Founders & Executives
Founders and executives of life-sciences companies come to us at recognisable moments: the first trial is about to open in Europe; a large pharma partner or a hospital customer has sent a due-diligence questionnaire; a financing round or an acquisition is under way and the data room needs a data protection file; or a product has just become an AI system under the EU AI Act.
The questions are practical. Who is accountable? What do we have to appoint, document and sign? What will an investor, a partner or an authority ask for, and how fast can we produce it? How much does it cost, and how do we keep it from becoming a distraction for a team that should be running the science?
iliomad answers with a fixed-fee mandate: a named DPO or AI Officer, a representative address in the EU and the UK where needed, a compliance file built in the first year and maintained after, and a monthly reporting rhythm your board can read in five minutes.
What an executive is accountable for
The company, not the DPO, is the controller. These are the decisions and documents that sit with the executive team, and that a partner, a buyer or a regulator will trace back to you.
A DPO under Art. 37 GDPR where processing of health data is large-scale; an EU and UK representative under Art. 27 where the company has no establishment there; an AI compliance owner where the company provides or deploys AI systems. Outsourcing the roles is permitted and, below a certain size, the only realistic option. iliomad provides them as one mandate — see Global DPO and AI Officer.
Pharma partners, acquirers and investors ask for the record of processing, the DPIAs, the DPA register, the breach procedure, the privacy notices and evidence that the roles above exist. A company that can produce them in a day negotiates from strength. iliomad builds the file to that standard and runs due-diligence audits on both sides of transactions.
iliomad prices mandates as a flat monthly fee for the life of the engagement, with the build-out concentrated in the first year and maintenance thereafter. Scoped deliverables — a DPIA, a gap assessment, an ICF review — are quoted as fixed amounts. There is no rate card surprise and no incentive to prolong work.
Each mandate includes a monthly report and a monthly meeting: what was done, what is open, what changed in the regulation and what the company must decide. Executives see the risk position without reading the underlying documents. When a regulator or a partner writes, iliomad drafts the answer.
Employees adopt AI tools faster than policies follow, and companies that develop AI systems acquire provider obligations under the EU AI Act. An acceptable-use policy, an AI inventory and an onboarding process for third-party tools are the minimum; provider obligations come with classification. iliomad delivers governance and AI Act compliance as one programme — see AI compliance services.
Law firms tell you what the law requires. iliomad does the work: the appointments, the documents, the contracts, the training, the audit responses. We are regulatory-compliance specialists with ISO 27001, 27005 and 9001 certification and CDPO-certified consultants, working exclusively in life sciences across more than 75 countries.
How iliomad Health Data can help you
iliomad Health Data is the external data protection and AI compliance function of more than thirty life-sciences companies, most of them founder-led and venture-backed. The CEO speaks to a senior consultant, the team speaks to the same consultant, and the board reads one report. The mandate scales with the company — from a first European study to a global programme — without a change of provider.
FAQs
Our frequently questions
