Who we are

Mathias Avocats is a law firm dedicated to digital law, personal data protection, cybersecurity, IT contracts, artificial intelligence and intellectual property.

For over 20 years, we have been supporting our clients in their projects (IT, digital transformation, GDPR compliance, etc.), managing their legal risks (contracts, pre-litigation, etc.) and providing legal, European and international intelligence and training.

We bring a global, cross-practice business perspective and in-depth knowledge of the evolving regulatory and legal compliance landscape.  In today’s technology-driven world, businesses of every size (from startups to large multinational corporations) and public entities in every sectors (health, education…), have to face privacy and cybersecurity legal requirements and risks.  From artificial intelligence (AI) to cybersecurity risks, we are skilled at identifying and managing legal concerns with regards to new technologies. 

We offer clients proactive cyber, privacy legal services (contracts, etc.). We help our clients legally manage and respond to a cyber incident (including the impact of data breaches in several countries and the coordination of international teams) and help develop a strategic plan and update cybersecurity, IA and data privacy risk frameworks.

Our services include Tailor-made legal monitoring of our clients’ activities and businesses (a versatile client assistance).

Our team offers holistic privacy and cybersecurity compliance legal help to address every issue, such as:

Legal advice and complex contractual negotiations:

  • Drafting and negotiating SaaS agreements, data processing agreements, data security and privacy agreements and addendums, contracts, and other legal documents,
  • Drafting unique and novel contract language to put legal protections in place for the use and business dealings surrounding emerging technology (IA, cybersecurity liabilities, etc.)

DPO extern activity (financial, health, distribution, and marketing sectors)

  • Evaluating the legality of data collection and sharing practices, including ensuring that all legal requirements to enable the same are met (data transfers outside UE/ UK, cookies and/or data trackers, DPIA, etc.)
  • Drafting and/or updating privacy policies

Mediation, pre-litigation and litigation

While our attorneys help organizations do their best to avoid litigation, sometimes it is unavoidable. Our team of experienced litigators can defend and, if needed, prosecute actions concerning cybersecurity and privacy issues, such as:

  • Advising on litigation strategy for threatened or recently commenced actions
  • Defending or prosecuting cases involving cyber negligence and privacy violations (including right to publicity cases and alleged illegal website features)
  • Responding to or drafting pre-litigation letters and notices

Legal monitoring and compliance

Our team offers holistic privacy and cybersecurity compliance legal help to address every issue. We help organizations do their best to evaluate and address compliance issues with the use or development of new technologies, including artificial intelligence as well as:

  • GDPR (data protection impact assessment, DPIA, data transfers (TIA), etc.)
  • NIS 2 (gouvernance, impact for group entities in several EU member states, etc.)
  • DORA (implementation, guidelines from the supervisory authorities, etc.)
  • Cyber Resilience Act, Directive on critical entities
  • AI Act (impact assessment on fundamental rights; implementation of requirements for AI systems, for AI models, negotiating and drafting AI contractual clauses…)
  • Etc.

Cybersecurity / Cyber Incident Response (crisis management assistance)

When a cyber incident occurs (cyberattacks, Fake President frauds, information security breaches, etc.), we help clients take rapid action to address the incident and mitigate the damage.
We work with clients to ensure compliance with all relevant legal obligations, create an accurate audit to document compliance, and prepare to deal with potential litigation and regulatory investigations.

Our work includes:

  • Acting as “triage” cyber incident response counsel to ensure effective legal representation at all times
  • Closing out the incident and conducting a “lessons learned” review and policy update once the matter is resolved
  • Evaluating and managing cyber incidents of all sizes from a small email account take over to a large ransomware event
  • Overseeing and retaining the forensics team and engaging with law enforcement as needed

Custom training program

Our team offers training the C-Suite and staff on their obligations and how to manage them, such as

  • Privacy & Data protection
  • Cybersecurity
  • Artificial Intelligence, etc.

Expert blog and monthly newsletter on Digital Law, Data Protection, Cybersecurity, AI…

Keeping our clients informed of new and considered legal changes that could affect the development of their products, their services.

Who are our clients

  • From start-ups to major international groups
  • From all business sectors: banking, industry, energy, tech, software publishers, consulting, healthcare, universities…
  • Private or public entities