Service · Cybersecurity

GDPR and personal data protection

The GDPR asks for appropriate technical and organisational measures and then stops talking. In practice the question only reaches the IT side after something goes wrong: a payroll file sent to the wrong address, or an accountancy firm discovering that a colleague who left in March can still open the file server from home. Our job is to convert that broad wording into settings you can point at during an inspection: who sees what, what the logs keep, and what is encrypted the moment it leaves your premises.

GDPR
turned into working settings
72 hours
to notify the CNIL
One person
one named account, no shared logins
In waves
no pause in daily work

Where this service reaches

What we cover follows what you hold. A patient file does not call for the same defences as a mailing list, and we avoid building protection that the actual risk does not justify.

Put your scope to an engineer

Mapping the processing

We look for where the data genuinely sits: payroll software, the sales system, SharePoint, network shares, mailbox attachments and forgotten spreadsheet exports on a sales laptop. That inventory feeds straight into your record of processing activities.

Named accounts

Shared logins such as reception or accounts, with the password on a label stuck to the monitor, give way to named accounts in Entra ID or Google Workspace. From then on every action belongs to a person.

Audit logging

We switch on Microsoft 365 auditing and access tracking on file shares, and keep records long enough to reconstruct who opened what once an incident comes to light.

Encryption

BitLocker or FileVault on laptops, encrypted mail for documents in the special categories, and TLS on everything that travels from your network to an outside party.

Leavers and movers

A routine agreed with HR: access ends on the last day of the contract, including in online services outside your directory such as a recruitment tool or an invoicing platform.

Handling a breach

A one-page card for the first few hours: who assesses the incident, who calls the DPO, who drafts the notification to the CNIL, and which logs must be frozen before they roll over.

The way an engagement runs

We start with the gaps that pay back most for the least effort. Heavier work waits until the foundations hold.

01

Review

A video call with whoever owns the data, or with your DPO, followed by a remote look at the environment. You end up with a list of systems holding personal data and how well each is protected today.

02

Quick wins

Shared accounts, accounts of people who have left and sign-ins without a second factor all disappear. The effect is immediate and the cost close to nothing.

03

Technical work

Encryption, logging, a sane permission tree and tighter external sharing, rolled out in batches so that no team is left waiting.

04

Written measures

You receive a description of the protection now in place, drafted to sit inside your GDPR documentation and to be handed over unchanged if anyone asks.

Most data breaches are not break-ins. They are emails sent to the wrong recipient, mislaid storage devices and accounts belonging to people who left two years ago. Everyday habits and well-configured systems therefore matter far more than any expensive product.

Questions and answers

Give them a route that is easier than the one they use, because a ban with no alternative lasts about a week. A restricted OneDrive or SharePoint folder with automatic deletion after an agreed period covers it nearly every time. Add a one-page instruction and, on phones enrolled in Intune, block saving work files into personal apps.

Yes, provided the transfer rests on a valid basis, and the simplest answer is to keep the data in European regions. We check where your services actually store it and pin the European region wherever the vendor allows; OVHcloud and Scaleway make that straightforward. Reviewing the processing contracts belongs to your DPO or your lawyer.

Write to support@apply.fr at once, or to helpme@apply.fr if you are under contract with us. We help you cut off the source, freeze the logs before they are overwritten and measure what was exposed, so that your DPO or counsel can decide in time whether to notify the CNIL and, where relevant, the people affected. The legal judgement stays with them.

Long enough to notice an incident and then investigate it. Intrusions often surface weeks later, while the default retention in many services is far shorter. We set the period against how sensitive the data is and what storage costs, then write the decision into your documentation.

That depends on the nature and scale of your processing, and it is a legal question for counsel rather than for an IT provider. Where a DPO is already appointed, in-house or external, we work with them directly and answer their technical questions, including groundwork for a data protection impact assessment.

Put your personal data in order

Tell us which systems hold information about your clients and your staff. We reply with a first read on where the usual gaps tend to be.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.