Your privacy expertise at your service
GDPR & EU AI Act

Phénix Privacy helps organisations comply privacy and AI laws with a pragmatic, business-first approach, from GDPR compliance to AI Act readiness.

Pragmatic

Certified Experts

Proven methodology

Trusted by leading organisations

Our GDPR and AI ACT experts support a wide range of businesses and organisations in ensuring their compliance. Whether they are SMEs, large corporations, local authorities or associations, they all rely on us to safeguard their data, deploy trusted AI, and ensure compliance with legal requirements.

WHY ACT NOW

The regulatory landscape is evolving
and challenging

Compliance is not just a legal box to tick, It is a strategic asset that builds customer trust and reduces business risk. Phénix Privacy turns regulatory obligation into competitive advantage.

GDPR fines can reach
€20M or 4% of global turnover

Most organisations are partially compliant, but partially compliant is not enough compliant. Regulators are increasing their enforcement activity across Europe raising compliance level expected from all.

The EU AI Act is now in force

If you deploy or use AI systems, obligations already apply to you. AI requirements apply since february 2025. Anticipation is key.

Our services

A complete approach
GDPR and AI Act

Our services

Our custom-made approach ensures that your projects’ personal data is protected to the appropriate standard and that you have adequate control over the AI systems you use.

WHY PHÉNIX PRIVACY

More than a provider,
a business partner

Our Pragmatic approach

Whether you are a business or a public body, we support you in your efforts to comply with the GDPR through a structured approach. We provide you with a methodology, tools and expertise tailored to your sector and business goal.

We coordinate the process with business stakeholders and technical experts (CIOs, CISO).

Our aim is to enhance and secure your information assets!

…unique

What sets us apart

We are a firm of privacy specialists

All our experts hold a relevant university degree in privacy and are certified as Data Protection Officers (DPOs).

 

A team close to you

Standard or tailored programs, in-house or outsourced, we adapt our approach to your teams, your organisation’s needs, and your level of compliance maturity.

 

Extensive experience and proven methods

We have supported more than two hundreds different organisations across sectors such as healthcare, transport, industry, banking, mutual insurance, medical and social services, and the charitable sector.

 

A network of partners

We collaborate with a network of partners who work alongside us on issues related to the GDPR: cybersecurity, consent collection, and GDPR monitoring and management tools.

HOW WE WORK

A structured, pragmatic approach

Tailored to your organisation: from first audit to daily monitoring and tracking.

Step 1
Step 1

Audit & gap analysis

Review existing practices to identify non-compliance points.

Step 2
Step 2

Risk mapping

Evaluate risks for each processing activity, human and technical.

Step 3
Step 3

Compliance roadmap

Define a prioritised action plan and build a compliance programme.

Step 4
Step 4

Implementation

Compliance documentation, accountability procedures, policies, data processing agreements and training.

Step 5
Step 5

Ongoing monitoring

Continuous improvement to maintain compliance and track regulation framework evolutions over time.

THE TEAM

The people behind Phénix Privacy

Founded in 2023 by two certified privacy experts working together since 2017. Independent, pragmatic, and committed to your success. Based in Lyon, serving clients across Europe.

Céline Gallay, Managing Director, holds a Master’s degree in Law (from Lyon II University) and is CNIL and IAPP certified. In 2025, she qualified as a Digital Ethics Officer at EDHEC Business School.
After more than 10 years as a corporate lawyer, she is responsible for quality assurance and oversees the firm’s operations.

Sylvain Chemtob, Chairman, holds a law degree (Master’s in Law from Paris II Panthéon Assas University) and is a graduate of Audencia Business School. He is IAPP certified.
After more than 15 years working for several IT and management consultancy firms, he oversees support functions and manages the firm.

OUR ECOSYSTEM

A network of complementary specialists

To ensure that we provide high-quality support level, we work with partners specialising in cybersecurity, digital law and data governance. Our GDPR experts also work closely with solicitors, legal professionals and providers of compliance solutions to deliver comprehensive solutions tailored to the needs of each business.

Our partnerships with certification bodies and recognised institutions enable us to offer solutions that comply with the latest legal and technical developments. This approach allows us to provide a comprehensive service, focused on the protection of personal data and trusted AI, encompassing expertise, methodology and tools.