- Compliance & personal data
- 3 sections
- 14 slides
- 4 quizzes
- 20-30 min
Data breach: reacting in the first hour
A data breach is personal information seen, altered or made inaccessible without authorisation. An email sent to the wrong recipient is one, just as much as ransomware. The response comes down to very little: raise the alarm internally without delay, write down what happened and when, contain the spread, keep the traces, then let notification be decided at the right level. None of those steps requires you to already understand the extent of the damage.
- Written by Skillrung team
- Review by a subject-matter expert under way
- Updated on
What is this course about?
Recognise a data breach, hold the right course of action from the very first hours, and document the facts so that the decision goes to the right person.
This is a core course: the material taught is the same for everyone, only the examples, the tools mentioned and the people you deal with change with your job. It has 3 sections, of which 1 section is followed by a quiz, and reads in 20-30 min. The legal framework cited is French law.
This is not a matter for IT people
You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.
Key points
Four situations nobody ever reports spontaneously
None of them involves a hacker; all of them deserve to be reported.
- A work phone stolen, with no lock code
- A former colleague who keeps their access after leaving
- A box of paper files left in a waiting area
- A backup that has become unreadable, with no other copy available
What you will be able to do
- Understand what a data breach covers in ordinary working life.
- Recognise a data breach and trigger the right response immediately.
- Turn the principles covered into steps you can apply in the coming week.
The first 4 slides, free
What you read with no account and no card. Here, the generic version; in the player, the examples take the vocabulary of your job.
Try it, before you even create an account
Choose a job: the passage below is rewritten straight away. Nothing is saved, and no extra content opens.
No job selected: the generic version is being shown.
You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.
Real extract from the free slide “This is not a matter for IT people” of this course.
- FreeSlide 1 of 14 · A leak does not look like what you imagine
This is not a matter for IT people
You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.
- FreeSlide 2 of 14 · A leak does not look like what you imagine
Three reflexes to acquire
- Spot a data breach behind an unremarkable incident
- Carry out the right steps in the hour following the discovery
- Write an incident report your management can actually use
- FreeSlide 3 of 14 · A leak does not look like what you imagine
Four situations nobody ever reports spontaneously
None of them involves a hacker; all of them deserve to be reported.
- A work phone stolen, with no lock code
- A former colleague who keeps their access after leaving
- A box of paper files left in a waiting area
- A backup that has become unreadable, with no other copy available
- FreeSlide 4 of 14 · A leak does not look like what you imagine
Where do you stand?
One question before you start, with no score: it places what you would do the day the incident happens.
1 short questions, marked immediately, inside the course.
These 4 slides can be read in the player, with no account and no card.
Read the first slideProgramme
3 sections, 14 slides and 4 quizzes in total. Each content section ends with a quiz that checks it has been learned.
- IntroductionFree
A leak does not look like what you imagine
Understand what a data breach covers in ordinary working life.
- 4 slides
- SectionSubscribers
The day a piece of data gets away from you
Recognise a data breach and trigger the right response immediately.
- 7 slides
- Section quiz: 5 questions
- RecapSubscribers
Your action plan
Turn the principles covered into steps you can apply in the coming week.
- 3 slides
10 slides are for subscribers
The first four slides of this course can be read without an account and without a bank card. From the fifth on, the €29.99/month incl. VAT subscription is needed. The Beginner level quiz, though, stays free: it measures your level without asking you for anything.
How your level is measured
- Beginner
- Questions drawn
- 10
- Pass mark
- 70 %
- Question bank
- ≥ 30
- Time limit
- 20 min
Free, no account and no subscription.
- Intermediate
- Questions drawn
- 12
- Pass mark
- 75 %
- Question bank
- ≥ 36
- Time limit
- 24 min
Subscribers only, once the Beginner level is passed.
- Expert
- Questions drawn
- 15
- Pass mark
- 80 %
- Question bank
- ≥ 45
- Time limit
- 30 min
Subscribers only, once the Intermediate level is passed.
The level shown for a course is the highest level you have passed, with your best score and its date. Questions are drawn at random on every attempt. Play the Beginner quiz for this course or read how we measure your level.
Which jobs is it for?
Common core: the examples change with your job, what is taught stays the same. It addresses all 58 jobs in the directory. See courses by job.
Frequently asked questions
Is an email sent to the wrong person a data breach?
Yes, as soon as it contains information relating to identifiable people. The Regulation does not reserve the word for computer attacks: data seen by someone who had no right to see it is enough. A wrong-recipient error falls squarely within that definition. It is handled like any other: an internal report, a dated written record, then a decision taken at the right level.
Does the CNIL have to be told about every incident?
No, and it is not for you to decide. Notification depends on the risk the breach creates for the people concerned, and that assessment is made with management and, where there is one, the data protection officer. Your role stops at a precise point: report quickly, describe what you know, and destroy nothing. The CNIL provides an online service for this procedure.
What should you do if you discover a leak several days after the event?
You report it anyway, and you do it straight away. The starting point taken is the moment you gain reasonable certainty that a breach has affected personal data, not the date of the incident itself. A late discovery is documented: say when you found out, how you learned of it, and what you did next. Hiding the gap costs more than explaining it.
What can I read without a subscription?
The first four slides of every course are available without an account and without a subscription, as is the Beginner level quiz. From the fifth slide onwards, the €29.99/month incl. VAT subscription is required. Creating a free account unlocks no extra slide: it keeps your progress, your job and your results.
How is my level measured?
By three level quizzes: Beginner (10 questions, 70 % to pass), Intermediate (12 questions, 75 %) and Expert (15 questions, 80 %). The level shown is the highest level passed, with the best score obtained and its date.
Who writes and who reviews this course
Editorial team of skillrung.com
The skillrung editorial team writes the courses from the publications of the French and European authorities: ANSSI, CNIL, Cybermalveillance.gouv.fr, Légifrance and EUR-Lex. Every figure is tied to its primary source, dated and verifiable from the course page. The team does not stand in for an expert reviewer: every course intended for publication is reviewed by a named professional of the field concerned, whose name and review date appear on the course page.
Review by a subject-matter expert under way
This course is written by our editorial team from dated primary sources, and its review by an external subject-matter expert is under way. Last updated: .
We invent no name, no title and no qualification to look the part. Our production process is described in detail on the page our method.
Artificial intelligence assisted the drafting. Editorial responsibility for the published text remains human.
Statements with regulatory scope verified on .
Sources
Every figure stated in this course points to a primary source, dated and verifiable.
- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD)
EUR-Lex, Union européenne, published on
- Le registre des activités de traitement
CNIL, published on
- Les bases légales d'un traitement de données personnelles
CNIL, published on
- Les durées de conservation des données
CNIL, published on
- Professionnels : comment répondre à une demande de droit d'accès ?
CNIL, published on
- Travailler avec un sous-traitant
CNIL, published on
- Notifier une violation de données personnelles
CNIL, published on
- Transférer des données hors de l'Union européenne
CNIL, published on
What Skillrung is not
- Skillrung is not a French training body certified under the Qualiopi scheme.
- As things stand, our content is not eligible for the French CPF, OPCO, DPC or FAF funding schemes.
- A Skillrung certificate of completion is not a diploma, not a professional title and not a qualification registered in any national register. It records a result obtained in an unsupervised online assessment, on a given date.
- Taking a Skillrung course does not make your organisation compliant and does not replace the obligations that fall on your employer or on you.
- Our content is educational. It is neither legal advice, nor medical advice, nor a security audit.
- For a self-employed professional or a company, the subscription is a deductible business expense : confirm this with your accountant.
Same topic
The other compliance & personal data courses
Know what to ask for, what to put in writing and what to check before entrusting your data to a service provider, and what to do when it changes.
- 20-30 min
- 13 slides
- 4 quizzes
See the programmeSpot a rights request as soon as it arrives, get it moving the same day, and respond within the deadline without improvising.
- 20-30 min
- 13 slides
- 4 quizzes
See the programmeSpot, in your own files, what counts as personal data, what is sensitive, and what already counts as a processing operation.
- 20-30 min
- 13 slides
- 4 quizzes
See the programmeBe able to say why you hold each file, on what legal ground, and until what date you keep it.
- 20-30 min
- 13 slides
- 4 quizzes
See the programme
Keep going on Skillrung
The pages that follow on from this one, in the recommended order.
- Compliance & personal data courses
- Entrusting your data to a service provider without losing control
- Rights requests: spotting them and responding within the deadline
- Recognising personal data and processing in your everyday work
- Purpose, legal basis, retention period: justifying every file you hold
- Backing up your work data: what, where and how often
- Who writes this: Skillrung team
- The course catalogue
- Courses by job
- Practical guides
- Free quizzes
- Our teaching method
- The subscription and its price