In 2019, one of several major service contracts behind the call centers of France’s largest legal-protection groups came under a test it could not avoid. Under the obligations of the General Data Protection Regulation (GDPR), the client, Groupama Protection Juridique, imposed a compliance audit of every process tied to the service and sent in specialized consultants from EY to run it. I worked for Juritravail, the legal-tech subsidiary whose subcontracting activity ran those call centers; it lived on a handful of such contracts.
Three constraints shaped the work:
- A 70-person entity held to the standard of a large legal-protection client.
- Services delegated to, and pooled inside, the parent group, so not every process sat under one roof.
- A contract kept long-term only by passing the audit.
- Almost no headroom: two people to carry the response, on top of their day jobs.
If you have faced an external audit that sets the bar for an operation you cannot refuse and cannot staff for, this is vision to execution. I was already the group’s GDPR project manager, so I was put in direct charge of the response, backed by the parent group’s data protection officer (DPO).
TL;DR
A legal-protection client imposed a GDPR-driven audit of every process behind a service contract the entity could not afford to lose. I ran the response with the group’s DPO, on a method already proven inside the group. The contract was validated, and the documentation outlived the audit.
The diagnosis: a bar that had never been demanded
The presenting symptom was an audit that had to pass. The real cause was not negligence. The standard Juritravail had met as a subsidiary of the parent group, during its initial GDPR work, was a lower bar than a dedicated legal-protection entity of Groupama Protection Juridique’s size required. That level of documented, auditable process had never been asked of this entity, and no internal precedent or template existed to copy from.
What I decided, and what I ruled out
I chose to run the response as a project, not a scramble. The method was not improvised: I reused the Scrum approach already proven during the group’s own GDPR rollout, which this site tells as its own case study, and the shape of the work followed from it:
- Split the load with the parent group’s DPO, who carried the response with me.
- Gather the digital documentation that already existed, before deciding what to write.
- Attend the auditor’s interviews, and note every point where their expected level was higher than the standard already in place.
- Work in iterations with the consultants, so they had what they needed to establish their report.
The option I rejected was the confrontational or stalling posture toward the auditor. Staying collaborative from the start was the only way the consultants could build their compliance and maturity report; a report built in friction is not one you can repair afterward.
What was actually built
The output was a two-person audit-response machine: the DPO and I split the work, assembled the existing documentation, and ran the response in agile iterations. Concretely:
- Assembling every digital document already available, then writing what was missing.
- Convening ad hoc meetings with the EY consultants and the head of the assisted service wherever questions kept bouncing around the organization.
- Delivering remediation against deadlines negotiated with the client, accounted for through reports and additional documentation, with a client-side delegate keeping the dialogue open.
The durable piece was the documentation itself, strengthened under Confluence and managed as Scrum sprints under Jira. Together they became a system, not a one-off folder.
What broke, and what it cost
The friction was real. The earlier standard did not reach the level a dedicated legal-protection entity needed, so the bar had to be raised for this one subsidiary, with a thinner resource pool than the task deserved. The auditor’s report flagged subjects to strengthen, so this was not a clean first pass. And the effort sat on two people, on top of their day jobs.
The outcome, with its status
Two results are measured. The service contract was validated once everything was cleared. The chief executive officer (CEO) was practically never solicited during the operation, which kept his attention on the business stakes he was carrying. One result is qualitative: afterward, the reinforced documentation and the sprint machine let the DPO and me answer later audits from other legal-protection clients with more ease and less time. No figure exists for that gain, and I will not invent one. That documentation now sits in the wider compliance portfolio on the about page.
If this is the shape of your problem, let’s talk.

