# GDPR: the essentials for every employee and public-sector worker

URL : https://skillrung.com/en/courses/data-compliance/gdpr-essentials
Topic: Compliance & personal data · Duration: 60-80 min · Updated on 2026-09-11

## In brief

The GDPR governs any use of information relating to an identifiable person: a customer, a patient, a resident, a colleague. For a working professional, it comes down to four questions asked about every file in use: why is this data collected, on what legal basis, for how long, and who can access it. The record of processing activities, privacy notices and the response to a data breach are simply the written trace of those answers.

## Programme

- 1. Why the GDPR already applies to you : Identify your real role in the data processing carried out by your organisation
- 2. What you really handle : Recognise personal data, sensitive data and a processing operation in your own work
- 3. Why you collect, and for how long : Link every collection to a purpose, a legal basis and a written retention period
- 4. Data subject rights and how to respond to them : Identify a rights request and respond to it within the legal deadline
- 5. Sharing, outsourcing, hosting elsewhere : Check what a service provider does with your data before entrusting it to them
- 6. The day a piece of data gets away from you : Recognise a data breach and trigger the right response immediately
- 7. Your action plan : Turn the principles covered into steps you can apply in the coming week

5 content sections, each with its quiz. Three level quizzes: Beginner, Intermediate, Expert.

## Free preview (first 4 slides)

### 1. You process personal data every day

A spreadsheet of contact details, a list of registered people, a file open on your screen: you were using personal data long before you ever heard the word compliance. The EU General Data Protection Regulation (GDPR) has applied across the Union, France included, since 25 May 2018, and it is not aimed only at large organisations. As soon as a piece of information relates to an identifiable person, it applies, including at your structure, and it covers données personnelles first and foremost.
  - The General Data Protection Regulation has applied throughout the European Union since 25 May 2018. (EUR-Lex, Union européenne, 2016-04-27, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32016R0679)

### 2. What you will be able to do by the end

- Recognise données personnelles in your files
- Respond to a rights request within the legal deadline
- React within the first hour to a data leak

### 3. Four questions to ask about any file

Ask them before creating a file, and go back over the ones already sitting in your logiciel métier or in your spreadsheets.
- Why is this data collected, and for what precise use?
- What authorises the collection: the law, a contract, consent?
- How long does it stay useful, and what happens to the file afterwards?
- Who can view it, internally and at a service provider?

### 4. Three questions to see where you stand

Three quick questions, with no score and no judgement: what you would do if the CNIL asked to see your files.
_Self-assessment of 3 questions in the player._

## Access

The first four slides of every course and the Beginner-level quiz are free, with no account. From the fifth slide onwards a subscription is required: €29.99/month incl. VAT, no commitment, cancellable online. skillrung is not a French training body certified under the Qualiopi scheme; its content is not eligible for the French CPF, OPCO or DPC schemes.

## Frequently asked questions

### Does this course replace the advice of a lawyer?

No, and it does not claim to. It explains general obligations and refers each time to the legal text or official publication that carries them. A question specific to your organisation is a matter for your data protection officer or a legal professional. This course has not yet been reviewed by a named legal professional: that notice is displayed until such a review has taken place.

### Do you need to be a data protection officer to take this course?

No. It is written for people who handle data without holding a compliance role: reception, administration, production, line management. The documentation obligations are explained from the point of view of the person who feeds them, not the person who steers them.

### My organisation is small; are we really concerned?

Yes. The Regulation sets no headcount threshold for its application. The CNIL, the French data protection authority, describes a very limited exemption from keeping the record of processing activities for organisations with fewer than two hundred and fifty employees, which exempts them neither from the principles, nor from data subject rights, nor from the conduct required in the event of a breach.

### What is the deadline for responding to a request for access to one's data?

The CNIL reminds organisations that the standard deadline is one month from receipt of the request, based on Article 12.3 of the Regulation. A two-month extension is possible because of the complexity or the number of requests, provided the person is informed within one month of receipt.

### How quickly must a data leak be reported?

The CNIL states that the controller notifies the breach without undue delay and, where feasible, no later than seventy-two hours after becoming aware of it, when the breach presents a risk to people's rights and freedoms. An initial notification can be completed afterwards.

### Is a provider hosted in France enough to settle the question of transfers?

Not automatically. What matters is the place of processing and the law the provider is subject to, including through its own sub-processors. The course explains how to put those two questions to a supplier and what to ask for in writing in the contract.

## Sources

- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD) : EUR-Lex, Union européenne, 2016-04-27, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32016R0679
- Le registre des activités de traitement : CNIL, 2026-09-11, https://www.cnil.fr/fr/RGPD-le-registre-des-activites-de-traitement
- Les bases légales d'un traitement de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-bases-legales
- Les durées de conservation des données : CNIL, 2026-09-11, https://www.cnil.fr/fr/passer-laction/les-durees-de-conservation-des-donnees
- Professionnels : comment répondre à une demande de droit d'accès ? : CNIL, 2026-09-11, https://www.cnil.fr/fr/repondre-une-demande-de-droit-dacces
- Travailler avec un sous-traitant : CNIL, 2026-09-11, https://www.cnil.fr/fr/sous-traitant
- Notifier une violation de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/services-en-ligne/notifier-une-violation-de-donnees-personnelles
- Transférer des données hors de l'Union européenne : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-outils-de-la-conformite/transferer-des-donnees-hors-de-lue
