken.
Where notification to the CNIL is required, it must be made without undue delay and, where feasible, no later than 72 hours after the controller became aware of it. If the breach is likely to result in a high risk to the rights and freedoms of the individuals concerned, they must also be informed.
Every breach must be analysed and, for the controller, documented internally, whether or not notification to the CNIL is required.
We also assist the company in its dealings with the CNIL or, where applicable, with another European supervisory authority.
CNIL inspections, formal notices and sanctions
Cabinet Bouchara & Avocats assists companies subject to a CNIL inspection, whether carried out on site, on documents, by hearing or online.
Our lawyers prepare the responses and observations sent to the CNIL and assist the company throughout the inspection.
We also assist the company in the event of a formal notice or in sanction proceedings.
A formal notice is not itself a sanction, but it requires the organisation concerned to remedy the identified shortcomings within the time limit set.
Personal data litigation
The firm acts both for claimants and for defendants in personal data protection litigation.
Our lawyers handle in particular disputes between controllers and processors, appeals against supervisory authority decisions and litigation relating to the protection of personal data.
The firm also assists organisations not established in the European Union where they are caught by the GDPR.
Examples of matters handled by the firm in Strasbourg
Bringing a website into compliance after a redesign
A company had completely redesigned its website and integrated new audience measurement and marketing tools.
When reviewing the site, the firm found that some trackers were being placed before consent was obtained and that the information presented on the site no longer matched the processing actually carried out. The firm revised the information notices and the cookie management system.
Securing a digital project in the healthcare sector
The firm assisted a company developing a digital service using health data.
Before the service was launched, our lawyer reviewed the conditions under which the data was collected and used, its hosting and the contracts with the technical providers. An impact assessment was also carried out given the nature of the data processed.
Organising the data flows of a French-German group
A company based in Strasbourg wanted to centralise certain tools used by its French and German teams, in particular for managing staff and commercial relationships.
The firm supported the roll-out of this new organisation in order to clarify the data flows between the various companies in the group and the involvement of several technical providers in countries outside the European Economic Area.
GDPR litigation before the Strasbourg judicial court
The firm acted for a Strasbourg company in a dispute over the use of personal data in a commercial relationship.
The opposing party contested in particular the retention of certain data and its use after the end of the contractual relationship. The case was brought before the Strasbourg judicial court.
The firm defended the company on the conditions under which the data was processed, the information provided to the individuals concerned and the obligations laid down by the GDPR.
A GDPR law firm in Strasbourg
Cabinet Bouchara & Avocats welcomes companies at its Strasbourg office:
Cabinet Bouchara & Avocats — Strasbourg
From Strasbourg, our team assists companies in the Eurométropole, the Bas-Rhin and the Grand Est, including where their activities have a European or international dimension.
Awards
Cabinet Bouchara & Avocats is recognised in particular for its data law, cybersecurity and digital law practices.
Décideurs | Leaders League 2026 — Data law and cybersecurity
Cabinet Bouchara & Avocats — “Forte notoriété”.
Décideurs | Leaders League 2026 — Digital platform and application law
Cabinet Bouchara & Avocats — “Forte notoriété”.
Personal data and digital law team
FAQ
Can our in-house DPO call on the firm for a complex matter?
Yes. The firm can act alongside your DPO on a specific legal question, a new processing operation, a DPIA, a contract, a transfer of data to a third country or proceedings with a supervisory authority.
Your DPO stays in place; we only step in on the matters that call for legal advice or assistance.
Can we instruct you for an audit or a specific GDPR project only?
Yes. You can instruct us on a one-off basis without outsourcing your entire GDPR compliance.
Our lawyers act, for example, to carry out a targeted audit, review a contract with a provider, secure a new processing operation, carry out a DPIA or prepare a response to the CNIL.
Why call on a lawyer rather than a GDPR consultant?
The GDPR very often raises questions of contract, liability or litigation, beyond internal documentation alone.
A lawyer can therefore advise the company upstream, assist it and/or defend it if a dispute or proceedings arise.
Can the firm check the GDPR compliance of our processors?
Yes. The firm can review the safeguards offered by a processor, its contractual undertakings, the conditions under which it uses other providers and any data transfers linked to the service used.
We flag the clauses or practices to be corrected before the contract is signed or during its performance.
Can the firm act quickly in the event of an inspection or an incident?
Yes. If your company has received a request from the CNIL or discovers a data breach, certain steps must be taken quickly. The firm acts to analyse the situation, organise the response to the CNIL with your teams or assess and manage the incident, taking the applicable deadlines into account.
Do you have a question about your compliance or a project involving the processing of personal data?


