GDPR essentials

Essentials plan

Five short modules for all staff: recognise personal data, collect only what is needed, send to the right recipient, report a breach, pass on a GDPR request.

  • 9 min
  • 5 modules
  • 15-question check
  • English · Français
  • Attestation

You will be able to

  • Recognise personal data, direct or indirect
  • Collect only what the purpose needs
  • Check the full address, not the autocomplete
  • Recognise a personal data breach, accidental ones included
  • Recognise a data subject request without magic words

Programme

5 modules · 9 min
  1. Personal data, or not? 2 min
    • Recognise personal data, direct or indirect
    • Recognise sensitive data (GDPR Article 9)
    • When in doubt, treat it as personal data and ask the DPO
  2. Just what we need 2 min
    • Collect only what the purpose needs
    • Don't reuse data for a new purpose without a check
    • Keep data only for its retention period, then delete or anonymise
  3. The wrong recipient 1 min
    • Check the full address, not the autocomplete
    • Use BCC or the right tool for group mails
    • Open the attachment before sending: hidden tabs and columns
    • Share sensitive files through a controlled link, never via personal tools
  4. Report it within the hour 2 min
    • Recognise a personal data breach, accidental ones included
    • Report it at once through the usual channel: what, when, which data
    • Know that the company decides about notifying the CNIL and the people concerned
  5. “Send me everything you have on me” 2 min
    • Recognise a data subject request without magic words
    • Know the one-month deadline
    • Forward it the same day to the DPO, without answering, filtering or deleting anything yourself
  6. Knowledge check

    15 questions, pass mark 80 %. Explanations after each answer; you can try again.

  7. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Version 1 · updated October 3, 2026