Compliance

Your compliance stops being declarative

Your regulatory obligations rest on dates, deadlines, and proof. DataBait gives you all three: every alert is sealed by a qualified eIDAS timestamp that puts an enforceable date on the signal from which your date of awareness runs, every signal is consolidated into court-admissible proof within 72 hours, and together they form the file you will produce in an inspection. What you knew, when you knew it, and what you did about it.

  • Qualified eIDAS timestamp
  • AFNOR NF Z67-147 report
  • SecNumCloud-qualified hosting (ANSSI)

Starting point

An enforceable date of awareness

The GDPR requires you to notify a personal data breach to the CNIL within 72 hours (article 33) and, where the risk to the individuals concerned is high, to communicate it to them (article 34). That deadline does not run from the leak itself: it runs from the moment you became aware of it.

That starting point is precisely what is hard to establish after the fact, and it is what the supervisory authority examines. DataBait makes it certain: every alert is sealed by a qualified eIDAS timestamp, issued by a QTSP on the EU Trusted List. Under article 41 of the eIDAS Regulation, that timestamp enjoys a legal presumption of validity throughout the European Union.

You no longer declare the date on which you discovered the incident: you prove it. And because the alert waits for neither a customer complaint nor the publication of a dump, that starting point comes early, while the 72 hour deadline is still comfortable.

What you document

Detection, incident dossier, third-party monitoring

Every digital risk management regime, sector-specific or cross-sector, rests on the same three requirements. DataBait tools all three by construction, from the same setup.

A documented detection capability

The fictitious accounts DataBait injects into your databases match no real person. Any contact they receive is therefore illegitimate by construction: detection is continuous, enforceable, and with no structural false positives. It complements your perimeter defences, which remain blind to what is done with your data once it has left your information system.

A timestamped incident dossier within 72 hours

Signals are then consolidated, on request, into a commissaire de justice report compliant with the AFNOR NF Z67-147 standard, drawn up within 72 hours and sealed by a qualified eIDAS timestamp. The dossier can be used directly for your notifications to supervisory authorities, and it constitutes court-admissible proof if you bring an action.

Continuous monitoring of your processors

Article 28 of the GDPR requires you to select your processors with due diligence and to monitor their performance. By injecting fictitious accounts dedicated to each database you entrust, DataBait turns that oversight duty into a permanent signal: you no longer wait for the annual audit to learn what became of a shared database.

Compliance stops being an annual deliverable: it becomes a continuous posture, timestamp-sealed at every alert.

Cross-sector regime

NIS2 applies whatever your industry

Directive (EU) 2022/2555 (NIS2) extends the European cybersecurity regime well beyond the historic operators and classifies the entities covered as essential entities or important entities according to their sector and size.

Its transposition into French law (the Résilience bill) will require the entities covered to put in place a documented digital risk management framework, a notification timeline to ANSSI, and an obligation to keep control of the subcontracting chain.

24 h
Early warning
72 h
Notification
1 month
Final report

The three pillars above answer these requirements directly: documented detection for the risk management framework, the incident dossier timestamped within 72 hours for the notification timeline, and continuous monitoring of entrusted databases for control of the chain. With no additional audit, and no change to your information system.

Internal compliance

Your own gaps before anyone else's

DataBait is not only there to document a third party's abuse. It makes your own compliance gaps visible while they can still be fixed.

A campaign sent without opt-in, a sender outside the allowlist defined by your CISO or your DPO, data collected for one purpose and reused for another: these gaps happen inside your own organisation, with no fraudulent intent, and today they trigger no signal at all.

The fictitious accounts make them visible at the first contact. The signal comes back to you, and to you alone: you keep control of your processes and fix the gap before it becomes a notifiable incident.

Scope

What DataBait proves, and what it does not

Proof is only worth something if its scope is stated unambiguously. Three limits we set ourselves.

Detection

DataBait detects and proves, it does not prevent

DataBait establishes that a leak occurred and documents the use made of your data once it has left your information system. It replaces neither your security measures nor your security obligation under article 32 of the GDPR. Only dark web scanning operates upstream of any contact: it reveals a distributed database before it is exploited.

Attribution

Attribution requires segmented databases

On a single database shared with several providers, a contact received proves the misappropriation but does not identify who did it. To identify the third party behind a leak, the database must be segmented by recipient and dedicated fictitious accounts injected into each segment. This is a design condition, decided with you at deployment.

Notification

The notification remains yours

DataBait produces the dossier; assessing whether the breach is notifiable, qualifying its severity, and reporting it to the supervisory authority are for you and your DPO. We supply the evidentiary material, not the regulatory decision.

By industry

What your own regime requires

The GDPR and NIS2 baseline applies to everyone. Five industries are additionally subject to a regime of their own, adding its authorities, its deadlines, and its third-party monitoring obligations.

Banking and finance · DORA, ACPR

Three pillars, a tight notification timeline

Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025, requires financial entities to maintain a documented ICT risk management framework: detection (art. 10), major ICT incident reporting (art. 17 to 23), and oversight of critical third-party providers (art. 28 to 30). Delegated Regulation (EU) 2025/301 sets the timeline: initial notification within 4 hours of classifying the incident as major, and no later than 24 hours after detection, an intermediate report within 72 hours, and a final report within 1 month, to the ACPR.

The DataBait dossier, timestamped within 72 hours, feeds that notification chain directly. Continuous monitoring extends to your PSD2 partners (AISP, PISP) and to your critical processors: the oversight duty takes the form of a permanent signal, with no additional audit. And the report supports the follow-up only you can bring: banking secrecy (art. L.511-33 of the French Monetary and Financial Code) binds every employee to article 226-13 of the French Criminal Code.

See the Banking and Finance page

Insurance · DORA, Solvency II

A delegation chain to monitor, an ORSA to feed

DORA applies to insurance and reinsurance undertakings and to their intermediaries (art. 2), with the same three pillars and the same notification timeline to the ACPR. What sets the industry apart is its administration chain: third-party administrators, brokers, and health-payment operators, each one a database entrusted beyond your walls, and the exact vector of the Viamedis and Almerys incident (more than 33 million insured persons exposed, January to February 2024).

The same setup feeds your risk governance under Solvency II: data leak risk, a component of operational risk, stops being a declarative assumption and becomes a measured, documented signal, fed into your ORSA (art. 45 of Directive 2009/138/EC). And as soon as a leak touches health data, the CNIL requirement is heightened under article 9 of the GDPR.

See the Insurance page

Healthcare · health IS incident reporting, NIS2, HDS

Three deadlines running from the same date

Article L.1111-8-2 of the French Public Health Code already requires healthcare organisations to report serious information system security incidents without delay; that report, addressed to the ARS, is passed on to the ANS (CERT Santé). NIS2 also classifies healthcare among the essential entities, with the ANSSI notification timeline described above.

The timestamped alert fixes your date of awareness, the common starting point for these deadlines and for your CNIL notification, under the heightened requirement of article 9 of the GDPR on health data. The report also lets you bring disciplinary proceedings: medical confidentiality (art. L.1110-4 of the French Public Health Code) binds every professional to article 226-13 of the French Criminal Code. One architectural point often decides the matter in committee: because DataBait hosts no patient data, deploying it adds no HDS scope to your information system.

See the Healthcare page

E-commerce · heightened GDPR, marketing, NIS2

Article 34 and the class action risk

In e-commerce, the constraint is not only the 72 hour deadline: it is article 34, which requires you to communicate the breach to every customer concerned where the risk is high, meaning mass notification and immediate exposure to collective redress (class action). The timestamped dossier fixes what you knew and when, the central exhibit in litigation where your diligence will be challenged.

When a third party uses your database for unsolicited marketing, the report establishes the breach under the electronic marketing rules (article L.34-5 of the French Postal and Electronic Communications Code). And if you run an online marketplace, NIS2 classifies you among the important entities (annex II, digital providers), with the corresponding documented framework and ANSSI timeline.

See the E-commerce page

Legal professions · professional secrecy

Diligence to prove without widening the circle of secrecy

Your obligation does not stop at the GDPR: professional secrecy imposes a duty of preservation that extends to your processors, practice software vendors, legaltech providers, signature platforms, hosts, and digitisation providers. Article 28 of the GDPR requires you to select and monitor them with due diligence; DataBait turns that oversight duty into continuous monitoring of every database entrusted.

The data you handle is among the most sensitive there is, including data on offences and convictions (article 10 of the GDPR) in litigation. In a CNIL inspection or professional disciplinary proceedings, the timestamped dossier demonstrates what you knew, when, and what you did about it. And because DataBait accesses none of your case documents, it brings no new third party into the circle of secrecy.

See the Legal Professions page

Our own compliance

A provider that adds no risk to you

Adding a provider to your chain means adding an exposure surface and a monitoring duty. DataBait is designed to add neither.

DataBait neither accesses nor receives your databases: the fictitious accounts are injected through your own import routes, and the only things retained on our infrastructure are the inbound emails and SMS received by those accounts when their sender is not on your allowlist. In other words, messages originating outside your organisation, which by construction contain no business data belonging to you. Your exposure surface with us is nil: there is nothing, on your side, that could constitute a leak.

The chain of control, data minimisation, and third-party verifiable guarantees are detailed on the Sovereignty page.

See the Sovereignty page

Our guarantees, point by point

  • No customer data stored
  • No HDS scope added to your information system
  • SecNumCloud-qualified hosting (ANSSI)
  • ISO 27001-certified managed services
  • Qualified eIDAS timestamp issued by a QTSP on the EU Trusted List
  • Contractual confidentiality (Terms of Service art. 12)
  • Annual technical audit right (Terms of Service art. 9.3)
  • Sub-processors under our responsibility (Terms of Service art. 22)
  • Reversibility option provided for in the contract (Terms of Service art. 11.2)

Compliance, proof, and obligations

How does a DataBait alert secure my 72 hour deadline?

The article 33 GDPR deadline runs from your date of awareness of the breach, not from the leak itself. That is the date the supervisory authority examines, and it is the one that is hard to establish after the fact. Every DataBait alert is sealed by a qualified eIDAS timestamp issued by a QTSP on the EU Trusted List, which enjoys a legal presumption of validity throughout the European Union (article 41 of the eIDAS Regulation). You no longer declare your date of awareness: you prove it.

Does DataBait notify on my behalf?

No. DataBait produces the evidentiary material: the timestamped alert, the forensic metadata, and the commissaire de justice report. Assessing whether the breach is notifiable, qualifying its severity, and reporting it to the supervisory authority are for you and your DPO. We supply the dossier, not the regulatory decision.

Is the report enforceable outside France?

The commissaire de justice report, compliant with the AFNOR NF Z67-147 standard, is admissible before the French courts. The qualified eIDAS timestamp that seals it enjoys, for its part, a legal presumption of validity throughout the European Union.

Is injecting fictitious accounts GDPR-compliant?

The injected accounts match no real natural person: they are generated from public statistical datasets (INSEE, IRIS, BDNB), with no LLM and no hallucination, and therefore do not constitute personal data of your customers. They carry a real email address and a mobile number, operated by DataBait, which makes them contactable and therefore detectable.

What happens if no alert is raised for the whole term of the contract?

A database under DataBait that has never triggered an alert demonstrates, by construction, the absence of detectable misuse. For your CISO and your risk function, that is a measurable indicator of the maturity of your setup and of your processors'. For the supervisory authority, it is an exhibit added to your compliance file.

Can you identify the third party behind a leak?

Yes, if you segment your databases by recipient: DataBait injects dedicated fictitious accounts into each database entrusted, and a contact received on the accounts of a given database identifies the third party concerned. On a single database shared with several providers, a contact proves the misappropriation but does not identify who did it; attribution then requires your own investigation.

What is the impact on my information system and my record of processing activities?

No agent to install, no schema migration, no connector to maintain: the fictitious accounts are injected through the same import routes as your new customers. As for your record of processing activities, the scope of the processing DataBait carries out is limited to the inbound messages received by the fictitious accounts; your own databases are not transmitted to us. The exact allocation of roles under the GDPR is settled in the contract (Terms of Service article 8 and annex I).

Get in touch

Let us review your obligations with you

Book 30 minutes with our team: we go through the regime that applies to you, your notification deadlines, and the databases you share with third parties, and we identify the areas where injecting fictitious accounts documents your diligence fastest.

Reply within 24 business hours

Request a demo or ask a question

Pick your channel. We reply within 24 business hours.