Administrative9 min read

GDPR for French training providers: how to protect your learners' data

A training organisation processes sensitive personal data from its very first learner: contact details, professional situation, assessment results, and sometimes information related to disability or health. The General Data Protection Regulation (GDPR) applies fully, regardless of the size of the organisation — and the CNIL, France’s data protection authority, has explicitly flagged training providers as a sector to watch. Here are the concrete obligations to put in place, without unnecessary legal jargon.

Why training organisations are particularly exposed

Contrary to a common assumption, GDPR doesn’t only target large companies. A training organisation, even a sole trader, processes personal data the moment it collects an enrolment form, an attendance sheet, or an entry-level assessment. Several features of the activity heighten the exposure:

  • Volume and recurrence: every session generates new data (identity, contact details, results), processed continuously rather than occasionally.
  • Potential sensitivity: exchanges with the disability accessibility contact sometimes involve health data, a special category under Article 9 of the GDPR.
  • Multiple recipients: funders (OPCOs, France Travail), the EDOF platform for CPF-eligible courses, and technical providers (LMS, management software, email tools) all receive some or all of this data.

The processing register: the foundational document

Article 30 of the GDPR requires every data controller to keep a register of processing activities, listing for each activity (enrolment management, attendance, satisfaction surveys, commercial prospecting…) the purpose pursued, the categories of data and individuals concerned, the recipients, the retention periods, and the associated security measures.

The exemption for organisations with fewer than 250 employees only covers occasional processing, without particular risk and not involving sensitive data. Since tracking learners is a recurring, structural activity, it almost never falls into that category: in practice, nearly every training organisation — even the smallest — must keep a register, even a simplified one. The CNIL provides a free template to handle this without excessive complexity.

Do you need to appoint a Data Protection Officer (DPO)?

Appointing a DPO is only mandatory in specific situations: regular and systematic large-scale monitoring of individuals, or large-scale processing of sensitive data (health data, in particular). A modest-sized training organisation, without large-scale profiling activity, is generally not required to appoint one.

That doesn’t remove the need to organise compliance: designating an internal GDPR contact — often the founder themselves in a small structure — who centralises the register, rights requests, and processor oversight is recommended practice, even without a strict legal obligation to appoint a formal DPO.

Learners’ rights, and the deadlines to respect

The GDPR grants each learner enforceable rights: access to their data, rectification, erasure, portability, objection, and restriction of processing. The organisation must be able to respond to any request within one month, extendable by two further months for complex requests, provided the person is informed.

In practice, this means knowing exactly where data is stored (management software, mailbox, LMS platform, shared spreadsheet) so it can be found, corrected, or deleted quickly — a point often overlooked once tools have piled up over time without central organisation.

Your providers are processors under GDPR

As soon as a training organisation entrusts data to an external provider — management software, LMS platform, email tool, hosting provider — that provider becomes a processor under Article 28 of the GDPR. A written contract must govern this relationship and specify in particular:

Required element What it covers
Subject and duration of processing The exact scope of operations entrusted to the provider
Nature and purpose of the data Types of data processed and the objective pursued
Security obligations Technical and organisational measures required of the provider
Sub-processing Prior authorisation if the provider itself uses further sub-processors
Assistance with individual rights How the provider helps respond to learner requests
Fate of the data at contract end Guaranteed return or deletion upon termination

Most serious software vendors (LMS, training CRM) provide a standard GDPR clause or DPA (Data Processing Agreement). Check it exists before signing, rather than discovering its absence during an inspection.

The special case of data shared via EDOF

For any CPF-eligible course, the organisation transmits learner data to the Caisse des Dépôts via the EDOF platform: identity, contact details, progress, assessments. This transmission is governed by EDOF’s terms of use, but it doesn’t remove the organisation’s own obligations toward the learner — notably informing them about the recipients of their data, as part of the privacy policy shared before enrolment. See our article on EDOF and CPF registration for the general framework of this relationship.

Security and breach notification

The GDPR requires implementing security measures proportionate to the risk: restricted data access, strong passwords, backups, encryption for sensitive exchanges. In the event of a breach (loss, theft, unauthorised access) likely to create a risk for the individuals concerned, the organisation must:

  1. Notify the CNIL within 72 hours of discovering the incident, via the dedicated online service.
  2. Individually inform affected learners if the risk to their rights and freedoms is high.
  3. Document the incident in an internal breach register, even when notifying the CNIL isn’t required.

The link with Qualiopi compliance

The Référentiel National Qualité doesn’t include an indicator dedicated exclusively to GDPR, but Indicator 23 on legal and regulatory monitoring covers knowledge and application of the obligations that apply to the organisation — GDPR included. An auditor can legitimately ask how you monitor this: who handles it, how often, and how regulatory changes get reflected in your practices (updating the register, processor contracts, the privacy policy).

Documenting your GDPR compliance, even briefly, therefore indirectly strengthens your audit file — and avoids a compliance scramble triggered in a hurry by a complaint or an inspection.

Take action

GDPR compliance can’t be improvised at the moment of an inspection: it’s built from the moment the organisation is created, alongside its other administrative obligations and Qualiopi audit preparation. The Kit Qualiopi Complet provides processing register and confidentiality clause templates suited to a training organisation; the ebook Créer son organisme de formation en 30 jours structures all your administrative steps in order; and the combined pack brings both together to secure your compliance from your very first learner.

FAQ

Frequently asked questions

+Does a training organisation have to appoint a Data Protection Officer (DPO)?

Not automatically. Appointing a DPO is only mandatory in specific cases defined by the GDPR: regular and systematic large-scale monitoring of individuals, or large-scale processing of special category data. Most small training providers aren't required to, but can appoint an internal GDPR contact as good practice.

+Is the processing register mandatory for a small training organisation?

Yes, in almost every case. The exemption under GDPR Article 30.5 for organisations with fewer than 250 employees only applies to occasional, low-risk processing that doesn't involve special category data. Tracking learners (enrolments, assessments, attendance) is a recurring, non-occasional activity, so nearly every training organisation must keep a register, even a simplified one.

+What must a GDPR clause in a contract with a provider (LMS, management software) include?

The contract must specify the subject and duration of the processing, the nature and purpose of the data involved, the processor's security obligations, the conditions for any further sub-processing, the assistance provided for learners exercising their rights, and what happens to the data at the end of the contract (return or deletion), as required by GDPR Article 28.

+How quickly must a data breach be reported to the CNIL?

Within 72 hours of becoming aware of it, whenever the breach is likely to result in a risk to the rights and freedoms of the individuals concerned (GDPR Article 33). If the risk is high, affected learners must also be individually notified.

+Is GDPR compliance checked during a Qualiopi audit?

The Référentiel National Qualité doesn't have an indicator dedicated exclusively to GDPR, but Indicator 23 on legal and regulatory monitoring covers knowledge and application of the obligations that apply to the organisation, GDPR included. An auditor can legitimately ask how you keep track of this and where your compliance stands.

Read next