Sector-specific support

Cybersecurity and digital law counsel: support tailored to your sector

Cyber risks and legal obligations vary by activity. An industrial subcontractor, a SaaS publisher and a healthcare facility do not face the same exposures, nor the same levers of response.

EMPREINTE Avocats supports SMEs and mid-sized companies in Auvergne-Rhône-Alpes and across France on their cybersecurity, data protection and IT contract challenges. We also advise Swiss companies exposed to French or European law.

Swiss companies

A cross-border dimension we know well

The Geneva–Annecy–Lake Geneva economic basin is one of the most integrated in Europe. Many Swiss companies, in industry, tech or healthcare, work with clients, partners or service providers based in France and the EU. This creates concrete legal obligations that are often overlooked.

The GDPR may apply as soon as you process data of European residents, regardless of your location
NIS2 may affect your subsidiaries or partners established in France
Your contracts with French providers (IT, SaaS, subcontracting) often fall under French law or require a governing law analysis
In the event of a cyber incident affecting European data, notification obligations apply on the EU side

We advise on these cross-border matters in coordination with Swiss colleagues when Swiss law is at stake.

01

Industry and manufacturing

A ransomware attack on a production line means immediate shutdown, accumulating contractual penalties and a principal contractor demanding answers. Few industrial SMEs have an in-house legal team to deal with this. That is where we step in.

Ransomware on production systems
IT subcontracting contracts imposed by principal contractors
Protection of know-how and technical data
Crisis management without an in-house legal team

Are you an industrial SME facing an incident or a complex IT contract? Let's talk.

02

IT and Tech providers

Software publishers, tech startups, digital service companies, platforms.

A large-account client demanding GDPR compliance you are not sure you have. A liability limitation clause negotiated hastily that turns against you after an incident. A competitor copying your interface. The legal risks for IT service providers and SaaS publishers are concrete, frequent and often avoidable.

SaaS contracts: liability clauses, limitations, exclusions, SLAs, what looks standard can be costly in a dispute
GDPR and NIS2 as market access requirements: your large-account clients demand guarantees you must be able to provide
Data Act: data portability and reversibility: new concrete obligations for software publishers
Liability allocation in the event of an incident: who is responsible for what between the publisher, the host and the client?
AI Act: if you integrate AI components into your solution, obligations apply from August 2026, better to anticipate

Looking to secure your contracts or anticipate your regulatory obligations? Let's talk.

03

Healthcare and medtech

Health data is among the most sensitive under the GDPR and among the most coveted by cyber attackers. A breach, an incident, a flaw in a contract with your HDS host: the consequences are severe, notification deadlines are short, and supervisory authorities are attentive.

Ransomware targeting hospital information systems: service disruption, patient care compromised, media pressure
Healthcare data hosting (HDS): contractual obligations with certified hosts
CNIL notification in the event of a health data breach: deadlines and procedures
NIS2: healthcare facilities of a certain size are now important entities
Contracts with medical software publishers: liability, reversibility, continuity

Are you facing an incident, a CNIL notification or an HDS contract to secure? Let's talk.

04

Local authorities and public sector

Local authorities are increasingly targeted and their constraints are specific: public procurement, continuity of public services, constrained budgets, and a transparency obligation that complicates crisis management.

Ransomware and disruption of public services: incidents have increased sharply since 2020
NIS2: local authorities of a certain size are now important entities
GDPR: processing of sensitive data of citizens
IT contracts under public procurement rules: specifications, competitive tendering, SLAs
ANSSI and CNIL notifications in the event of an incident

Is your authority facing an incident or needs to structure its NIS2 response? Let's talk.

05

Outdoor, sports and mountain tourism

International brands, booking platforms, rapidly growing e-commerce: outdoor and mountain tourism players face overlapping challenges of intellectual property, customer data protection and system security, often without having structured their legal response.

Brand and digital asset protection against online counterfeiting
E-commerce platform security and customer data (GDPR)
Contracts with IT providers and digital agencies: liability, reversibility
Cyber incidents targeting booking or ski resort management systems
Creators' rights and intellectual property in digital projects

Do you have a digital project to secure or an incident to manage? Let's talk.

06

E-commerce and digital retail

The more volumes grow, the more technical architectures become complex, and the heavier the contractual and regulatory risks. E-commerce players are among the most frequent targets for their customer databases.

T&Cs and terms of use: compliance with French and European legal requirements
Customer data breach: CNIL notification obligation and communication to individuals concerned
Contracts with technical providers: hosting, payment solution, logistics, CRM
Disputes with clients or commercial partners: claims, refunds, liability
Data Act: new obligations for platforms collecting usage data

Do you have a question about your T&Cs, an ongoing dispute or an incident to manage? Let's talk.

The firm

The lawyers handling your cases

At EMPREINTE Avocats, your cases are handled by Lamia EL FATH and Marie MUNICCHI, lawyers at the Annecy Bar.

Lamia El Fath

Lamia El Fath

Marie Municchi

Marie Municchi

Does your sector present specific challenges? Let's discuss your situation.

Every case is different, even within the same sector. An initial discussion allows us to understand your context, identify the risks specific to your activity and explain how we can help.

We acknowledge receipt within 24 working hours. The first discussion is non-binding.