Banking and finance · DORA, ACPR
Three pillars, a tight notification timeline
Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025, requires financial entities to maintain a documented ICT risk management framework: detection (art. 10), major ICT incident reporting (art. 17 to 23), and oversight of critical third-party providers (art. 28 to 30). Delegated Regulation (EU) 2025/301 sets the timeline: initial notification within 4 hours of classifying the incident as major, and no later than 24 hours after detection, an intermediate report within 72 hours, and a final report within 1 month, to the ACPR.
The DataBait dossier, timestamped within 72 hours, feeds that notification chain directly. Continuous monitoring extends to your PSD2 partners (AISP, PISP) and to your critical processors: the oversight duty takes the form of a permanent signal, with no additional audit. And the report supports the follow-up only you can bring: banking secrecy (art. L.511-33 of the French Monetary and Financial Code) binds every employee to article 226-13 of the French Criminal Code.
See the Banking and Finance page
Insurance · DORA, Solvency II
A delegation chain to monitor, an ORSA to feed
DORA applies to insurance and reinsurance undertakings and to their intermediaries (art. 2), with the same three pillars and the same notification timeline to the ACPR. What sets the industry apart is its administration chain: third-party administrators, brokers, and health-payment operators, each one a database entrusted beyond your walls, and the exact vector of the Viamedis and Almerys incident (more than 33 million insured persons exposed, January to February 2024).
The same setup feeds your risk governance under Solvency II: data leak risk, a component of operational risk, stops being a declarative assumption and becomes a measured, documented signal, fed into your ORSA (art. 45 of Directive 2009/138/EC). And as soon as a leak touches health data, the CNIL requirement is heightened under article 9 of the GDPR.
See the Insurance page
Healthcare · health IS incident reporting, NIS2, HDS
Three deadlines running from the same date
Article L.1111-8-2 of the French Public Health Code already requires healthcare organisations to report serious information system security incidents without delay; that report, addressed to the ARS, is passed on to the ANS (CERT Santé). NIS2 also classifies healthcare among the essential entities, with the ANSSI notification timeline described above.
The timestamped alert fixes your date of awareness, the common starting point for these deadlines and for your CNIL notification, under the heightened requirement of article 9 of the GDPR on health data. The report also lets you bring disciplinary proceedings: medical confidentiality (art. L.1110-4 of the French Public Health Code) binds every professional to article 226-13 of the French Criminal Code. One architectural point often decides the matter in committee: because DataBait hosts no patient data, deploying it adds no HDS scope to your information system.
See the Healthcare page
E-commerce · heightened GDPR, marketing, NIS2
Article 34 and the class action risk
In e-commerce, the constraint is not only the 72 hour deadline: it is article 34, which requires you to communicate the breach to every customer concerned where the risk is high, meaning mass notification and immediate exposure to collective redress (class action). The timestamped dossier fixes what you knew and when, the central exhibit in litigation where your diligence will be challenged.
When a third party uses your database for unsolicited marketing, the report establishes the breach under the electronic marketing rules (article L.34-5 of the French Postal and Electronic Communications Code). And if you run an online marketplace, NIS2 classifies you among the important entities (annex II, digital providers), with the corresponding documented framework and ANSSI timeline.
See the E-commerce page
Legal professions · professional secrecy
Diligence to prove without widening the circle of secrecy
Your obligation does not stop at the GDPR: professional secrecy imposes a duty of preservation that extends to your processors, practice software vendors, legaltech providers, signature platforms, hosts, and digitisation providers. Article 28 of the GDPR requires you to select and monitor them with due diligence; DataBait turns that oversight duty into continuous monitoring of every database entrusted.
The data you handle is among the most sensitive there is, including data on offences and convictions (article 10 of the GDPR) in litigation. In a CNIL inspection or professional disciplinary proceedings, the timestamped dossier demonstrates what you knew, when, and what you did about it. And because DataBait accesses none of your case documents, it brings no new third party into the circle of secrecy.
See the Legal Professions page