From may 25, 2018, all companies using personal data must implement a personal data governance policy.
The CNIL (National Commission of Informatique and Liberty) has published a 6-step guide to setting up confidentiality governance :
https://www.cnil.fr/sites/default/files/atoms/files/pdf_6_etapes_interactifv2.pdf
Cnil condamnation in 2018 :
The best way to get IT support is to use the new
Service One Platform.