- Compliance & personal data
- 7 sections
- 40 slides
- 8 quizzes
- 60-80 min
GDPR: the essentials for every employee and public-sector worker
The GDPR governs any use of information relating to an identifiable person: a customer, a patient, a resident, a colleague. For a working professional, it comes down to four questions asked about every file in use: why is this data collected, on what legal basis, for how long, and who can access it. The record of processing activities, privacy notices and the response to a data breach are simply the written trace of those answers.
- Written by Équipe Skillrung
- Relecture par un expert du domaine en cours
- Updated on
What is this course about?
Know which data you handle, which rights apply, and what to do the day a piece of information leaves your organisation.
This is a core course: the material taught is the same for everyone, only the examples, the tools mentioned and the people you deal with change with your job. It has 7 sections, of which 5 sections are followed by a quiz, and reads in 60-80 min. The legal framework cited is French law.
You process personal data every day
A spreadsheet of contact details, a list of registered people, a file open on your screen: you were using personal data long before you ever heard the word compliance. The EU General Data Protection Regulation (GDPR) has applied across the Union, France included, since 25 May 2018, and it is not aimed only at large organisations. As soon as a piece of information relates to an identifiable person, it applies, including at your structure, and it covers données personnelles first and foremost.
Key points
Four questions to ask about any file
Ask them before creating a file, and go back over the ones already sitting in your logiciel métier or in your spreadsheets.
- Why is this data collected, and for what precise use?
- What authorises the collection: the law, a contract, consent?
- How long does it stay useful, and what happens to the file afterwards?
- Who can view it, internally and at a service provider?
What you will be able to do
- Identify your real role in the data processing carried out by your organisation.
- Recognise personal data, sensitive data and a processing operation in your own work.
- Link every collection to a purpose, a legal basis and a written retention period.
- Identify a rights request and respond to it within the legal deadline.
- Check what a service provider does with your data before entrusting it to them.
- Recognise a data breach and trigger the right response immediately.
- Turn the principles covered into steps you can apply in the coming week.
The first 4 slides, free
What you read with no account and no card. Here, the generic version; in the player, the examples take the vocabulary of your job.
Try it, before you even create an account
Choisissez un métier : le passage ci-dessous se réécrit tout de suite. Rien n'est enregistré, et aucun contenu supplémentaire ne s'ouvre.
Aucun métier retenu : c’est la version générique qui s’affiche.
A spreadsheet of contact details, a list of registered people, a file open on your screen: you were using personal data long before you ever heard the word compliance. The EU General Data Protection Regulation (GDPR) has applied across the Union, France included, since 25 May 2018, and it is not aimed only at large organisations. As soon as a piece of information relates to an identifiable person, it applies, including at your structure, and it covers données personnelles first and foremost.
Real extract from the free slide “You process personal data every day” of this course.
- Règlement (UE) 2016/679 du 27 avril 2016, article 99 : entrée en application : EUR-Lex, Union européenne, 2016-04-27
- FreeSlide 1 of 40 · Why the GDPR already applies to you
You process personal data every day
A spreadsheet of contact details, a list of registered people, a file open on your screen: you were using personal data long before you ever heard the word compliance. The EU General Data Protection Regulation (GDPR) has applied across the Union, France included, since 25 May 2018, and it is not aimed only at large organisations. As soon as a piece of information relates to an identifiable person, it applies, including at your structure, and it covers données personnelles first and foremost.
- Règlement (UE) 2016/679 du 27 avril 2016, article 99 : entrée en application : EUR-Lex, Union européenne, 2016-04-27
- FreeSlide 2 of 40 · Why the GDPR already applies to you
What you will be able to do by the end
- Recognise données personnelles in your files
- Respond to a rights request within the legal deadline
- React within the first hour to a data leak
- FreeSlide 3 of 40 · Why the GDPR already applies to you
Four questions to ask about any file
Ask them before creating a file, and go back over the ones already sitting in your logiciel métier or in your spreadsheets.
- Why is this data collected, and for what precise use?
- What authorises the collection: the law, a contract, consent?
- How long does it stay useful, and what happens to the file afterwards?
- Who can view it, internally and at a service provider?
- FreeSlide 4 of 40 · Why the GDPR already applies to you
Three questions to see where you stand
Three quick questions, with no score and no judgement: what you would do if the CNIL asked to see your files.
3 short questions, marked immediately, inside the course.
These 4 slides can be read in the player, with no account and no card.
Read the first slideProgramme
7 sections, 40 slides and 8 quizzes in total. Each content section ends with a quiz that checks it has been learned.
- IntroductionGratuit
Why the GDPR already applies to you
Identify your real role in the data processing carried out by your organisation.
- 4 slides
- SectionAbonnés
What you really handle
Recognise personal data, sensitive data and a processing operation in your own work.
- 6 slides
- Quiz de section : 5 questions
- SectionAbonnés
Why you collect, and for how long
Link every collection to a purpose, a legal basis and a written retention period.
- 7 slides
- Quiz de section : 5 questions
- SectionAbonnés
Data subject rights and how to respond to them
Identify a rights request and respond to it within the legal deadline.
- 6 slides
- Quiz de section : 5 questions
- SectionAbonnés
Sharing, outsourcing, hosting elsewhere
Check what a service provider does with your data before entrusting it to them.
- 7 slides
- Quiz de section : 5 questions
- SectionAbonnés
The day a piece of data gets away from you
Recognise a data breach and trigger the right response immediately.
- 7 slides
- Quiz de section : 5 questions
- RécapitulatifAbonnés
Your action plan
Turn the principles covered into steps you can apply in the coming week.
- 3 slides
36 slides sont réservées aux abonnés
Les quatre premières slides de cette formation se lisent sans compte et sans carte bancaire. À partir de la cinquième, l'abonnement à 29,99 € TTC/mois est nécessaire. Le quiz de niveau Découverte, lui, reste gratuit : il mesure votre niveau sans rien vous demander.
How your level is measured
- Beginner
- Questions drawn
- 10
- Pass mark
- 70 %
- Question bank
- ≥ 30
- Time limit
- 20 min
Free, no account and no subscription.
- Intermediate
- Questions drawn
- 12
- Pass mark
- 75 %
- Question bank
- ≥ 36
- Time limit
- 24 min
Subscribers only, once the Beginner level is passed.
- Expert
- Questions drawn
- 15
- Pass mark
- 80 %
- Question bank
- ≥ 45
- Time limit
- 30 min
Subscribers only, once the Intermediate level is passed.
The level shown for a course is the highest level you have passed, with your best score and its date. Questions are drawn at random on every attempt. Play the Beginner quiz for this course or read how we measure your level.
Which jobs is it for?
Common core: the examples change with your job, what is taught stays the same. It addresses all 45 jobs in the directory. See courses by job.
Frequently asked questions
Does this course replace the advice of a lawyer?
No, and it does not claim to. It explains general obligations and refers each time to the legal text or official publication that carries them. A question specific to your organisation is a matter for your data protection officer or a legal professional. This course has not yet been reviewed by a named legal professional: that notice is displayed until such a review has taken place.
Do you need to be a data protection officer to take this course?
No. It is written for people who handle data without holding a compliance role: reception, administration, production, line management. The documentation obligations are explained from the point of view of the person who feeds them, not the person who steers them.
My organisation is small; are we really concerned?
Yes. The Regulation sets no headcount threshold for its application. The CNIL, the French data protection authority, describes a very limited exemption from keeping the record of processing activities for organisations with fewer than two hundred and fifty employees, which exempts them neither from the principles, nor from data subject rights, nor from the conduct required in the event of a breach.
What is the deadline for responding to a request for access to one's data?
The CNIL reminds organisations that the standard deadline is one month from receipt of the request, based on Article 12.3 of the Regulation. A two-month extension is possible because of the complexity or the number of requests, provided the person is informed within one month of receipt.
How quickly must a data leak be reported?
The CNIL states that the controller notifies the breach without undue delay and, where feasible, no later than seventy-two hours after becoming aware of it, when the breach presents a risk to people's rights and freedoms. An initial notification can be completed afterwards.
Is a provider hosted in France enough to settle the question of transfers?
Not automatically. What matters is the place of processing and the law the provider is subject to, including through its own sub-processors. The course explains how to put those two questions to a supplier and what to ask for in writing in the contract.
What can I read without a subscription?
The first four slides of every course are available without an account and without a subscription, as is the Beginner level quiz. From the fifth slide onwards, the €29.99/month incl. VAT subscription is required. Creating a free account unlocks no extra slide: it keeps your progress, your job and your results.
How is my level measured?
By three level quizzes: Beginner (10 questions, 70 % to pass), Intermediate (12 questions, 75 %) and Expert (15 questions, 80 %). The level shown is the highest level passed, with the best score obtained and its date.
Who writes and who reviews this course
Équipe éditoriale de skillrung.com
L'équipe éditoriale de skillrung rédige les formations à partir des publications des autorités françaises et européennes : ANSSI, CNIL, Cybermalveillance.gouv.fr, Légifrance et EUR-Lex. Chaque affirmation chiffrée est rattachée à sa source primaire, datée et vérifiable depuis la page de la formation. L'équipe ne se substitue pas à un relecteur expert : toute formation destinée à la publication est relue par un professionnel nommé du domaine concerné, dont le nom et la date de relecture figurent sur la fiche de la formation.
Review by a subject-matter expert under way
This course is written by our editorial team from dated primary sources, and its review by an external subject-matter expert is under way. Last updated: .
We invent no name, no title and no qualification to look the part. Our production process is described in detail on the page our method.
Artificial intelligence assisted the drafting. Editorial responsibility for the published text remains human.
Statements with regulatory scope verified on .
Sources
Every figure stated in this course points to a primary source, dated and verifiable.
- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD)
EUR-Lex, Union européenne, published on
- Le registre des activités de traitement
CNIL, published on
- Les bases légales d'un traitement de données personnelles
CNIL, published on
- Les durées de conservation des données
CNIL, published on
- Professionnels : comment répondre à une demande de droit d'accès ?
CNIL, published on
- Travailler avec un sous-traitant
CNIL, published on
- Notifier une violation de données personnelles
CNIL, published on
- Transférer des données hors de l'Union européenne
CNIL, published on
What Skillrung is not
- Skillrung is not a French training body certified under the Qualiopi scheme.
- As things stand, our content is not eligible for the French CPF, OPCO, DPC or FAF funding schemes.
- A Skillrung certificate of completion is not a diploma, not a professional title and not a qualification registered in any national register. It records a result obtained in an unsupervised online assessment, on a given date.
- Taking a Skillrung course does not make your organisation compliant and does not replace the obligations that fall on your employer or on you.
- Our content is educational. It is neither legal advice, nor medical advice, nor a security audit.
- For a self-employed professional or a company, the subscription is a deductible business expense : confirm this with your accountant.
Keep going on Skillrung
The pages that follow on from this one, in the recommended order.
- Compliance & personal data courses
- Backing up your work data: what, where and how often
- What data can you share with an AI: the four confidentiality levels
- Digital culture at work: find your level
- Personal data at the office: test your reflexes
- Who writes this: Équipe Skillrung
- The course catalogue
- Courses by job
- Practical guides
- Free quizzes
- Our teaching method
- The subscription and its price