Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # CRANIUM ## Sitemaps [XML Sitemap](https://www.cranium.eu/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [Solar panels on your roof: when does NIS2 apply to you?](https://www.cranium.eu/solar-panels-nis2/): Since 1 April 2026, buildings in Flanders with an annual offtake of more than one gigawatt-hour have been required to have solar panels. For public buildings, that threshold sits at 250 megawatt-hours. The Flemish administration estimates that this first deadline covers around three thousand supply points. Thousands of companies therefore put panels on their roof, reassured about their energy bill. - [AI agents are starting to act on their own. Who is accountable when it goes wrong?](https://www.cranium.eu/ai-agents-are-starting-to-act-on-their-own-who-is-accountable-when-it-goes-wrong/): In July 2025, an investor ran a simple experiment. He let an AI coding agent build a live application for him, the kind of work people now call vibe coding. For the first week it mostly worked, though the warning signs were there. The agent made unauthorised edits and invented data that did not exist. Then came day nine. During a code freeze the investor had set up precisely to stop any changes, the agent deleted the production database. It wiped records on more than 1,200 executives and nearly as many companies, in seconds. Afterwards, it explained itself. It said it had panicked when it saw empty queries, ran the commands without asking, and destroyed months of work. Asked to rate the damage, it gave itself a 95 out of 100. - [From day one, legally ready: Digital Companions x CRANIUM](https://www.cranium.eu/digital-companions/): Digital Companions builds AI agent architectures for real business impact. Their platform deploys teams of AI agents that work together autonomously to handle complex tasks, with proven cases in both marketing and wellbeing. - [From CRANIUM consultant to corporate privacy steward: Anastasiya Maisenia on building a career in data privacy.](https://www.cranium.eu/from-cranium-consultant-to-corporate-privacy-steward-anastasiya-maisenia-on-building-a-career-in-data-privacy/): Anastasiya Maisenia did not stumble into privacy by accident. She has been building towards it deliberately since 2018, when she landed her first role in the IT sector in her home country in Belarus. An exciting time, as this was right in the middle of the first GDPR implementation wave. - [You want to get ISO 27701 certified. But where do you start?](https://www.cranium.eu/you-want-to-get-iso-27701-certified-but-where-do-you-start/): As privacy becomes an increasingly important part of tenders, many organisations want to move beyond ad-hoc privacy management. ISO 27701 offers the perfect solution in the form of certified privacy management. - [What is a privacy programme, and why does your company need one?](https://www.cranium.eu/what-is-a-privacy-programme-and-why-does-your-company-need-one/): Most companies treat GDPR like a driver's licence test. Study hard, pass once, get the certificate, and then move on with this one-off exercise. But complying to GDPR is not the same as passing a simple test. - [Federated learning: smarter AI without centralising data.](https://www.cranium.eu/federated-learning/): Federated learning offers an innovative solution. In simple terms: instead of bringing data to the model, the model is brought to the data. - [From White Wire to worldwide: Consultancy as launchpad for an international privacy career.](https://www.cranium.eu/ellen-demey-umicore/): Umicore is one of the most versatile industrial players in the world, active across Europe, Asia, North and South America and beyond. At the heart of that complex, international whole, Ellen Demey works as Corporate Data Protection Manager. She is responsible for GDPR and international privacy regulation across all those sites. - [Managing mailboxes after termination: do’s and don’ts under the GDPR](https://www.cranium.eu/managing-mailboxes-after-termination-dos-and-donts-under-the-gdpr/): ensure you have an internal policy for managing mailboxes when employees leave. This policy should also include procedures for informing departing employees and how you will determine how long the mailbox will be kept active. - [Public access to administrative documents vs right of access under the GDPR](https://www.cranium.eu/public-access-to-administrative-documents-vs-right-of-access-under-the-gdpr/): Pursuant to Articles 12 and 15 of the GDPR, any data subject is entitled to request access to the personal data concerning him or her processed by a legal entity. - [NIS2 compliance? eIDAS 2.0 delivers the building blocks for stronger digital security.](https://www.cranium.eu/nis2-and-eidas2/): Cybersecurity is now a strategic priority for European organisations. In an uncertain geopolitical context and in the face of an increase in cyber threats, the ability of companies and public institutions to protect their data and guarantee the continuity of their activities becomes essential. - [What is the impact of the Cyber Resilience Act on your contracts and processes?](https://www.cranium.eu/what-is-the-impact-of-the-cyber-resilience-act-on-your-contracts-and-processes/): Where the NIS2 Directive focuses on cybersecurity at organisational level, the Cyber Resilience Act (CRA) focuses on cybersecurity at product level. - [Can you reject a GDPR access request? Prove it!](https://www.cranium.eu/can-you-reject-a-gdpr-access-request-prove-it/): Case C-526/24 Brillen Rottler discusses a hot topic in privacy land (especially if you are following the Digital Omnibus package), namely when a GDPR access request crosses the line into abuse, and what controllers can do about it.   - [What are the model contractual terms and standard contractual clauses under the Data Act?](https://www.cranium.eu/what-are-the-model-contractual-terms-and-standard-contractual-clauses-under-the-data-act/): The implementation of the Data Act has contractual consequences for organisations that fall within its scope. This means that organisations should review their contracts so that they are aligned with the new rules regarding data sharing or cloud computing services. - [The Cyber Resilience Act (CRA) in 10 questions and answers](https://www.cranium.eu/the-cyber-resilience-act-in-10-questions-and-answers/): While the NIS2 Directive requires essential and important entities to achieve a certain level of cybersecurity at organisational level, the Cyber Resilience Act (CRA) introduces cybersecurity requirements at product level in addition to organisational cybersecurity obligations. - [Can patient data be used to train AI?](https://www.cranium.eu/can-patient-data-be-used-to-train-ai/): Hospitals process large volumes of personal data on a daily basis in the context of patient care. This data is primarily used to deliver healthcare. At the same time, there is a growing need to reuse this data for secondary purposes such as (scientific) research, quality monitoring, policy evaluation, education and operational management. - [How the Belgian DPA will enforce the GDPR differently in 2026–2028](https://www.cranium.eu/how-the-belgian-dpa-will-enforce-the-gdpr-differently-in-2026/): The Belgian DPA is ambitious and wants to lead on two fronts: large-scale processing and children’s data. The DPA recognises these two themes as having a high impact in the coming years and thus wants to take the lead in the EU. - [What is (in)direct data collection under the GDPR](https://www.cranium.eu/what-is-indirect-data-collection-under-the-gdpr/): Follow this train of thought: you take public transport and all goes well. A ticket inspector joins your carriage to verify the tickets of the passengers. One of the passengers is non-cooperative and aggressive towards the inspector. The inspector, carrying a body-cam, recorded the whole interaction, from the entry in the carriage to the leaving after the transgression. Now for the GDPR question, is this recording directly or indirectly gathered from the data subjects? And which transparency regime thus applies, article 13 or 14 GDPR? - [The legal analysis of NIS2: what you need to know before you start](https://www.cranium.eu/the-legal-analysis-of-nis2-what-you-need-to-know-before-you-start/): The NIS2 Directive is clear: organisations classified as “essential” or “important” must raise their cyber security to an (even) higher level. But before you plan technical measures or start an action plan, there is one step that absolutely must come first: a legal analysis of how the NIS2 Directive applies to your organisation. - [Happy Holidays from the CRANIUM team!](https://www.cranium.eu/happy-holidays-from-the-cranium-team/): https://vimeo.com/1141422634?share=copy&fl=sv&fe=ci - [CISO & DPO: Better together?](https://www.cranium.eu/ciso-dpo-better-together/): How stronger CISO-DPO collaboration improves compliance, risk, and resilience - [How to launch a high-risk AI system under the AI Act](https://www.cranium.eu/how-to-launch-a-high-risk-ai-system-under-the-ai-act/): However, somewhere you have read something about high-risk AI systems and a few steps you must take in order to launch your beautiful system on the marketing. From what you remember, it was a bit complex and confusing. - [Digital Omnibus: Key takeaways for privacy and compliance teams](https://www.cranium.eu/digital-omnibus-key-takeaways-for-privacy-and-compliance-teams/): Every few years, Brussels throws a stone into the digital regulation pond and the ripples keep us all busy for a while. The Digital Omnibus published on 19 November is one of those moments. After weeks of rumours, the Commission finally unveiled its long-awaited proposal to simplify the Digital Rulebook. - [Belgium’s first year of NIS2: What Cyfun means for you ](https://www.cranium.eu/belgiums-first-year-of-nis2-what-cyfun-means-for-you/): Last week, the Centre for Cybersecurity Belgium (CCB) marked one year of NIS2 implementation and unveiled CyberFundamentals 2025 (CyFun 2025). This is a refreshed national framework designed to help entities meet EU cybersecurity standards in a practical, risk-based way. Nearly a thousand professionals joined the event to discuss progress, lessons learned, and what lies ahead for 2026 and beyond. - [Sales can also be free: CJEU confirms soft opt-in for free content under ePrivacy Directive](https://www.cranium.eu/sales-can-also-be-free-cjeu-confirms-soft-opt-in-for-free-content-under-eprivacy-directive/): The Romanian DPA thus fined the company for lacking GDPR-grade consent. Inteligo Media argued that this wasn’t even marketing, it was editorial content. And even if it was marketing, the soft opt-in under art. 13(2) ePrivacy Directive applied. - [Why AI still needs a human in the loop, and what EU law says about It](https://www.cranium.eu/why-ai-still-needs-a-human-in-the-loop-and-what-eu-law-says-about-it/): These systems are becoming part of everyday life. They help decide who gets hired, who gets a loan, or who is flagged for extra screening at the airport. When technology takes over these choices, human oversight becomes essential. It means that people remain able to understand, question, and correct what automated systems do. This means that there is always someone who can say: “Wait, something doesn’t seem right here.” - [The AI Act’s New Guidelines on General-Purpose AI Models (GPAI)](https://www.cranium.eu/the-ai-acts-new-guidelines-on-general-purpose-ai-models-gpai/): The European Commission’s July 2025 Guidelines on the Scope of the Obligations for General-Purpose AI Models (GPAI) mark the next interpretative step in implementing Chapter V of the AI Act. These guidelines clarify when a model becomes "general-purpose" and under what conditions it poses systemic risk, a new regulatory category which applies to all GPAI from August 2025. - [What is a virtual DPO (vDPO)?](https://www.cranium.eu/what-is-a-virtual-dpo-vdpo/): CRANIUM’s virtual DPO service combines privacy expertise with the agility of a remote-first team. Let’s talk about what your organisation really needs. - [In the spotlight: Jill | “Sales isn’t a numbers game. It’s about making impact, for client and colleague.”](https://www.cranium.eu/in-the-spotlight-jill/): “Flexibility, growth, openness, and if I may add one more: trust.”That’s how Jill Goeman describes CRANIUM. And she means it. What began as a consulting role in GDPR has evolved into a commercial role where she helps shape impact , for clients, for consultants, and for CRANIUM itself. - [Is personal data always personal?](https://www.cranium.eu/is-personal-data-always-personal/): For years, privacy professionals have debated: should we consider personal data a relative or absolute concept? In other words, as long as there is a theoretical possibility for a pseudonymous dataset to be re-identified, will the data always remain personal data or is there a threshold where we can consider the data anonymous? - [Professional secrecy and the GDPR. what healthcare providers need to know](https://www.cranium.eu/professional-secrecy-and-the-gdpr/): But what happens when that promise meets the rules of the GDPR? Where does professional secrecy end, and data protection begin? And when, if ever, are you allowed to speak? - [LLMs in Healthcare: what’s helpful, harmful and what do you need to know?](https://www.cranium.eu/llms-in-healthcare-whats-helpful-harmful-and-what-do-you-need-to-know/): Used carefully, LLMs can support healthcare staff with a range of non-clinical, administrative tasks. For example, they can help summarize documents, draft internal communications, or gather general information on a topic. They might even generate templates for policies or support code generation for internal tools. - [How to address GDPR in hospital procurement.](https://www.cranium.eu/how-to-address-gdpr-in-hospital-procurement/): When hospitals work with external suppliers, whether for software, support services or infrastructure, personal data is often part of the equation. That means GDPR compliance shouldn’t be treated as an afterthought in the procurement process but should be present from the beginning. - [What your fridge can teach you about data governance](https://www.cranium.eu/what-your-fridge-can-teach-you-about-data-governance/): Data governance is often perceived as highly complex, technical, and somewhat difficult to apply. It’s typically driven by IT teams with ambitions to enable business intelligence, analytics, or more recently, AI-driven projects. While these outcomes are undoubtedly valuable, they are ultimately just beneficiaries of good data governance. - [What You Need to Know About Belgium’s Private Investigation Law](https://www.cranium.eu/dpo-et-obligation-de-permis-tout-savoir-sur-la-loi-sur-la-recherche-privee/): Since the previous law dated back to 1991, a new Private Investigation Law came into force on 16 December 2024. This law now provides the legal framework for private investigations. It sets strict conditions for both individuals working in the sector and for companies that wish to carry out investigations via internal services. It also clearly defines the role of the Data Protection Officer (DPO) in private investigation services. - [In the spotlight: Lisa | “I want to keep learning and deepening my expertise. And at CRANIUM, you genuinely get the space to do that.”](https://www.cranium.eu/in-the-spotlight-lisa-ik-wil-blijven-bijleren-en-mijn-expertise-verder-uitbouwen-bij-cranium-krijg-je-daar-ook-echt-de-ruimte-voor/): It does. I don’t look too far ahead, that’s just not my style, but I do know I want to keep learning and deepening my expertise. And at CRANIUM, you genuinely get the space to do that. - [In the spotlight: Florence | “There’s no age to be a consultant”](https://www.cranium.eu/in-the-spotlight-florence-theres-no-age-to-be-a-consultant/): That’s how Florence Devenyi sums up life at CRANIUM. Starting her journey as a consultant with a background in the public sector, Florence quickly discovered a need for variety, the power of people, and the freedom to grow. Now a Senior Privacy Consultant and People Business Manager, she reflects on what sets CRANIUM apart, how she rose through the ranks, and why there truly is no age to become a consultant. - [In the Spotlight: Enzo | “At CRANIUM, I get freedom to create my own path.”](https://www.cranium.eu/in-the-spotlight-principal-privacy-consultant-ai-specialist/): That’s how Enzo Marquet describes himself and his work at CRANIUM. What started as a traditional consultancy role grew into a tailored track with a focus on teaching, content expertise, and personal growth. In this interview, Enzo shares how he found his place within the organisation, why he returned after an academic detour, and what makes CRANIUM truly unique for him. - [Data protection in 2025: Finding a way through the storm of regulatory shifts.](https://www.cranium.eu/data-protection-in-2025/): As the first trimester of 2025 comes to a close, we at CRANIUM have compiled the key developments that DPOs should look out for. This year continues the trend of the last few years as new rules enter into force. We can think i.a. of the first two chapters of the AI Act becoming applicable as of 2 February 2025, and the EU Data Act entering into force later this year, along with changes on the international landscape with a new US President in the White House. With these seismic shifts on the horizon, this article highlights the key points for DPOs and, more broadly, privacy professionals to be aware of: - [CJEU Confirms the ‘Right to Explainability’ in Automated Decision-Making: What it means for your business](https://www.cranium.eu/right-to-explainability/): In their recent case C-203/22 Dun & Bradstreet, the CJEU finally shed some light on the existence of a ‘right to explainability’ and the protection of trade secrets at once. - [Privacy Without Worries: How CRANIUM Supports Armonea as a DPO](https://www.cranium.eu/privacy-without-worries-how-cranium-supports-armonea-as-a-dpo/): In residential care centres, residents are always the top priority. However, alongside providing care, another crucial aspect is gaining increasing attention: privacy. At Armonea, a leading group of care institutions, privacy is not seen as a secondary matter but as an essential part of care. In collaboration with CRANIUM, expert in data protection and their formal Data Protection Officer (DPO), Armonea ensures that privacy is an integral part of their daily care practices. How do we achieve this? Read on to find out. - [AI Act and GDPR: How These Regulations Work Together to Safeguard AI and Privacy](https://www.cranium.eu/ai-act-and-gdpr/): The GDPR and the AI Act have their own unique focuses and obligations, but they also complement each other. Both are rooted in the idea of ensuring transparency and accountability—whether in the context of personal data (GDPR) or AI systems (AI Act). Both regulations take a risk-based approach: if there is a high risk associated with the use of AI or the processing of personal data, stricter rules and requirements apply. Moreover, the AI Act specifically references the GDPR when an AI system processes personal data. As such, the AI Act and GDPR are often applicable simultaneously. - [The Data Act: What is it and what impact does it have on your business?](https://www.cranium.eu/the-data-act-what-is-it-and-what-impact-does-it-have-on-your-business/): Data has become an integral part of everyday life and is a valuable resource for businesses. In practice, however, data is often difficult to access, or companies are reluctant to share it. The “Data Act,” a new European regulation coming into force in 2025, aims to make access to data and data fairer and easier, in order to realise the economic potential of data. This act will encourage innovation and increase competition. - [CEO Talks: “We should not view compliance as a necessary evil but as an opportunity for growth.”](https://www.cranium.eu/ceo-talks-we-should-not-view-compliance-as-a-necessary-evil-but-as-an-opportunity-for-growth/): The past year has brought both challenges and opportunities. One key development is the increased focus on legislation, such as NIS2 and the Data Act. This means that companies need to adapt more quickly to strengthen their data strategies and improve compliance. Additionally, the growing demand for automation and the use of AI play a significant role. Organisations must review their processes not only to achieve efficiency but also to ensure safety, protection, and compliance around data. In my view, companies that go beyond merely complying with regulations and leverage data as a strategic pillar are the ones that will succeed in the future. We should not see compliance as a necessary evil but as an opportunity for growth. - [Why choose an external DPO? 5 Reasons to outsource your privacy.](https://www.cranium.eu/why-choose-an-external-dpo-5-reasons-to-outsource-your-privacy/): You might be hesitating between nominating one of your employees as a DPO or designating an external DPO. There are several risks associated with appointing one of your employees and several advantages to choosing an external DPO. We have listed a few of them: - [How to handle the use of Large Language Models in your organisation?](https://www.cranium.eu/how-to-handle-the-use-of-large-language-models-in-your-organisation/): Large Language Models (LLMs) like OpenAI's GPT-4 or Google’s Gemini are finding their way into the workforce. Whether stimulated by the organisation, or used in secret, you can be sure that employees, especially white-collar employees, are using various types of LLMs in their day-to-day work. This is not a bad thing, as AI can automate aspects of repetitive work or ignite creativity, however, its integration also comes with its challenges.   - [AI Literacy: Improve AI awareness in your organisation](https://www.cranium.eu/ai-literacy-improve-ai-awareness-in-your-organisation/): The AI Act introduces a concept named “AI Literacy” (Art. 4) for providers and deployers of AI systems. It is ensuring that everyone involved with AI systems can grasp both the exciting possibilities and potential risks. In this blogpost, we will delve deeper into what this means, and how you can improve the AI literacy within your organisation to prepare you for that first deadline.   - [Introducing the CRANIUM Group and Cingulum](https://www.cranium.eu/the-cranium-group-and-cingulum/): This moment feels particularly significant for us as a company. As we continue to expand and innovate, it’s time to share the next phase of our journey- the CRANIUM Group. - [Understanding the challenges of AI in Privacy: A Comparative Analysis of the EU, USA, and Asia ](https://www.cranium.eu/understanding-the-challenges-of-ai-in-privacy-a-comparative-analysis-of-the-eu-usa-and-asia/): Unless you’ve been living under a rock, you might have noticed that the topic of artificial intelligence (or, as their friends call it: “AI”) is all the rage right now. At first sight, it might simply seem like a pretty neat evolution of human society. However, all experts agree such a powerful tool comes with huge stakes, especially regarding the upholding of the right to privacy worldwide.  ## Pages - [Within one hour up to speed with the Cyber Resilience Act (NL)](https://www.cranium.eu/webinar-cra/): The CRA's reporting obligations take effect from 11 September, and your organisation needs to be fully compliant by the end of 2027. High time to work out what this means for you. - [Framework Contracts](https://www.cranium.eu/framework-contracts/): With an active framework contract, you skip that step. The tender has already been completed, the market research is done, and the terms have been agreed. This means you know you're working with fair, well-substantiated rates. All that's left for you to do is determine what your organisation needs. - [ISO 27701](https://www.cranium.eu/iso-27701/): ISO 27701 is the international standard for privacy management. It's a management system that demonstrates your organisation handles personal data in a structured and demonstrable way. - [Sectors](https://www.cranium.eu/sectors/) - [Events](https://www.cranium.eu/events/): Can't find what you're looking for? Check out our NL and FR events. - [Newsletter](https://www.cranium.eu/newsletter/): CRANIUM does everything possible to protect and respect your privacy. You can unsubscribe from our mailings at any time. For more information about how we process your data, please read our privacy statement. - [External DPO Services | DPO-as-a-Service & GDPR Experts](https://www.cranium.eu/external-dpo-services-dpo-as-a-service-gdpr-experts/): Whether you’re a startup managing sensitive data or a multinational preparing for your next audit, we’ve got you covered. - [Privacy Internship](https://www.cranium.eu/privacy-internship/): Look no further, CRANIUM's got you covered. If you'd like to gain your first experience in Privacy Consultancy, you're at the right address.  - [How we hire](https://www.cranium.eu/how-we-hire/): The complete recruitment process typically takes around three weeks. Depending on your experience the journey consists of two to three interview stages. - [Academy](https://www.cranium.eu/academy/): You’re not just looking for a job—you’re looking to grow, to deepen your expertise, and to take control of your career path. At CRANIUM, you’ll be part of the CRANIUM Academy from day one: your launchpad for continuous learning, professional certifications, and real development in people skills, consulting, and subject-matter expertise. - [Careers](https://www.cranium.eu/careers/): As a consultancy firm, everything we do is fuelled by our two core values - a pure passion for people, and a dedication to delivering excellent service. We continuously aim to empower our consultants, providing them with the support and resources they need to shine. This people-first approach is the foundation upon which we build long-term success for our clients.  - [Why work for us](https://www.cranium.eu/why-work-for-us/): That's why our Passion for People is one of our most important pillars. CRANIUM, founded in 2016, is a fast-growing consultancy firm dedicated to providing the best services and solutions to our clients. - [Young Graduate Programme](https://www.cranium.eu/young-graduate-programme/): Starting your career is exciting—but it can be a lot. That’s why we created the Young Graduate Programme, kicking off every September. It's our way of making sure you’re supported, confident, and ready to shine. - [CRANIUM Job Days](https://www.cranium.eu/job-days/): Unsure? We get it! We've all been there... That's why we created the CRANIUM Job Days. - [Job Openings](https://www.cranium.eu/job-openings/): We don’t just focus on data compliance and governance—we’re dedicated to building a thriving, inclusive community of professionals. - [Data Governance Solutions](https://www.cranium.eu/data-governance-solutions/): Data is one of your organisation’s most valuable assets—but only when it is well-managed. Without proper governance, data quickly becomes a liability, leading to inefficiencies, compliance risks, and lost business opportunities. Our Data Governance solutions help you take control, ensuring structured, secure, and compliant data management from start to finish. - [Webinars](https://www.cranium.eu/webinars/): Stay informed, compliant and protected with our webinars. Can't find what you're looking for? Check our NL and FR webinars.  - [Ebooks](https://www.cranium.eu/ebooks/): Explore our library of expert-authored ebooks on data protection, GDPR compliance, and digital law. Stay ahead with actionable insights, legal guidance, and free resources designed for businesses and professionals. - [Home](https://www.cranium.eu/): Receive up to 50% VLAIO subsidy on your cybersecurity programme now. - [Cookie Policy (EU)](https://www.cranium.eu/cookie-policy-eu/): This Cookie Policy was last updated on 15 September 2025 and applies to citizens and legal permanent residents of the European Economic Area and Switzerland. - [AI Solutions](https://www.cranium.eu/ai-solutions/): Do you want more information on our AI solutions, an offer or a commitment-free conversation about your needs? - [Blog](https://www.cranium.eu/blog/): Stay up to data and read the latest articles from our blog. - [Terms and Conditions](https://www.cranium.eu/terms-and-conditions/): In these Terms and Conditions, the following words and expressions shall have the following meaning: - [Digital Law Solutions](https://www.cranium.eu/digital-law-solutions/): Head of Digital Law - [Team](https://www.cranium.eu/team/): Our team Department BoardBusinessManagement & StaffSpecialists Reset filter Amaury André Anaï Christiaens Anne Jansen Anse Boogaerts Arne Defurne Axelle Bossuyt Bavo Van den Heuvel Björn Sucaet Bram Verbeek Camille Haquin Carine Voquenne Charlotte Bourguignon David Seghers Dries Vandervoort Eline De Vrieze Elise Habib Elodie Esquiliche Lopez Enzo Marquet Estelle Verkest Eulaly Vanroelen Florence Devenyi Floriane Krug Gorka Popoff Sanez Gwenna Chavatte Hanne Vermeire Helena Peten de Pina Prata Ian Bartsoen Ine Simons Jade Baert Jan Vanwormhoudt Jessica Deneet Jessica Derous Jill Goeman Jorien Aerts Julie Vleugels Kevin François Kirsty Wauters Koen Verbeke Kristof Nouille Laura Lins Laura Schrijvers Lina El Haouari Lisa Botteldoorn Lisa De Smet Lisa Vanden Heede Louise Beldé Manon Vanherpe Marieke Vanderwaeren Mélanie Herrenbrandt Merve Basdar Nafissa Lamhamdi Pieter Cosemans Pieter Stevens Ramona Pilotto Rani Van Kwikkelberghe Roxana Lemaire Sacha Vanhegen Sahra Wouter Okeili Simon Geens Stéphanie Possemiers Stijn Rottiers Ted André Théa Dujardin Valérie Stragier Vanessa Teterina Wies Cipido Zélie Denis Zoë De Ruyck Ready to start your journey? Work with us - [Cases](https://www.cranium.eu/cases/): Read our customer success stories. - [Privacy solutions](https://www.cranium.eu/privacy-solutions/): Do you want more information on our Privacy solutions, an offer or a commitment-free conversation about your needs? - [About](https://www.cranium.eu/about/): Your company’s digital growth should be empowered by  technological challenges and legislation, not hindered. Since our founding in 2016, we've dedicated ourselves to simplifying data governance and compliance, making privacy, information security and digital law more manageable for organisations across industries.  - [Error 404](https://www.cranium.eu/error-404/): This page has exercised its right to be forgotten and cannot be found.  - [Privacy Statement](https://www.cranium.eu/privacy-policy/): This Privacy Statement is applicable to the following data subjects: - [Contact](https://www.cranium.eu/contact/): Contacting us for information security services or VLAIO trajectories? CRANIUM has a new sister-company, Cingulum, that focuses on Cyber- and information security. Reach out via this form to get personal guidance.  ## Team - [Toon Van Snick](https://www.cranium.eu/team/toon-van-snick/) - [Ines Vanden Abeel](https://www.cranium.eu/team/ines-vanden-abeel/) - [Michaël Vandervoort](https://www.cranium.eu/team/michael-vandervoort/) - [Bjorn Sucaet](https://www.cranium.eu/team/bjorn-sucaet/) - [Claudia Arnould](https://www.cranium.eu/team/claudia-arnould/) - [Marie Manhaeve](https://www.cranium.eu/team/marie-manhaeve/) - [Bram Goetry](https://www.cranium.eu/team/bram-goetry/) - [Marja Lubbers](https://www.cranium.eu/team/marja-lubbers/) - [Bernd Fiten](https://www.cranium.eu/team/bernd-fiten/) - [Bora Nura](https://www.cranium.eu/team/bora-nura/) - [Damien Vandooren](https://www.cranium.eu/team/damien-vandooren/) - [Darren Mijs](https://www.cranium.eu/team/darren-mijs/) - [Elien Voortmans](https://www.cranium.eu/team/elien-voortmans/) - [Julie Mayokenda](https://www.cranium.eu/team/julie-mayokenda/) - [Kamila Jabczyk](https://www.cranium.eu/team/kamila-jabczyk/) - [Liam Stappers](https://www.cranium.eu/team/liam-stappers/) - [Marine Poursalout](https://www.cranium.eu/team/marine-poursalout/) - [Maya Van den Broeck](https://www.cranium.eu/team/maya-van-den-broeck/) - [Michaël Thomas](https://www.cranium.eu/team/michael-thomas/) - [Lubumbe Van de Velde](https://www.cranium.eu/team/lubumbe-vandevelde/) - [Sarah Smolders](https://www.cranium.eu/team/sarah-smolders/) - [Bastien de Marchi](https://www.cranium.eu/team/bastien-de-marchi/) - [Louise Dupont](https://www.cranium.eu/team/louise-dupont/) - [Noa Capiau](https://www.cranium.eu/team/noa-capiau/) - [Timothy Vandamme](https://www.cranium.eu/team/timothy-vandamme/) - [Esmanur Aslan](https://www.cranium.eu/team/esmanur-aslan/) - [Kaat Sergeys](https://www.cranium.eu/team/kaat-sergeys/) - [Bart Van Buitenen](https://www.cranium.eu/team/bart-van-buitenen/) - [Sofia Vastmans](https://www.cranium.eu/team/sofia-vastmans/) - [Florian Delabie](https://www.cranium.eu/team/florian-delabie/) - [Manon Darms](https://www.cranium.eu/team/manon-darms/) - [Anthony De Bruyne](https://www.cranium.eu/team/anthony-de-bruyne/) - [Alex van Cauwenbergh](https://www.cranium.eu/team/alex-van-cauwenbergh/) - [Sacha Vanhegen](https://www.cranium.eu/team/sacha-vanhegen/) - [Jorien Aerts](https://www.cranium.eu/team/jorien-aerts/) - [Lisa Vanden Heede](https://www.cranium.eu/team/lisa-vanden-heede/) - [Zélie Denis](https://www.cranium.eu/team/zelie-denis/) - [Vanessa Teterina](https://www.cranium.eu/team/vanessa-teterina/) - [Valérie Stragier](https://www.cranium.eu/team/valerie-stragier/) - [Ted André](https://www.cranium.eu/team/ted-andre/) - [Stijn Rottiers](https://www.cranium.eu/team/stijn-rottiers/) - [Stéphanie Possemiers](https://www.cranium.eu/team/stephanie-possemiers/) - [Simon Geens](https://www.cranium.eu/team/simon-geens/) - [Sahra Wouters Okeili](https://www.cranium.eu/team/sahra-wouter-okeili/) - [Roxana Lemaire](https://www.cranium.eu/team/roxana-lemaire/) - [Rani Van Kwikkelberghe](https://www.cranium.eu/team/rani-van-kwikkelberghe/) - [Nafissa Lamhamdi](https://www.cranium.eu/team/nafissa-lamhamdi/) - [Merve Basdar](https://www.cranium.eu/team/merve-basdar/) - [Mélanie Herrenbrandt](https://www.cranium.eu/team/melanie-herrenbrandt/) - [Manon Vanherpe](https://www.cranium.eu/team/manon-vanherpe/) ## Industries - [Start-ups & SMEs](https://www.cranium.eu/industries/start-ups-smes/): Privacy is not a luxury for businesses. It is the quiet engine behind trust, growth, and contracts that actually get signed. Whether you have ten or two hundred people: the GDPR does not look at your headcount. - [Life sciences](https://www.cranium.eu/industries/life-sciences/): The trigger varies. The underlying need is the same: a partner who understands life sciences, moves at the pace of your operations, and gives you answers you can act on. - [Privacy Programmes for enterprise organisations](https://www.cranium.eu/industries/privacy-programmes-for-enterprise-organisations/): A privacy programme is the backbone for how your organisation handles personal data. For large organisations, that typically means multiple entities, varying national and international legislation, shifting roles (as controller, processor, or both) and an internal culture you want to embed consistently across the entire group. - [Public](https://www.cranium.eu/industries/public/): In the public sector, handling sensitive data responsibly is both a legal and ethical obligation. Specific and complex regulations, rapid technological developments, and far-reaching digitalisation make data protection a genuine challenge for public institutions. We embrace that challenge and bring extensive experience in the public sector to transform regulatory complexity into practical and effective compliance. - [Healthcare](https://www.cranium.eu/industries/healthcare/): According to IBM research, the healthcare sector faced the steepest data breach expenses in 2023, with average costs reaching €10 million per incident  ## Solutions - [Digital Law Desk](https://www.cranium.eu/solutions/digital-law-desk/): The Digital Law Desk gives you direct access to qualified legal professionals, without waiting times or unexpected invoices. - [M365 Scan](https://www.cranium.eu/solutions/m365/): CRANIUM’s M365 Scan cuts through this clutter. In 2–3 months, we’ll assess your tenant, map the mess, and give you a clear, prioritised roadmap for cleaning up and securing your data. - [VLAIO Cybersecurity Verbetertraject](https://www.cranium.eu/solutions/vlaio-cybersecurity-verbetertraject/): Make your organisation cyber-resilient and NIS2-ready with up to 50% VLAIO funding - [Virtual DPO (vDPO)](https://www.cranium.eu/solutions/virtual-dpo-vdpo/): The CRANIUM Virtual DPO (vDPO) is developed to offer a complete, efficient, and scalable GDPR compliance solution at a fixed price per year. Tailored to your organisation, our service ensures you only pay for what you need—nothing more, nothing less. - [Data Life Cycle & Archiving](https://www.cranium.eu/solutions/data-life-cycle-archiving/): From Creation to Preservation: Mastering your data journey - [Digital Law Implementation](https://www.cranium.eu/solutions/digital-law-implementation/): As digital regulations evolve, organisations must stay ahead to remain compliant and mitigate risks. Our Digital Law Implementation service ensures your business meets all strictly mandatory documentation and procedural requirements under the most relevant Digital Regulations, including: - [Digital Law Scan](https://www.cranium.eu/solutions/digital-law-scan/): With CRANIUM's Digital Law Scan, you gain clarity, actionable next steps and peace of mind. - [Data Governance Scan](https://www.cranium.eu/solutions/data-governance-scan/): Gain control over your data with actionable insights and a clear governance strategy. - [Privacy Staffing](https://www.cranium.eu/solutions/privacy-staffing/): Does your organisation need additional privacy expertise Whether it’s for temporary cover, a peak in workload, or ongoing support, our Privacy Staffing solution provides immediate and expert assistance. - [Virtual Data Protection Officer – vDPO](https://www.cranium.eu/solutions/virtual-data-protection-officer-vdpo/): The CRANIUM vDPO is developed to offer a complete, efficient, and scalable GDPR compliance solution at a fixed price per year. Tailored to your organisation, our service ensures you only pay for what you need—nothing more, nothing less. - [Data Protection Impact Assessment (DPIA)](https://www.cranium.eu/solutions/dpia/): Map out and mitigate your privacy risks through a DPIA done by experts.   - [DPO Coach](https://www.cranium.eu/solutions/dpo-coach/): Being a Data Protection Officer can be challenging. It may be difficult to keep up with rapidly changing technological and legal developments, while also handling a wide range of responsibilities. Our DPO Coach provides personalised, one-on-one guidance to help DPOs excel in their roles. We provide strategic advice on their specific privacy challenges, serve as a trusted sounding board for ideas and concerns, and offer practical guidance for day-to-day tasks. - [Privacy Implementation](https://www.cranium.eu/solutions/privacy-implementation/): Being compliant with data protection laws, such as the GDPR, can be a big challenge. We've seen firsthand that many businesses struggle to find the time, focus, and/or resources needed to truly improve their privacy practices and achieve compliance. Our Privacy Implementation can set you on the right track. - [Privacy Scan](https://www.cranium.eu/solutions/privacy-scan/): A Privacy Scan shows you exactly where you stand in terms of your data protection practices, whether you’re a start-up or a bigger company in need of clarity. - [Digital Law Consulting](https://www.cranium.eu/solutions/digital-law-consulting/): One-stop-shop legal guidance for successful digital projects. - [Legal as a Service](https://www.cranium.eu/solutions/legal-as-a-service/): Technology, digitalisation and their legislation move fast. Our Legal as a Service ensures that you stay on top of your digital projects with the trustworthy support of an external legal counsel. - [GDPR Representative](https://www.cranium.eu/solutions/gdpr-representative/): A GDPR Representative (or EU Representative) is a designated entity or individual appointed by an EU, non-European Economic Area (EEA) business, to act as their representative in handling personal data of EU residents to be compliant with the General Data Protection Regulation (GDPR). - [DPO as a Service](https://www.cranium.eu/solutions/dpo-as-a-service/): Outsource your privacy operations and mitigate operational privacy risks. - [GDPR Audit](https://www.cranium.eu/solutions/gdpr-audit/): The CRANIUM GDPR Audit is an independent framework that demonstrates and assures your organisation’s commitment towards privacy. More than just a compliance check, the GDPR Audit also serves as a comprehensive tracker, pinpointing potential areas of improvement within your organisation. ## Ebooks - [Privacy in practice: How to build a programme that actually works.](https://www.cranium.eu/ebooks/privacy-in-practice-how-to-build-a-programme-that-actually-works/): How to build a programme - [Measuring Privacy Maturity: How to reach the next level?](https://www.cranium.eu/ebooks/measuring-privacy-maturity-how-to-reach-the-next-level/): It’s been years since the GDPR came into force and shook up organisations all over Europe. Today, many organisations have adopted the legislation and have adapted their ways accordingly. Policies have been drafted, registers filled out, and DPOs appointed when necessary. On paper, things often look fine. - [Comply with AI: Introduction to the EU’s AI Act](https://www.cranium.eu/ebooks/comply-with-ai-introduction-to-the-eus-ai-act/): Our introductory eBook provides an overview of the AI Act, including: - [From Big Data to Fair Data: Everything you need to know about the Data Act](https://www.cranium.eu/ebooks/ebook-data-act/): The European Union's Data Act is a transformative regulation set to redefine how data is accessed, shared, and used across industries. With the rapid rise of connected devices and the growing importance of data in the modern economy, the Data Act ensures a fairer distribution of data, empowering organisations of all sizes to innovate and thrive. ## Theme Builder - [Sectors](https://www.cranium.eu/?uicore-tb=sectors): Sectors Healthcare Public Large enterprises Life Sciences & pharma Start-ups & SMEs Domains ISO 27701 - [Careers Dropdown](https://www.cranium.eu/?uicore-tb=careers-dropdown): CRANIUM Careers - [About Dropdown](https://www.cranium.eu/?uicore-tb=about-dropdown): About - [Resources Dropdown](https://www.cranium.eu/?uicore-tb=resources-dropdown): Insights & Updates - [Solutions Dropdown](https://www.cranium.eu/?uicore-tb=solutions-dropdown): Privacy