Resources
Protecting personal data
Handling personal data commits an organisation on five points: the purpose pursued, the basis authorising it, the amount collected, the retention period and the security applied. Each is documented in a few lines.
Five lines per processing activity
A processing register describes, for each use of personal data, what the organisation pursues and what authorises it. The purpose is stated in one concrete sentence: managing orders, sending a newsletter, tracking applications. The amount collected follows from that purpose and nothing more. Retention follows from use, security follows from sensitivity. The document lives in a spreadsheet, it is updated with every new service, and it is the first item requested in an inspection.
- A concrete purpose, stated in one sentence
- The basis authorising the processing, identified for each use
- Only the data the purpose makes necessary
- A retention period, and the action applied at its term
- Security measures, proportionate to sensitivity
The rights individuals exercise
Know what is held
A person requests a copy of the data concerning them. An up-to-date register makes the answer fast and accurate.
Have it corrected
Inaccurate data is corrected on request. The process is planned for, like any customer request.
Ask for erasure
Once the purpose is fulfilled, the data is erased. The written rule makes the decision simple and traceable.
Retrieve their data
An export in a machine-readable format. Designed in, it costs one function; added later, a project.
The programmes covering the subject
Law, security and transformation management approach data protection through three different doors. Taught volumes and fees appear exactly as published in the catalogue.
| Programme | Level | Duration | Credits and hours | Fees |
|---|---|---|---|---|
| Business Law and OHADA Compliance | Bachelor's degree | 3 years | 180 credits · 1800 h | 5 200 000 GNF per year |
| Cybersecurity programme — Bac+5 level | Master's degree | 2 years | 120 credits · 1200 h | 7 500 000 GNF per year |
| Digital Transformation Certificate | Professional certification | 6 months | 18 credits · 180 h | 3 600 000 GNF in total |
Common questions
Does a small company need a register?
As soon as it handles customer, employee or applicant data, a register serves it well: it makes requests fast to handle and inspections simple to prepare. One page per activity is enough, and the exercise often reveals collections that no longer have a purpose.
How do I handle data hosted abroad?
By documenting the location, the applicable jurisdiction and the contractual guarantees obtained, then verifying reversibility with a tested export. Those three elements are what an inspection asks for, and they fit in the governance table.
Who carries responsibility in the organisation?
Management, which delegates operational follow-up to an identified person. The business law and compliance programme works on that split, and the financial compliance certificate applies it to institutions under prudential supervision.
Explore next
- Industrial site safetyHSE management system, work permits, co-activity, internal audit, leading indicators and safety culture: a site's complete arrangement.
- Assessing a riskHazard, exposure, criticality, risk register and the hierarchy of prevention measures: risk assessment applied to a real workstation.
- Incident investigationFact gathering, causal tree, root causes, action plan and lessons learned: conducting an investigation after an incident or a near miss.
- Cybersecurity reflexesIdentities and permissions, updates, tested backups, network segmentation and awareness: the measures that protect most for the least effort.
- Responding to an incidentDetection, containment, eradication, restoration, evidence collection and the post-incident report: the response procedure and what it requires you to prepare.
- Service continuityAcceptable downtime, acceptable data loss, backups, switchover, power and drills: building a verifiable continuity plan.