Skip to content
Cyber Experts

Glossary

RGPD

European regulation (effective 2018) governing the collection and processing of personal data, with fines up to 4% of revenue.

The GDPR (General Data Protection Regulation) applies to any organisation processing personal data of EU residents, regardless of size or location. For a small French business, the main obligations are: keep a record of processing activities, inform data subjects, secure the data, notify any breach to the supervisory authority within 72 hours, and designate a DPO when activities require it.

Supervisory authority fines can reach 4% of global revenue, but in practice for SMBs, the most material risk isn't the fine — it's losing B2B contracts. More and more enterprise customers now refuse to contract with a supplier whose GDPR compliance isn't demonstrated.

GDPR controls overlap heavily with cybersecurity controls: access security, data encryption, traceability, vendor management. That's why the Essentials training includes a light GDPR register + a compliant supplier clause — not to make you a lawyer, but to check the technical boxes B2B customers look at.