From may 25, 2018, all companies using personal data must implement a personal data governance policy.
A personal data is simply a data allowing the identification of an individual. The name, address, phone, IP of a computer, ... are personal data.
The CNIL (National Commission of Informatique and Liberty) has published a 6-step guide to setting up confidentiality governance :
https://www.cnil.fr/sites/default/files/atoms/files/pdf_6_etapes_interactifv2.pdf
For further information : http://ec.europa.eu/justice/data-protection/index_en.htm
In the event of a failure in the management of personal data, the incurred expenses may be up to 4% of the turnover or 20 million euros (the highest of the 2).
If you use personal or sensible data, make sure to:
- clearly define the aims of your study
- define a responsible for treatment
- secure all your data at all levels
Often, we can work on aggregated or encrypted data. This is a good way to hide personal data, but be careful in the steps upstream of these transformations.
Cnil condamnation in 2018 :
The best way to get IT support is to use the new
Service One Platform.