Managers pack: the team lead's reflexes

Complete plan

The manager's reflexes: close access when someone leaves the team, react well when a team member says "I clicked", get unused access handed back, report a data breach within the hour and pass the GDPR gates of a new project.

  • 12 min
  • 5 modules
  • 15-question check
  • English · Français
  • Attestation

You will be able to

  • Request the access removal of someone who leaves, for their last day, through the usual channel, contractors, interns and temps included
  • Welcome a team member's report without blame, so the next one comes just as fast
  • Understand why unused access is a risk (stolen account, former employee)
  • Recognise a personal data breach, accidental ones included
  • Involve the DPO at the start of a project that uses personal data

Programme

5 modules · 12 min
  1. Leaving or changing role: nothing stays open 3 min
    • Request the access removal of someone who leaves, for their last day, through the usual channel, contractors, interns and temps included
    • Organise the handover before they leave: shared mailboxes, files, groups and links they created
    • Recover the equipment, have the shared passwords they knew changed, and review who still has access to the team's folders
    • When someone changes role, request removal of the old access, not just the new access
  2. "I clicked": the manager's first reflex 3 min
    • Welcome a team member's report without blame, so the next one comes just as fast
    • Escalate immediately through the usual channel (IT, security, the DPO for personal data)
    • Keep the evidence and don't run your own investigation: delete nothing, switch nothing off, don't open or spread the message
  3. Access you no longer need 2 min
    • Understand why unused access is a risk (stolen account, former employee)
    • Report access you no longer need when you change role or project
    • Answer an access review honestly, and leave without keeping copies
  4. Report it within the hour 2 min
    • Recognise a personal data breach, accidental ones included
    • Report it at once through the usual channel: what, when, which data
    • Know that the company decides about notifying the CNIL and the people concerned
  5. New project: three GDPR gates 2 min
    • Involve the DPO at the start of a project that uses personal data
    • Check a supplier: processor contract, hosting, access and transfers outside the European Union
    • Check before go-live: record, information, retention, people's requests, need for a DPIA
  6. Knowledge check

    15 questions, pass mark 80 %. Explanations after each answer; you can try again.

  7. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Version 1 · updated October 6, 2026