GDPR essentials
Essentials plan
Five short modules for all staff: recognise personal data, collect only what is needed, send to the right recipient, report a breach, pass on a GDPR request.
- 9 min
- 5 modules
- 15-question check
- English · Français
- Attestation
You will be able to
- Recognise personal data, direct or indirect
- Collect only what the purpose needs
- Check the full address, not the autocomplete
- Recognise a personal data breach, accidental ones included
- Recognise a data subject request without magic words
Programme
5 modules · 9 min-
Personal data, or not? 2 min
- Recognise personal data, direct or indirect
- Recognise sensitive data (GDPR Article 9)
- When in doubt, treat it as personal data and ask the DPO
-
Just what we need 2 min
- Collect only what the purpose needs
- Don't reuse data for a new purpose without a check
- Keep data only for its retention period, then delete or anonymise
-
The wrong recipient 1 min
- Check the full address, not the autocomplete
- Use BCC or the right tool for group mails
- Open the attachment before sending: hidden tabs and columns
- Share sensitive files through a controlled link, never via personal tools
-
Report it within the hour 2 min
- Recognise a personal data breach, accidental ones included
- Report it at once through the usual channel: what, when, which data
- Know that the company decides about notifying the CNIL and the people concerned
-
“Send me everything you have on me” 2 min
- Recognise a data subject request without magic words
- Know the one-month deadline
- Forward it the same day to the DPO, without answering, filtering or deleting anything yourself
-
Knowledge check
15 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Version 1 · updated October 3, 2026