Skip to main content
Institute of Advanced Technological and Commercial Studies

Glossary

Personal data: anything relating to an identifiable person

Personal data relates to an identified or identifiable individual. Collecting it assumes a stated purpose, a defined retention period and rights available to the person concerned. The security applied stays proportionate to the risk involved.

What the notion covers

Personal data is any information relating to an identified or identifiable individual: name, number, address, technical identifier, image. Processing follows a few constant principles: a purpose stated before collection, strictly the quantity that purpose requires, a defined retention period, security proportionate to the risk, and rights the person concerned can exercise.

  • A purpose stated before collection, and honoured afterwards
  • Strictly the quantity required, kept for a defined period
  • Rights the person can exercise, within an announced time

Four questions to ask before collecting

The Cybersecurity programme has candidates build the technical measures: encryption, access control, logging, deletion at term. The Business Law and OHADA Compliance programme handles the contractual side, with the clause that frames a processor and the trace that makes compliance demonstrable.

  1. 01

    1 — The purpose

    Write down what the data serves, before collecting it: that sentence bounds everything else.

  2. 02

    2 — The quantity

    Collect what the purpose requires, and stop there: every superfluous field becomes a burden to protect.

  3. 03

    3 — The period

    Set a retention deadline and apply it automatically, with a record of the deletion.

  4. 04

    4 — The rights

    Organise access, correction and deletion on request, within a time that is announced and met.

Programmes that handle the subject

2 catalogue programmes put “Personal data” to work: 300 credits and 3000 taught hours in total. The official rule holds throughout — one credit stands for 25 hours of work, 10 of them taught. Every line below is recomputed from the programme page: level, duration, credits, taught volume and fees in Guinean francs appear exactly as filed in the official catalogue.

ProgrammeLevelDurationVolumeFees
Cybersecurity programme — Bac+5 levelMaster's degree2 years120 credits · 1200 taught hours7 500 000 GNF per year
Business Law and OHADA ComplianceBachelor's degree3 years180 credits · 1800 taught hours5 200 000 GNF per year

“Personal data” in practice

Is a technical identifier personal data?

As soon as it allows an individual to be traced, it falls under the same regime and the same obligations.

How do you demonstrate compliance?

Through a processing register, written purposes, applied retention periods and a record of requests handled.

Does the subject concern small organisations?

Yes, as soon as they handle customers, employees or job applications. The principles apply at the scale of the activity.

Personal data: anything relating to an identifiable person — Glossary | IHETC — IHETC