

The regulator's perspective to anticipate the risks and defend your interests
Odoné advises and represents French and international companies in complex data-protection and AI matters, by combining technical excellence and pragmatism, from compliance advisory to pre-litigation and litigation.
When to contact us?
The initial decisions made when facing the CNIL often significantly impact the outcome of a case. Knowing when to get the right support allows you to maintain control of discussions and limit your organization's exposure.
You are assessing the feasibility of an innovative or sensitive project that could attract regulatory scrutiny.
You anticipate a CNIL audit and wish to prepare for it.
You have experienced a data breach and must determine whether it needs to be reported to the CNIL or communicated to the data subjects.
You have received a formal notice, a letter appointing the rapporteur, or a sanction report.
You have been audited and are still awaiting a response from the authority.
A complaint has been filed against you, and you have received a letter from the complaints department requesting your explanation.
Why Odoné ?
As a former lawyer at CNIL for 7 years, including 3 years in the sanctions department, Joanna Masson assists companies facing complaints, personal data breaches, inspections, formal notices, and sanction procedures. This experience allows the firm to anticipate the authority's expectations and intervene effectively at each stage of the process.

+ 20years
7years at the CNIL
30clients
100%
80%
Odoné, the expertise trusted by
the most demanding companies
Executives, in-house counsel, DPOs and former CNIL colleagues attest to the firm’s ongoing commitment to excellence, grounded in rigor, proximity and determination.
A team that's close-knit,
commited to excellence


Joanna Masson
Before founding Odoné, Joanna spent seven years in leading international law firms.
She then joined the French Data Protection Authority (CNIL), where she worked within the Compliance Directorate and later in the Sanctions Departmentt.
In this role, she supported major corporations, private-sector organisations and government ministries in their in their GDPR and French data-protection compliance efforts.
Since 2022, Joanna has also been a lecturer in data-protection law at École des Ponts ParisTech.
She holds a dual Master’s degree in French and English law (University of Cambridge and Paris II Panthéon-Assas), a Master’s degree in Industrial Property Law (Paris II), and a Master’s degree in Private Law (Paris I Panthéon-Sorbonne).
“Supporting a client means reconciling legal requirements and operational reality. Our mission: to provide clarity and security in a constantly evolving framework and to translate legal requirements into concrete solutions.”
— Joanna Masson


Emma Hanoun
A lawyer at the Paris Bar for four years, Emma works alongside Joanna.
Emma started her career in the legal department of a large international group, before joining a boutique firm where she managed the IT department as a counsel.
She holds a Master’s degree in Private Law (Paris II Panthéon-Assas), a University Diploma in Technology and Digital Law (Paris II Panthéon-Assas), and a Master’s degree in Multimedia and IT Law (Paris II Panthéon-Assas).
“Compliance is a corporate culture before it is a legal requirement. It is a marker of trust and a factor of credibility.”
— Emma Hanoun
Let's discuss your challenges
Have you been audited by the CNIL, need to respond to a formal notice, experienced a data breach, or want to secure your practices?
Let's schedule an appointment now
Direct conversation with Joanna Masson, Founding Attorney
7 years of experience at CNIL
3 years with CNIL's enforcement team
Advisory for CAC 40 companies and mid-sized businesses
Clear guidance begins
with precise answers
What are your timelines and terms of engagement?
We prioritize responsiveness and transparency in our communications. The timeline for our work and our fees are always determined upfront, based on the complexity and duration of the project.
How do you balance technical excellence with accessibility for your clients?
Our firm's strength lies in a simple and direct relationship with our clients, built on trust and involvement at every stage. Technical excellence is only valuable if it remains clear and actionable — our role is to provide precise, practical, and immediately applicable solutions.
Why has compliance become a strategic issue for businesses?
Because today it is a key factor in building trust and credibility. A company that controls its data processing strengthens its legal security, protects its reputation, and gains legitimacy with its clients and partners.
Do you represent individuals, for example, in the context of a complaint to the CNIL?
No. Our firm exclusively represents businesses in matters concerning their interactions with the CNIL and their data compliance and protection challenges. Our work focuses on supporting professional entities—from strategic consulting to litigation—to secure their practices and positions with respect to the regulator.
Do you provide outsourced DPO services?
No. Our firm does not act as an outsourced DPO, as this role requires daily, operational monitoring that falls outside our scope of work. We support internal or outsourced DPOs by assisting them with sensitive cases, complex issues, or CNIL audits.
Are you also involved in issues related to artificial intelligence?
Yes. We assist companies with the implementation of the Artificial Intelligence Regulation (AI Act). Our approach involves anticipating governance obligations, assessing risks, and documenting compliance, to integrate these new requirements into existing compliance frameworks.
Do you conduct mock CNIL audits?
Yes. We conduct mock audits to prepare our clients for the CNIL's methods and expectations. These simulations help raise awareness among teams about the procedures to follow during an inspection, assess compliance levels for a specific topic, and define priority areas for improvement. We also conduct online audits, particularly regarding cookie and tracker compliance, to identify any potential non-compliance issues.
Can you assist with a DPO transition?
Yes. We assist during DPO transitions to ensure a smooth and structured handover. This service includes mapping the outgoing DPO's activities, outlining key ongoing projects, and identifying critical points to facilitate the incoming DPO's onboarding.
How do you assist during a CNIL audit or pre-litigation?
The CNIL is often perceived as a "black box." We provide our clients with the necessary visibility to anticipate the next steps: explaining the investigation process, defining the defense strategy, and managing communications with the authority. Our goal is to secure the client's position, manage financial and reputational risks, and, where possible, re-establish a constructive dialogue with the CNIL.
How does your experience at the CNIL add value for your clients?
Joanna's seven years at the CNIL provide the firm with in-depth knowledge of the regulator's practices and its approach to control and enforcement. This experience allows us to anticipate the authority's expectations, build strong arguments, and develop compliance and defense strategies that are both credible and effective.
Why choose a boutique firm over a large generalist firm?
Because technical expertise and responsiveness are paramount when it comes to personal data. Odoné offers tailored support, built on a deep understanding of legal frameworks and a direct relationship with its clients. This agility enables us to provide precise, rapid, and strategic solutions, even for the most complex cases.
The latest resources from the Odoné firm


CNIL inspections: 6 mistakes that raise the risk of sanctions




















