# Recognising personal data and processing in your everyday work

URL : https://skillrung.com/en/courses/data-compliance/personal-data-and-processing
Topic: Compliance & personal data · Duration: 20-30 min · Updated on 2026-09-15

## In brief

Personal data is any information that makes it possible to identify someone, directly or indirectly, on its own or combined with another: a staff number or a case number is personal data. Processing covers the ordinary actions of work, from viewing a file to deleting it. Sensitive data, for its part, follows a stricter rule: processing it is prohibited in principle, unless an exception expressly provided for by the Regulation applies.

## Programme

- 1. Your files, seen differently : Take stock of what you handle before naming data, processing operations and sensitive categories
- 2. What you really handle : Recognise personal data, sensitive data and a processing operation in your own work
- 3. Your action plan : Turn these markers into actions applied to your own files as early as this week

1 content sections, each with its quiz. Three level quizzes: Beginner, Intermediate, Expert.

## Free preview (first 4 slides)

### 1. Your ordinary files are already processing operations

You open a file, you export a list, you send it to two colleagues, you archive the lot. None of that looks like law. Yet every one of those actions has a name in the Regulation, and the files concerned are not only the ones in your business software: they are also the spreadsheets that live alongside it, in your structure. Start by learning to recognise them.

### 2. What you will be able to spot afterwards

- Spot indirect identification in a file with no names
- Name the everyday actions that are already processing operations
- Tell sensitive categories apart from the rest of your data

### 3. Four markers to keep in mind

Four markers this section sets out, in the order in which you will meet them.
- Indirect identification is enough: staff number, case number, identifier
- Viewing, copying, sending, deleting: all of them processing operations
- Sensitive data follows a stricter rule
- The working copy is the most forgotten processing operation

### 4. Where do you stand?

One question before we get to the heart of it, with no score and no judgement: it is about the line between a harmless file and personal data.
_Self-assessment of 1 questions in the player._

## Access

The first four slides of every course and the Beginner-level quiz are free, with no account. From the fifth slide onwards a subscription is required: €29.99/month incl. VAT, no commitment, cancellable online. skillrung is not a French training body certified under the Qualiopi scheme; its content is not eligible for the French CPF, OPCO or DPC schemes.

## Frequently asked questions

### Is a file that contains no names really covered?

Yes, as soon as it leads back to someone. A staff number, a case number or an access identifier point to a person by cross-referencing, and that indirect identification is enough. So the useful question is not “is there a name?”, but “can we tell who this is, on its own or by cross-checking with another file?”.

### What makes a piece of data “sensitive” rather than ordinary?

The fact that it belongs to a category the Regulation lists: health, political opinions, religious beliefs, trade union membership, alleged racial or ethnic origin, sex life or sexual orientation, genetic data and biometric data used to identify a person. Processing it is prohibited in principle, unless an exception expressly provided for by the Regulation applies. Offences and convictions, for their part, fall under a separate regime, itself strictly framed.

### Does the spreadsheet I keep alongside the software really count?

Yes, and it is the one that gets forgotten. A list that has been exported and then annotated carries personal data, goes out to recipients and has a lifespan: a processing operation in its own right. The reflex to acquire comes down to one decision taken before the export — when it will be deleted, and by whom.

## Sources

- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD) : EUR-Lex, Union européenne, 2016-04-27, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32016R0679
- Le registre des activités de traitement : CNIL, 2026-09-11, https://www.cnil.fr/fr/RGPD-le-registre-des-activites-de-traitement
- Les bases légales d'un traitement de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-bases-legales
- Les durées de conservation des données : CNIL, 2026-09-11, https://www.cnil.fr/fr/passer-laction/les-durees-de-conservation-des-donnees
- Professionnels : comment répondre à une demande de droit d'accès ? : CNIL, 2026-09-11, https://www.cnil.fr/fr/repondre-une-demande-de-droit-dacces
- Travailler avec un sous-traitant : CNIL, 2026-09-11, https://www.cnil.fr/fr/sous-traitant
- Notifier une violation de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/services-en-ligne/notifier-une-violation-de-donnees-personnelles
- Transférer des données hors de l'Union européenne : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-outils-de-la-conformite/transferer-des-donnees-hors-de-lue
