# Data breach: reacting in the first hour

URL : https://skillrung.com/en/courses/data-compliance/responding-to-a-data-breach
Topic: Compliance & personal data · Duration: 20-30 min · Updated on 2026-09-15

## In brief

A data breach is personal information seen, altered or made inaccessible without authorisation. An email sent to the wrong recipient is one, just as much as ransomware. The response comes down to very little: raise the alarm internally without delay, write down what happened and when, contain the spread, keep the traces, then let notification be decided at the right level. None of those steps requires you to already understand the extent of the damage.

## Programme

- 1. A leak does not look like what you imagine : Understand what a data breach covers in ordinary working life
- 2. The day a piece of data gets away from you : Recognise a data breach and trigger the right response immediately
- 3. Your action plan : Turn the principles covered into steps you can apply in the coming week

1 content sections, each with its quiz. Three level quizzes: Beginner, Intermediate, Expert.

## Free preview (first 4 slides)

### 1. This is not a matter for IT people

You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.

### 2. Three reflexes to acquire

- Spot a data breach behind an unremarkable incident
- Carry out the right steps in the hour following the discovery
- Write an incident report your management can actually use

### 3. Four situations nobody ever reports spontaneously

None of them involves a hacker; all of them deserve to be reported.
- A work phone stolen, with no lock code
- A former colleague who keeps their access after leaving
- A box of paper files left in a waiting area
- A backup that has become unreadable, with no other copy available

### 4. Where do you stand?

One question before you start, with no score: it places what you would do the day the incident happens.
_Self-assessment of 1 questions in the player._

## Access

The first four slides of every course and the Beginner-level quiz are free, with no account. From the fifth slide onwards a subscription is required: €29.99/month incl. VAT, no commitment, cancellable online. skillrung is not a French training body certified under the Qualiopi scheme; its content is not eligible for the French CPF, OPCO or DPC schemes.

## Frequently asked questions

### Is an email sent to the wrong person a data breach?

Yes, as soon as it contains information relating to identifiable people. The Regulation does not reserve the word for computer attacks: data seen by someone who had no right to see it is enough. A wrong-recipient error falls squarely within that definition. It is handled like any other: an internal report, a dated written record, then a decision taken at the right level.

### Does the CNIL have to be told about every incident?

No, and it is not for you to decide. Notification depends on the risk the breach creates for the people concerned, and that assessment is made with management and, where there is one, the data protection officer. Your role stops at a precise point: report quickly, describe what you know, and destroy nothing. The CNIL provides an online service for this procedure.

### What should you do if you discover a leak several days after the event?

You report it anyway, and you do it straight away. The starting point taken is the moment you gain reasonable certainty that a breach has affected personal data, not the date of the incident itself. A late discovery is documented: say when you found out, how you learned of it, and what you did next. Hiding the gap costs more than explaining it.

## Sources

- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD) : EUR-Lex, Union européenne, 2016-04-27, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32016R0679
- Le registre des activités de traitement : CNIL, 2026-09-11, https://www.cnil.fr/fr/RGPD-le-registre-des-activites-de-traitement
- Les bases légales d'un traitement de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-bases-legales
- Les durées de conservation des données : CNIL, 2026-09-11, https://www.cnil.fr/fr/passer-laction/les-durees-de-conservation-des-donnees
- Professionnels : comment répondre à une demande de droit d'accès ? : CNIL, 2026-09-11, https://www.cnil.fr/fr/repondre-une-demande-de-droit-dacces
- Travailler avec un sous-traitant : CNIL, 2026-09-11, https://www.cnil.fr/fr/sous-traitant
- Notifier une violation de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/services-en-ligne/notifier-une-violation-de-donnees-personnelles
- Transférer des données hors de l'Union européenne : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-outils-de-la-conformite/transferer-des-donnees-hors-de-lue
