[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRUw_OFACW61cEkK4wJLl_-WmTPD9aBs0RYXeQ-7otIs":3},{"sections":4,"resultAnalysis":672,"id":920,"version":921,"newVersion":21,"label":922,"isPinned":21,"isShared":34,"sharingToken":923,"isRevision":21,"isBlockAnalysisShared":34,"nbReferences":924,"referenceId":9,"nbResponses":11,"parentId":9,"revisionDescription":9,"logoUrl":925,"description":926,"scheduleIntervalDays":9,"versionNumber":28,"dateCreation":927,"dateUpdate":928,"dateArchived":9,"archived":21,"type":929,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":929,"creator":930,"objectType":9,"defaultOwners":938,"tags":947,"privacyHubs":9,"nbQuestions":956,"nbQuestionsRequired":11,"nbDatas":11,"deadLineDays":9},[5,72,175,368,415,489,569],{"id":6,"slug":7,"label":8,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":13,"sections":71},"07672e02-1ed8-4ea1-b69d-fcdf8e4d50da","initial","Généralités",null,"Default",0,"SectionType_Default",[14,35,49],{"id":15,"slug":16,"label":17,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":22,"displayConditions":9,"answers":23,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"aa325032-49d6-41ae-91b7-2a5d64715faa","a24c5d23-4e37-4730-b80d-e748eb7e869b","Quand est entré en application le RGPD ? ","Radio",7,"Liste de cases à cocher (une seule réponse)",false,[],[24,30],{"id":25,"color":26,"rangeValue":9,"label":27,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":29},"0d23c141-3b27-423e-9393-e4d984a5059f","#ffffff","Le 25 mai 2018",1,[],{"id":31,"color":26,"rangeValue":9,"label":32,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":33},"be757c7b-c13f-4b2b-9456-1532c88ab48b","Le 24 mai 2016",[],true,{"id":36,"slug":37,"label":38,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":39,"displayConditions":9,"answers":40,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"fe3133dc-6986-464c-b24a-1087f437c337","640eb278-5c81-4dab-8928-a0933541c6df","A quoi sert le RGPD ? ",[],[41,45],{"id":42,"color":26,"rangeValue":9,"label":43,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":44},"52b56a44-6a7d-4bec-88cf-e5ee68ee2076","Renforcer la confiance des consommateurs dans l'offre de services numériques",[],{"id":46,"color":26,"rangeValue":9,"label":47,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":48},"0c6bb17e-98b3-46b5-994e-7f062e7a1041","Renforcer l'encadrement des pratiques en matière de collecte et d'utilisation des données à caractère personnel.",[],{"id":50,"slug":51,"label":52,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":53,"displayConditions":9,"answers":54,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"176ade0d-2aa1-42f9-835d-99d5fbbcae46","qui-est-concerne-par-le-rgpd-","Qui est concerné par le RGPD ?",[],[55,59,63,67],{"id":56,"color":26,"rangeValue":9,"label":57,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":58},"c7ed634d-a2b6-4e0d-b06e-5c83e4d0d880","Les organismes privés établis sur le territoire de l'Union européenne traitant des données personnelles",[],{"id":60,"color":26,"rangeValue":9,"label":61,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":62},"b51d0526-58b3-4758-9c18-f27528fe9b87","Les organismes publiques établis sur le territoire de l'Union européenne traitant des données personnelles",[],{"id":64,"color":9,"rangeValue":9,"label":65,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":66},"02de59cc-8a42-4333-b035-767b1972e176","Les organismes privés ou publiques établis sur le territoire de l'Union européenne ",[],{"id":68,"color":9,"rangeValue":9,"label":69,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":70},"714db8d1-16f1-40c4-94d1-1af5acdf8b10","Les organismes privés ou publiques traitant des données personnelles établis sur le territoire de l'Union européenne ou si leur activité cible directement des résidents européens",[],[],{"id":73,"slug":74,"label":75,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":76,"sections":174},"c9a411fb-fc19-45b2-b5c6-fd5cd329006b","donnees-personnelles-et-traitement-de-donnees-personnelles","Données personnelles et traitement de données personnelles",[77,91,107,117,129,139,153],{"id":78,"slug":79,"label":80,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":81,"displayConditions":9,"answers":82,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"a4bd4db1-13f0-4736-9d75-519d93f48295","quest-ce-quune-donnee-personnelle-","Qu'est-ce qu'une donnée personnelle ? ",[],[83,87],{"id":84,"color":26,"rangeValue":9,"label":85,"slug":9,"description":9,"score":9,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":86},"bfc1f3fe-78c4-499c-abed-00d88c02d254","Toute information se rapportant à une personne physique identifiée",[],{"id":88,"color":26,"rangeValue":9,"label":89,"slug":9,"description":9,"score":9,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":90},"588a87aa-81b5-4741-9696-756a8baea5b6","Toute information se rapportant à une personne physique identifiée ou identifiable",[],{"id":92,"slug":93,"label":94,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":95,"displayConditions":9,"answers":96,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"bc9b3127-8aef-495d-a0d9-35a9f2247c5f","une-donnee-chiffre-demeure-une-donnee-personnelle-_1","Une donnée chiffrée demeure une donnée personnelle ?",[],[97,102],{"id":98,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":101},"7c789ba6-c075-4a11-9a59-1ed205afd646","#1ab586","Oui",[],{"id":103,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":106},"b755a276-7cf0-4143-88ea-e8899813cce2","#dc3545","Non",[],{"id":108,"slug":109,"label":110,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":111,"displayConditions":9,"answers":112,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"e03fdb25-8e96-4d45-be4e-a529b4349ecf","une-donnee-chiffre-demeure-une-donnee-personnelle-","Une donnée codée demeure une donnée personnelle ?",[],[113,115],{"id":98,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":114},[],{"id":103,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":116},[],{"id":118,"slug":119,"label":120,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":121,"displayConditions":9,"answers":122,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"2f6506e2-1260-4f8f-ac67-94190e6a4ba9","une-donnee-anonymisee-demeure-une-donnee-personnelle-_1","Une donnée anonymisée demeure une donnée personnelle ?",[],[123,126],{"id":124,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":125},"09a32dd4-fafa-4e4a-9c42-356bb2add5ab",[],{"id":127,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":128},"5a17034e-59be-41a4-856b-6e1d6efbb767",[],{"id":130,"slug":131,"label":132,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":133,"displayConditions":9,"answers":134,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"003515ba-6b10-4dbc-bb14-6dcc2f5265bb","une-donnee-anonymisee-demeure-une-donnee-personnelle-","Une donnée pseudonymisée demeure une donnée personnelle ?",[],[135,137],{"id":124,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":136},[],{"id":127,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":138},[],{"id":140,"slug":141,"label":142,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":143,"displayConditions":9,"answers":144,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"dc9169e9-0373-48c9-aa9d-d97228cfa799","quest-ce-quun-traitement-de-donnees-personnelles-","Qu'est-ce qu'un traitement de données personnelles ? ",[],[145,149],{"id":146,"color":26,"rangeValue":9,"label":147,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":148},"f4a14ff9-695a-41be-9c1e-b34e48ddaad0","Toute opération ou tout ensemble d'opérations effectuées ou non à l'aide de procédés automatisés et appliquées à des données ou des ensembles de données ",[],{"id":150,"color":26,"rangeValue":9,"label":151,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":152},"b09839ff-7fff-47ef-a20e-fc492047590e","Toute opération ou tout ensemble d'opérations effectuées ou non à l'aide de procédés automatisés et appliquées à des données ou des ensembles de données à caractère personnel",[],{"id":154,"slug":155,"label":156,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":157,"displayConditions":9,"answers":158,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"8373af26-e0fe-4607-ae2d-1ba82611f185","les-donnees-personnelles-collectees-pour-un-traitement-de-donnees-sont-librement-conservees-","Les données personnelles collectées pour un traitement de données peuvent elles être conservées sans limite de durée ?",[],[159,163,167,171],{"id":160,"color":26,"rangeValue":9,"label":161,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":162},"5b02820e-0a67-455a-992a-73edd478ce77","Oui dans le secteur public",[],{"id":164,"color":26,"rangeValue":9,"label":165,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":166},"dd52f01f-559a-4bde-a0b2-e02f8cdabe03","Oui dans les secteur privé",[],{"id":168,"color":9,"rangeValue":9,"label":169,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":170},"5efefdf7-5e2e-4d4e-be13-bdc0ece7e365","Oui dans le secteur privé et public",[],{"id":172,"color":9,"rangeValue":9,"label":105,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":173},"52ebafa3-5ab9-4ca9-9322-7ca81c6d5572",[],[],{"id":176,"slug":177,"label":178,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":179,"sections":180},"b3be326a-d9f5-4211-bb25-77a4a413877c","les-differents-roles","Les différents rôles",[],[181,264,304,336],{"id":182,"slug":183,"label":184,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":185,"sections":263},"4dceb129-e472-4583-b4dc-56b0f97d7a5c","dpo-2-3-4","DPO",[186,207,221,233,245],{"id":187,"slug":188,"label":189,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":190,"typeIndex":191,"typeColor":9,"typeIcon":9,"typeText":192,"dynamicSelectType":9,"editableOptions":21,"complianceRules":193,"displayConditions":9,"answers":194,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"6887ae06-0c83-4f71-982f-8319d4e0e9c0","quest-ce-quun-dpo-","Qu'est-ce qu'un DPO ?","Checkbox",8,"Liste de cases à cocher (plusieurs réponses possibles)",[],[195,199,203],{"id":196,"color":9,"rangeValue":9,"label":197,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":198},"59e817fa-2ec7-43c5-a384-15a70b30553d","Un délégué à la protection des données",[],{"id":200,"color":9,"rangeValue":9,"label":201,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":202},"fcc9a273-8b41-42dc-a5ba-54252b0eef8e","Un data protection officer",[],{"id":204,"color":9,"rangeValue":9,"label":205,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":206},"c27a00b1-a4e0-4968-85ad-36a1fff81273","Il s'agit d'un responsable de traitement",[],{"id":208,"slug":209,"label":210,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":211,"displayConditions":9,"answers":212,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"30537f88-769e-466d-9c21-b5fd9333f3bd","quel-est-le-role-du-dpo-","Quel est le rôle du DPO ?",[],[213,217],{"id":214,"color":26,"rangeValue":9,"label":215,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":216},"bf21d479-deb0-42ce-b5ff-228a8953a855","Chargé de la gestion globale de l’application du RGPD",[],{"id":218,"color":26,"rangeValue":9,"label":219,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":220},"0e216b7c-8c25-40d2-ade3-0c281ae2565b","Conseiller et accompagner l'organisme dans la mise en conformité RGPD",[],{"id":222,"slug":223,"label":224,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":225,"displayConditions":9,"answers":226,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"8e0d69fc-baf9-4fe3-99b6-f34f50207dd8","le-dpo-est-necessairement-un-avocat-ou-juriste-","Le DPO est nécessairement un avocat ou juriste ?",[],[227,230],{"id":228,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":229},"2b3f2ed8-5ff8-4ffb-a7ff-0fb055ca11c4",[],{"id":231,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":232},"e54c7564-b29f-4440-a379-58ce61545468",[],{"id":234,"slug":235,"label":236,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":237,"displayConditions":9,"answers":238,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"c2ac38b0-0b0b-48df-84d7-1979482515f1","2cb7ad49-bb77-4e66-af01-c3545fdf20b5","La désignation d'un DPO est-elle toujours obligatoire ?",[],[239,242],{"id":240,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":241},"3c3a16be-8293-4aa1-b12e-1f87ed437c27",[],{"id":243,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":244},"527371aa-2483-4930-94ce-6245e1d4cef5",[],{"id":246,"slug":247,"label":248,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":190,"typeIndex":191,"typeColor":9,"typeIcon":9,"typeText":192,"dynamicSelectType":9,"editableOptions":21,"complianceRules":249,"displayConditions":9,"answers":250,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"71ff9b8c-a91e-4abf-879f-5ac7911c8885","dans-quels-cas-la-designation-dun-dpo-est-elle-obligatoire-","Dans quel(s) cas la désignation d'un DPO est-elle obligatoire ? ",[],[251,255,259],{"id":252,"color":9,"rangeValue":9,"label":253,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":254},"cc968612-3fad-4483-9330-b9479db4e8f5","Lorsque le traitement est effectué par une autorité publique ou un organisme public",[],{"id":256,"color":9,"rangeValue":9,"label":257,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":258},"5b1aef87-534b-4f34-a0df-9eab3a5010bf","Lorsque les activités de base du responsable du traitement ou du sous-traitant consistent en des opérations de traitement qui exigent un suivi régulier et systématique à grande échelle des personnes concernées",[],{"id":260,"color":9,"rangeValue":9,"label":261,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":262},"96978df9-0231-4e8e-8241-fa3ad7d5c6fe","Lorsque les activités de base du responsable du traitement ou du sous-traitant consistent en un traitement à grande échelle de catégories particulières de données ou de données à caractère personnel relatives à des condamnations pénales et à des infractions",[],[],{"id":265,"slug":266,"label":267,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":268,"sections":303},"57bbc06e-2ad4-424f-bad2-164eb93f4f93","responsable-de-traitement-1","Responsable de traitement",[269,291],{"id":270,"slug":271,"label":272,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":273,"displayConditions":9,"answers":274,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"ad40eac9-551c-418a-b041-a24cc9913e89","quest-ce-quun-responsable-de-traitement-_1","Qu'est-ce qu'un responsable de traitement ?",[],[275,279,283,287],{"id":276,"color":9,"rangeValue":9,"label":277,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":278},"5fa5d929-69fa-43a2-aaab-4abbc11fc00d","Une personne physique ou morale déterminant les finalités et les moyens du traitement",[],{"id":280,"color":9,"rangeValue":9,"label":281,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":282},"3b4389ad-e0a4-4a62-ac50-38b2cab76924","Une autorité publique déterminant les finalités et les moyens du traitement",[],{"id":284,"color":9,"rangeValue":9,"label":285,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":286},"f6affad0-b53a-49d6-a908-b77b881a02b0","Une personne physique ou morale, l’autorité publique, le service ou un autre organisme qui, seul ou conjointement avec d’autres, vérifie et conseille pour la bonne application du RGPD",[],{"id":288,"color":9,"rangeValue":9,"label":289,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":290},"21d90509-49bf-4aef-9284-c01a5e2cb1d4","Une personne physique ou morale, l’autorité publique, le service ou un autre organisme qui, seul ou conjointement avec d’autres, détermine les finalités et les moyens du traitement",[],{"id":292,"slug":293,"label":294,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":295,"displayConditions":9,"answers":296,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"5e900b44-3a98-47df-8032-8ca1f167d3ee","df15d32f-4995-4f1c-a31a-a08828a1ccf5","Peut-il y avoir plusieurs responsables de traitement pour un même traitement ?",[],[297,300],{"id":298,"color":26,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":299},"a18a3596-ca66-4162-9651-3903b07d851f",[],{"id":301,"color":26,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":302},"5d2e254d-a6b5-417c-ad93-68d43dd6f407",[],[],{"id":305,"slug":306,"label":307,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":308,"sections":335},"5579f47c-4848-4713-bdfb-cd4eef4d6d3e","sous-traitant-1","Sous traitant",[309,323],{"id":310,"slug":311,"label":312,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":313,"displayConditions":9,"answers":314,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"a5ec7b6e-730e-4911-b19c-c032f193ceb8","quest-ce-quun-responsable-de-traitement-","Qu'est-ce qu'un sous-traitant ?",[],[315,318,321],{"id":276,"color":9,"rangeValue":9,"label":316,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":317},"Une personne physique ou morale, l’autorité publique, le service ou un autre organisme qui traite des données à caractère personnel pour le compte de la personne concernée",[],{"id":288,"color":9,"rangeValue":9,"label":319,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":320},"Une personne physique ou morale, l’autorité publique, le service ou un autre organisme qui traite des données à caractère personnel pour le compte du responsable du traitement",[],{"id":284,"color":9,"rangeValue":9,"label":285,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":322},[],{"id":324,"slug":325,"label":326,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":327,"displayConditions":9,"answers":328,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"4bbe38b3-11f4-4b08-979e-4ab4b7559598","le-sous-traitant-doit-constituer-un-registre-de-ses-traitements-","Le sous traitant doit constituer un registre de ses traitements ? ",[],[329,332],{"id":330,"color":26,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":331},"b2a0a9b4-249d-4e6b-8e64-3c1e01c5ba91",[],{"id":333,"color":26,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":334},"04278460-525a-4fea-9a29-8deb91f391de",[],[],{"id":337,"slug":338,"label":339,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":340,"sections":367},"aede3aa5-62fb-4c16-8985-623b17efef5f","destinataires-1-2-3-4-5-6-7-8","Destinataires",[341,355],{"id":342,"slug":343,"label":344,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":345,"displayConditions":9,"answers":346,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"d8697470-144f-4601-9184-9ee8efb4b5fa","quest-ce-quun-destinataire-dans-un-traitement-de-donnees-personnelles-","Qu'est-ce qu'un destinataire dans un traitement de données personnelles ?",[],[347,351],{"id":348,"color":26,"rangeValue":9,"label":349,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":350},"0b6d9305-d8d4-430d-9069-d7a84d37e1bc","La personne physique ou morale, l'autorité publique, le service ou tout autre organisme qui reçoit communication de données à caractère personnel, qu'il s'agisse ou non d'un tiers",[],{"id":352,"color":26,"rangeValue":9,"label":353,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":354},"043f24dc-245b-4233-9b57-c49aee3a710b","Le responsable du traitement qui reçoit communication de données à caractère personnel",[],{"id":356,"slug":357,"label":358,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":359,"displayConditions":9,"answers":360,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"5fe1da96-c37d-4459-9b1a-f4958ee67525","un-sous-traitant-peut-il-etre-destinataire-de-donnees-personnelles-","Un sous-traitant peut-il être destinataire de données personnelles ?",[],[361,364],{"id":362,"color":26,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":363},"a10365f1-5bd3-419d-9b29-3a53ab120861",[],{"id":365,"color":26,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":366},"70e96b03-60c2-4360-894d-51cd01237a98",[],[],{"id":369,"slug":370,"label":371,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":372,"sections":414},"64ce11b4-0f73-48c9-8c65-9ec4ca16dc76","finalite","Les finalités et bases légales du traitement",[373,385,395],{"id":374,"slug":375,"label":376,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":377,"displayConditions":9,"answers":378,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"fd04a7ee-48b4-4b8f-a0d0-4482ce68cc50","un-traitement-de-donnees-personnelles-peut-il-avoir-plusieurs-finalites-_1","Un traitement de données personnelles peut-il avoir plusieurs finalités ?",[],[379,382],{"id":380,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":381},"8cbbb468-9732-49cd-b48c-3a98ba139b36",[],{"id":383,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":384},"76333584-3031-49be-b4c1-9ac2ecee36bd",[],{"id":386,"slug":387,"label":388,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":389,"displayConditions":9,"answers":390,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"25b24d0a-d2ed-4dd7-b771-cb147e8847c8","un-traitement-de-donnees-personnelles-peut-il-avoir-plusieurs-finalites-","Est-il possible d'indiquer plusieurs bases légales à la finalité du traitement de données ?",[],[391,393],{"id":380,"color":99,"rangeValue":9,"label":100,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":392},[],{"id":383,"color":104,"rangeValue":9,"label":105,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":394},[],{"id":396,"slug":397,"label":398,"tooltipHtml":9,"descriptionHtml":399,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":400,"displayConditions":9,"answers":401,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"5d4b15b0-8316-4595-bec5-4a58c81f5e6c","501a927a-26a6-4f23-9030-648c777ac51f","Est-il possible de traiter ultérieurement des données personnelles d'un premier traitement pour d'autres finalités ?","",[],[402,406,410],{"id":403,"color":26,"rangeValue":9,"label":404,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":405},"9b312b07-07e3-4671-b93d-8529f1675838","Oui dans tous les cas",[],{"id":407,"color":26,"rangeValue":9,"label":408,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":409},"20b66423-f3a6-4163-a02a-5fa0585106fa","Non jamais",[],{"id":411,"color":9,"rangeValue":9,"label":412,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":413},"79a0fa52-4e05-4dce-94f2-f0856aba9438","Oui lorsqu'il existe une compatibilité des finalités",[],[],{"id":416,"slug":417,"label":418,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":419,"sections":488},"7d9180fc-60e7-45f4-be4b-b254f2cecf14","transfert-hors-ue","Les transfert hors UE",[420,434,448,470],{"id":421,"slug":422,"label":423,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":424,"displayConditions":9,"answers":425,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"245452aa-0004-4f01-8ddb-2d994f890f50","828dde4c-6727-4986-886b-fe7b78cc2fa6","Le RGPD pose le principe fondamental selon lequel tout transfert de données personnelles en dehors de l'UE/EEE est interdit",[],[426,430],{"id":427,"color":26,"rangeValue":9,"label":428,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":429},"4e1a30d2-f401-405b-a575-e3181935561d","Vrai",[],{"id":431,"color":26,"rangeValue":9,"label":432,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":433},"739991bf-db48-4169-b38e-f14a278c139b","Faux",[],{"id":435,"slug":436,"label":437,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":438,"displayConditions":9,"answers":439,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"f47f46b6-5297-4a61-a508-dd19a172f840","un-transfert-hors-union-europeenne-est-il-encadre-","Existe t'il des justifications pour les responsables de traitement et les sous-traitants permettant de transférer des données hors de l’Union européenne (UE) et de l’Espace économique européen (EEE) ?",[],[440,444],{"id":441,"color":26,"rangeValue":9,"label":442,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":443},"c3f9e898-e138-4afe-b1d9-109b8c45220a","Oui il faut notamment assurer un niveau de protection des données suffisant et approprié",[],{"id":445,"color":26,"rangeValue":9,"label":446,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":447},"b2dbd70b-2a08-4651-97b2-072899f86310","Non la seule justification à un transfert de données hors UE ou EEE est le consentement de la personne concernée",[],{"id":449,"slug":450,"label":451,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":190,"typeIndex":191,"typeColor":9,"typeIcon":9,"typeText":192,"dynamicSelectType":9,"editableOptions":21,"complianceRules":452,"displayConditions":9,"answers":453,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"f36f85b6-00ec-4ec7-bc1a-0ca82414d4f5","6f16ed27-0220-4204-9014-c7061ae546a3","Quels outils juridiques permettent d’encadrer les transferts ?",[],[454,458,462,466],{"id":455,"color":9,"rangeValue":9,"label":456,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":457},"bbfe091c-29b2-483d-a487-dd8c0aa4d720","Décisions d'adéquation",[],{"id":459,"color":9,"rangeValue":9,"label":460,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":461},"2cffbbf5-fd81-4d1b-b1c2-8547d3cfec46","Garanties appropriées",[],{"id":463,"color":9,"rangeValue":9,"label":464,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":465},"7080bc44-6dc7-4e9c-99d6-c8a8631f2145","Dérogations",[],{"id":467,"color":9,"rangeValue":9,"label":468,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":469},"3196ee83-70c6-4b43-8b3a-ad92b8bacffd","Des exceptions ",[],{"id":471,"slug":472,"label":473,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":474,"displayConditions":9,"answers":475,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"6c7cf2fc-7c94-4ef5-99f8-1d417cc38ed0","97186cdf-bd73-4efe-abc3-b31d616ae2f5","Faut-il répertorier les transferts dans le registre des traitements ?",[],[476,480,484],{"id":477,"color":26,"rangeValue":9,"label":478,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":479},"1d47981e-ed92-4644-a052-ce51e3099fcf","Oui le responsable de traitement et sous traitant doivent répertorier les transferts",[],{"id":481,"color":26,"rangeValue":9,"label":482,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":483},"46cdff93-9292-437a-8994-b8603bef854b","Oui le responsable de traitement doit répertorier les transferts",[],{"id":485,"color":9,"rangeValue":9,"label":486,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":487},"09b303a7-91ec-42fd-b528-f610b64c3647","Non ",[],[],{"id":490,"slug":491,"label":492,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":493,"sections":568},"1cc3d6cd-3add-41d0-884a-3ed85fd5306a","exercice-des-droits","Les exercices des droits",[494,512,524,554],{"id":495,"slug":496,"label":497,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":498,"displayConditions":9,"answers":499,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"06294c78-1240-4767-a4e5-4603ce1d2837","qui-est-concerne-par-lexercice-des-droits-","Qui est concerné par l'exercice des droits ? ",[],[500,504,508],{"id":501,"color":26,"rangeValue":9,"label":502,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":503},"e189282c-0a96-451a-9caf-5e09899acb4c","Uniquement organismes privés établis en Europe",[],{"id":505,"color":26,"rangeValue":9,"label":506,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":507},"fadd1c7c-ee00-4995-b668-6959e91856c5","Les organismes privés établis hors Union européenne ",[],{"id":509,"color":9,"rangeValue":9,"label":510,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":511},"792561ae-ae13-4f78-97e1-29e4932d25ac","Les organismes publiques ou privés établis en Europe ou établies hors de l’Union Européenne mais traitant des données  personnelles d'européens",[],{"id":513,"slug":514,"label":515,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":516,"displayConditions":9,"answers":517,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"f8004983-fe0c-42e4-afc6-07c51aecadc0","bdf2027f-07a5-4cf0-a064-d80b2c28a65f"," Les entreprises ou organisations traitant des données personnelles ont l'obligation de faciliter l'exercice des droits ? ",[],[518,521],{"id":519,"color":26,"rangeValue":9,"label":100,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":520},"4a889e4e-1fb4-41ed-a43a-07c737c94b31",[],{"id":522,"color":26,"rangeValue":9,"label":105,"slug":9,"description":9,"score":9,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":523},"9af700cf-9072-4e03-9629-73000ec97129",[],{"id":525,"slug":526,"label":527,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":190,"typeIndex":191,"typeColor":9,"typeIcon":9,"typeText":192,"dynamicSelectType":9,"editableOptions":21,"complianceRules":528,"displayConditions":9,"answers":529,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"3845a310-c039-4bc9-a957-dac71c2c0a1c","quel-est-le-delai-pour-apporter-une-reponse-a-une-demande-dexercice-de-droit-","Quel est le délai pour apporter une réponse à une demande d'exercice de droit ?",[],[530,534,538,542,546,550],{"id":531,"color":9,"rangeValue":9,"label":532,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":533},"7b253897-3156-41c4-9285-c0e5cddb6663","1 semaine",[],{"id":535,"color":9,"rangeValue":9,"label":536,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":537},"58e61045-3862-493a-807b-e0a967ac3048","2 semaines",[],{"id":539,"color":9,"rangeValue":9,"label":540,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":541},"2e615164-d6bb-483f-8c8c-39bd9794f694","1 mois ",[],{"id":543,"color":9,"rangeValue":9,"label":544,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":545},"7393253e-5641-48b0-bb88-acc01c8e6cb9","2 mois ",[],{"id":547,"color":9,"rangeValue":9,"label":548,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":549},"5e928966-15f8-4d69-a140-71ae7e621f4a","4 mois",[],{"id":551,"color":9,"rangeValue":9,"label":552,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":553},"9b5536c7-7a04-4b1a-8ccd-8c9db614e9d7","6 mois",[],{"id":555,"slug":556,"label":557,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":558,"displayConditions":9,"answers":559,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"79e8e01f-d234-4546-b4cb-4acd9ce00505","le-delai-peut-il-etre-augmente-","Le délai pour apporter une réponse à une demande d'exercice de droit peut-il être augmenté ? ",[],[560,564],{"id":561,"color":26,"rangeValue":9,"label":562,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":563},"cd4ce219-5e45-4e05-8385-b6b9cbdb11f4","Oui en cas de demande complexe",[],{"id":565,"color":26,"rangeValue":9,"label":566,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":567},"9ff9e6f0-933e-4b74-89d6-cc1765a545b2","Non le délai est jugé suffisant pour apporter une réponse à toute demande",[],[],{"id":570,"slug":571,"label":572,"emoji":9,"type":10,"typeIndex":11,"typeColor":9,"typeIcon":9,"typeText":12,"descriptionHtml":9,"questions":573,"sections":671},"ef66a4bd-32fa-4ab8-8291-ab4b0b06528b","violations-de-donnees","Les violations de données",[574,592,610,632,649],{"id":575,"slug":576,"label":577,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":190,"typeIndex":191,"typeColor":9,"typeIcon":9,"typeText":192,"dynamicSelectType":9,"editableOptions":21,"complianceRules":578,"displayConditions":9,"answers":579,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"562e704a-fa56-4c18-a85d-15764d2b9397","quest-ce-quune-violation-de-donnees-","Qu'est-ce qu'une violation de données ? ",[],[580,584,588],{"id":581,"color":9,"rangeValue":9,"label":582,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":583},"46479f77-b438-4d9f-883e-ae439d97f1fd","Tout incident de sécurité, d’origine malveillante ou non et se produisant de manière intentionnelle ou non, ayant comme conséquence de compromettre l’intégrité, la confidentialité ou la disponibilité de données personnelles.",[],{"id":585,"color":9,"rangeValue":9,"label":586,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":587},"1a1383bb-c0f1-45f4-a19c-dfa35cdf4ad7","Tout incident de sécurité, d’origine malveillante et se produisant de manière intentionnelle ayant comme conséquence de compromettre l’intégrité, la confidentialité ou la disponibilité de données personnelles.",[],{"id":589,"color":9,"rangeValue":9,"label":590,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":591},"5ef7b118-16ec-4053-b5df-b1e929d375b5","La destruction, la perte, l'altération, la divulgation non autorisée de données à caractère personnel transmises, conservées ou traitées d'une autre manière, ou l'accès non autorisé à de telles données, de manière accidentelle ou illicite",[],{"id":593,"slug":594,"label":595,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":190,"typeIndex":191,"typeColor":9,"typeIcon":9,"typeText":192,"dynamicSelectType":9,"editableOptions":21,"complianceRules":596,"displayConditions":9,"answers":597,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"c6843bd1-cf21-4a86-b5ce-6b7ab4e5af0d","0adb79fe-cf54-4af7-8366-71de1dcce4e3","Qui est concerné par les violations de données ? ",[],[598,602,606],{"id":599,"color":9,"rangeValue":9,"label":600,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":601},"863e3104-7bc6-4dd9-bf7c-b463dd1e2b64","Tous les organismes, publics comme privés et quelle que soit leur taille, sont soumis à ces obligations dès lors qu’ils traitent des données personnelles et qu’ils ont connaissance d’une violation de données personnelles.",[],{"id":603,"color":9,"rangeValue":9,"label":604,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":605},"7a16474a-0190-40c9-a611-97a005321801","Seulement les fournisseurs de services de communication électronique",[],{"id":607,"color":9,"rangeValue":9,"label":608,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":609},"c5c2b007-538b-4255-9f2f-2a8e2a37cf4a","Les sous-traitants, qui traitent des données personnelles pour le compte d’un organisme responsable du traitement, ont également des obligations en matière de violation",[],{"id":611,"slug":612,"label":613,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":614,"displayConditions":9,"answers":615,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"07b8a1c9-d22a-487b-83ac-8be9cf1f2eb9","1eef0320-90f8-4f53-b549-79a0d575ff46","Quel est le délai maximal de notification à la CNIL pour le responsable de traitement en cas de violation de données ? ",[],[616,620,624,628],{"id":617,"color":26,"rangeValue":9,"label":618,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":619},"f556a3c0-d7fd-441c-af59-a70a1889c38f","48 heures",[],{"id":621,"color":26,"rangeValue":9,"label":622,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":623},"6c194922-1124-48d4-9470-b03157ae6491","96 heures",[],{"id":625,"color":9,"rangeValue":9,"label":626,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":627},"98d9adb4-e7da-4a26-aa41-5322b2c1992f","72 heures",[],{"id":629,"color":9,"rangeValue":9,"label":630,"slug":9,"description":9,"score":9,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":631},"32bdd529-e573-438e-9235-106293c7e016","36 heures",[],{"id":633,"slug":634,"label":635,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":636,"displayConditions":9,"answers":637,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"1a67409b-5d6e-4818-a2ec-4b29a8654f1f","c33ba174-1824-4a0c-86d9-f68797cb8e73","Les personnes concernées par la violation de données doivent elles être informées de la violation de données ?",[],[638,641,645],{"id":639,"color":26,"rangeValue":9,"label":408,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":640},"1b817f7a-e169-4b22-87cc-c45bf4d95df4",[],{"id":642,"color":26,"rangeValue":9,"label":643,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":644},"abbbeb81-cfcf-47f6-9e98-4654f094ed52","Oui les personnes concernées sont toujours informées de la violation de données",[],{"id":646,"color":9,"rangeValue":9,"label":647,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":648},"c740604b-9971-4508-93bb-e1aeef40913b","Oui les personnes concernées sont informées de la violation de données présentant un risque élevé pour leurs droits et libertés",[],{"id":650,"slug":651,"label":652,"tooltipHtml":9,"descriptionHtml":9,"badResponseCommentHtml":9,"goodResponseCommentHtml":9,"placeholder":9,"min":9,"max":9,"regex":9,"unit":9,"type":18,"typeIndex":19,"typeColor":9,"typeIcon":9,"typeText":20,"dynamicSelectType":9,"editableOptions":21,"complianceRules":653,"displayConditions":654,"answers":662,"listQuestions":9,"required":21,"requiredJustification":21,"suggestTask":21,"riskEnabled":34,"native":21},"4fa6c8ac-3ff9-436e-aef7-caebd6e720e6","c6b1e945-fb71-4e90-bb9e-0fbe40f217a3","En cas de risque élevé, est-il possible déroger à l'obligation d'information des personnes concernées ? ",[],{"id":655,"separator":656,"field":9,"operator":657,"value":9,"rules":658},"bf0f4bc0-7730-4fee-bbcb-5071e5163288","And","equal",[659],{"id":660,"separator":9,"field":633,"operator":657,"value":646,"rules":661},"99135652-4ac8-4178-aa00-b3e3dd216bda",[],[663,667],{"id":664,"color":26,"rangeValue":9,"label":665,"slug":9,"description":9,"score":28,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":666},"175ffcd5-78cf-44e3-8266-97d09619591b","Oui lorsque les données sont protégées par des mesures de protection techniques et organisationnelles appropriées et sont ainsi incompréhensibles pour toute personne qui n'est pas autorisée à y avoir accès",[],{"id":668,"color":26,"rangeValue":9,"label":669,"slug":9,"description":9,"score":11,"nonApplicable":21,"tooltip":9,"goodAnswer":21,"redFlag":21,"impact":9,"probability":9,"taskSuggestions":670},"622aace0-13be-4c09-b4ca-b3d165cefa6f","Non, en cas de risque élevé pour les droits et libertés, les personnes concernées doivent systématiquement être informées",[],[],[673,690,704,713,723,733,758,768,776,795,814,830,843,858,874,889,904],{"id":674,"label":675,"variant":676,"variantIndex":11,"variantColor":677,"variantIcon":678,"variantText":679,"contentHtml":680,"displayConditions":681},"ec7b6891-3b77-4a47-ba06-b59095ac3d21","Le RGPD, ça sert à quoi ?","Info","#1E8EE1","icon-alert-circle","Information","\u003Cp>Le RGPD définit un contexte juridique permettant d'encadrer le traitement des données personnelles sur tout le territoire de l'Union européenne.\u003C/p>\u003Cp>Il harmonise les règles en Europe en offrant un cadre juridique unique aux professionnels. Il permet de développer leurs activités numériques au sein de l’UE en se fondant sur la confiance des utilisateurs.\u003C/p>\u003Cp>C'est la proposition de «&nbsp;Règlement ePrivacy&nbsp;» qui vise à renforcer la confiance des consommateurs dans l'offre de services numériques (en ligne), à simplifier les règles relatives aux cookies et à rendre le marketing des entreprises plus transparent.\u003Cbr>Ce règlement aurait vocation à être complémentaire au RGPD.\u003C/p>",{"id":682,"separator":656,"field":9,"operator":657,"value":9,"rules":683},"715856a3-8fa0-44ae-9c34-80f4d1062518",[684,687],{"id":685,"separator":9,"field":36,"operator":657,"value":42,"rules":686},"4c5b3a0c-cd3d-4122-ba30-9e9da59480ea",[],{"id":688,"separator":9,"field":36,"operator":657,"value":46,"rules":689},"251c467f-8e84-4738-8dcb-78f5699bb502",[],{"id":691,"label":692,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":697,"displayConditions":698},"9562432a-252d-42d9-9b85-f460e5581688","Les données anonymisées","Warning",2,"#ffc107","Point d'attention","\u003Cp>Une donnée anonymisée rend impossible, en pratique, toute identification de la personne et ce, de manière irréversible.\u003Cbr>Une donnée anonymisée ne répond donc plus à la définition d'une donnée personnelle.\u003C/p>",{"id":699,"separator":656,"field":9,"operator":657,"value":9,"rules":700},"f902a1ff-f34d-4254-8958-677dd3d993bb",[701],{"id":702,"separator":9,"field":118,"operator":657,"value":9,"rules":703},"b3675c79-d3fb-41bb-82a2-75fc654cb48d",[],{"id":705,"label":692,"variant":676,"variantIndex":11,"variantColor":677,"variantIcon":678,"variantText":679,"contentHtml":697,"displayConditions":706},"150fbb62-3833-4a93-af9a-a3e5050bce55",{"id":707,"separator":708,"field":9,"operator":657,"value":9,"rules":709},"a50da43c-e63c-4e62-8768-a86993fc77c9","Or",[710],{"id":711,"separator":9,"field":130,"operator":657,"value":127,"rules":712},"63c54272-e5c5-49d7-ad5f-e8efea624370",[],{"id":714,"label":715,"variant":676,"variantIndex":11,"variantColor":677,"variantIcon":678,"variantText":679,"contentHtml":716,"displayConditions":717},"4c52c403-517c-446a-9ff9-6d14e27c6bd2","Donnée personnelle et personne physique identifiée ou identifiable","\u003Cp>Les données à caractère personnel sont : toute information se rapportant à une personne physique identifiée ou identifiable (art 4.1 RGPD)\u003C/p>\u003Cp>Est réputée être une «personne physique identifiable» une personne physique qui peut être identifiée, directement ou indirectement, notamment par référence à un identifiant, tel qu'un nom, un numéro d'identification, des données de localisation, un identifiant en ligne, ou à un ou plusieurs éléments spécifiques propres à son identité physique, physiologique, génétique, psychique, économique, culturelle ou sociale;\u003C/p>",{"id":718,"separator":708,"field":9,"operator":657,"value":9,"rules":719},"788f5157-1536-4297-99ac-a32d1c2f5cdb",[720],{"id":721,"separator":9,"field":78,"operator":657,"value":84,"rules":722},"b42f6d50-0a8b-4dfa-9828-6b5c69b1cbb8",[],{"id":724,"label":725,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":726,"displayConditions":727},"a8a53c71-06c1-4152-a75d-465e7025abb3","Données personnelles et personne physique identifiée ou identifiable ","\u003Cp>Les données à caractère personnel sont : toute information se rapportant à une personne physique identifiée ou identifiable (art 4.1 RGPD)\u003C/p>\u003Cp>Est réputée être une «personne physique identifiable» une personne physique qui peut être identifiée, directement ou indirectement, notamment par référence à un identifiant, tel qu'un nom, un numéro d'identification, des données de localisation, un identifiant en ligne, ou à un ou plusieurs éléments spécifiques propres à son identité physique, physiologique, génétique, psychique, économique, culturelle ou sociale.\u003C/p>",{"id":728,"separator":708,"field":9,"operator":657,"value":9,"rules":729},"420e403c-a1fa-479b-8f53-cc162f03174a",[730],{"id":731,"separator":9,"field":78,"operator":657,"value":84,"rules":732},"ee2bb452-9bce-4408-8442-8fe4e27fb2aa",[],{"id":734,"label":735,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":736,"displayConditions":737},"ec6edbef-5b4b-4ccb-8ba1-a4eac324eb9f","Les données personnelles chiffrées, codées, ou pseudonymisées","\u003Cp>Les données personnelles chiffrées, codées, ou pseudonymisées ne rendent pas impossible et de manière irréversible l'identification de la personne concernée.\u003C/p>\u003Cp>Par exemple, la pseudonymisation est un traitement de données personnelles réalisé de manière à ce qu'on ne puisse plus attribuer les données relatives à une personne physique sans information supplémentaire.\u003C/p>\u003Cp>En pratique, la pseudonymisation consiste à remplacer les données directement identifiantes (nom, prénom, etc.) d’un jeu de données par des données indirectement identifiantes (alias, numéro séquentiel, etc.).\u003C/p>\u003Cp>La pseudonymisation permet ainsi de traiter les données d’individus sans pouvoir identifier ceux-ci de façon directe. \u003C/p>\u003Cp>Néanmoins, en pratique, il demeure possible de retrouver l’identité des personnes concernées grâce à des données tierces&nbsp;: les données concernées conservent donc un caractère personnel.\u003C/p>",{"id":738,"separator":656,"field":9,"operator":657,"value":9,"rules":739},"6fcbe36f-0173-49ae-9332-b931da538683",[740,743,746,749,752,755],{"id":741,"separator":9,"field":92,"operator":657,"value":98,"rules":742},"0c5e0579-eeed-4c40-916b-a0669349f3c6",[],{"id":744,"separator":9,"field":92,"operator":657,"value":103,"rules":745},"f2092973-04a2-4fd1-bb1b-04793160ef15",[],{"id":747,"separator":9,"field":108,"operator":657,"value":98,"rules":748},"43a1d79e-ca8b-422d-8b71-76c709470d5a",[],{"id":750,"separator":9,"field":108,"operator":657,"value":103,"rules":751},"53675aa9-a042-4e54-bfd4-3526174cc72f",[],{"id":753,"separator":9,"field":130,"operator":657,"value":124,"rules":754},"f17e0b44-fcf1-4edc-8fd6-2b4130e2c6d8",[],{"id":756,"separator":9,"field":130,"operator":657,"value":127,"rules":757},"1dd80f18-2788-47ca-bd40-ce65f07c926e",[],{"id":759,"label":760,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":761,"displayConditions":762},"6c521df5-95b1-4eb0-9189-ed884ef73e09","La coresponsabilité ou responsabilité conjointe","\u003Cp>Il est possible que deux responsables du traitement ou plus déterminent ensemble les finalités et les moyens du traitement, ils sont ainsi responsables conjoints du traitement. \u003C/p>\u003Cp>Cette possibilité de coresponsabilité implique une prise de décision en accord avec toutes les personnes responsables. \u003C/p>\u003Cp>Pour éviter toute confusion, il est essentiel d’identifier clairement les rôles et les obligations de chacun.\u003C/p>",{"id":763,"separator":708,"field":9,"operator":657,"value":9,"rules":764},"3d2da16e-ce55-46da-ac30-f43b72b44c7d",[765],{"id":766,"separator":9,"field":292,"operator":657,"value":301,"rules":767},"6783f11d-28a1-45a3-a14d-e1558eac48cb",[],{"id":769,"label":760,"variant":676,"variantIndex":11,"variantColor":677,"variantIcon":678,"variantText":679,"contentHtml":761,"displayConditions":770},"1c095f78-19a8-4fe6-ab8b-eb729f34aa7e",{"id":771,"separator":708,"field":9,"operator":657,"value":9,"rules":772},"06ebc210-ca6e-4195-8452-cab356a746fd",[773],{"id":774,"separator":9,"field":292,"operator":657,"value":301,"rules":775},"15708123-5fb8-4c4a-b762-2d9b320bd54c",[],{"id":777,"label":778,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":779,"displayConditions":780},"818b9e0f-1e64-4f75-a4a0-6c5e644d6a64","Durées de conservation ","\u003Cp>Les données personnelles ne peuvent être conservées indéfiniment.\u003C/p>\u003Cp>Le responsable de traitement doit définir une durée de conservation fonction de l’objectif ayant conduit à la collecte de ces données.\u003C/p>\u003Cp>Ce principe de conservation limitée des données personnelles est prévu par le RGPD et la loi Informatique et Libertés.\u003C/p>\u003Cp>Dans certains cas, la durée &nbsp;de conservation est fixée par la règlementation (par exemple, l’article L3243-4 du Code du travail impose à l’employeur de conserver un double du bulletin de paie du salarié pendant 5 ans).\u003C/p>\u003Cp>Toutefois, pour de nombreux traitements de données, la durée de conservation n’est pas fixée par un texte. Il appartient alors au responsable du fichier de la déterminer en fonction de la finalité du traitement.\u003C/p>",{"id":781,"separator":656,"field":9,"operator":657,"value":9,"rules":782},"04bd5605-723a-4343-bf31-7f8064338331",[783,786,789,792],{"id":784,"separator":9,"field":154,"operator":657,"value":160,"rules":785},"832656bc-ccc7-4ed4-949e-d8ac3befb577",[],{"id":787,"separator":9,"field":154,"operator":657,"value":164,"rules":788},"50c78aa3-20e0-487c-ad5f-49b960f88afc",[],{"id":790,"separator":9,"field":154,"operator":657,"value":168,"rules":791},"8075e5c5-4168-4330-a26e-e32e7d74a2b7",[],{"id":793,"separator":9,"field":154,"operator":657,"value":172,"rules":794},"33b1908a-c5bb-4e3f-9e97-c64c4c4a0e95",[],{"id":796,"label":797,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":798,"displayConditions":799},"6c630eb1-6f34-4c42-b2cb-12079f43b4c2","Les outils juridiques permettant d'encadrer les transferts hors UE ou EEE","\u003Cp>Lorsqu’un État ne présente \u003Cu>ni décision d’adéquation et garanties appropriées\u003C/u>, il est possible de mettre en oeuvre un transfert sur le fondement de \u003Cstrong>l’article 49 du RGPD.\u003C/strong>\u003C/p>\u003Cp>L'article 49 du RGPD pose des conditions à l'utilisation de ce mécanisme : consentement ; transfert nécessaire à l'exécution du contrat ou \u003Cstrong>à la conclusion ou à l'exécution d'un contrat\u003C/strong> \u003Cstrong>conclu dans l'intérêt de la personne concernée ou pour des motifs importants d'intérêt public \u003C/strong>ou à \u003Cstrong>la constatation, à l'exercice ou à la défense de droits en justice ou à la sauvegarde des intérêts vitaux de la personne concernée ou d'autres personnes ou encore le transfert a lieu au départ d'un registre\u003C/strong> qui est légalement destiné à fournir des informations au public et est ouvert à la consultation du public ou de toute personne justifiant d'un intérêt légitime. \u003Cbr>\u003Cbr>Toutefois, l'article 49-1 du RGPD est applicable seulement dans les cas où le transfert :\u003C/p>\u003Cul>\u003Cli>\u003Cp>ne revêt pas de caractère \u003Cstrong>répétitif\u003C/strong>,\u003C/p>\u003C/li>\u003Cli>\u003Cp>ne touche qu'un \u003Cstrong>nombre limité de personnes concernées\u003C/strong>,\u003C/p>\u003C/li>\u003Cli>\u003Cp>est \u003Cstrong>nécessaire aux fins des intérêts légitimes impérieux\u003C/strong> poursuivis par le responsable du traitement sur lesquels ne prévalent pas les intérêts ou les droits et libertés de la personne concernée,\u003C/p>\u003C/li>\u003Cli>\u003Cp>et si le responsable du traitement a évalué toutes les circonstances entourant le transfert de données et a offert, sur la base de cette évaluation, des \u003Cstrong>garanties appropriées en ce qui concerne la protection des données à caractère personnel.\u003C/strong>\u003C/p>\u003C/li>\u003C/ul>\u003Cp>L’évaluation faite par l’organisme et les garanties mises en place pour encadrer le transfert, doivent être inscrites dans\u003Ca href=\"https://www.cnil.fr/fr/RGDP-le-registre-des-activites-de-traitement\"> le registre du responsable de traitement ou du sous-traitant.\u003C/a>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",{"id":800,"separator":656,"field":9,"operator":657,"value":9,"rules":801},"4e073fb8-ea37-4b1c-9303-63a474273c12",[802,805,808,811],{"id":803,"separator":9,"field":449,"operator":657,"value":455,"rules":804},"4a987c7b-4844-4123-8797-dfa187cc1b13",[],{"id":806,"separator":9,"field":449,"operator":657,"value":459,"rules":807},"00d21259-968c-4040-a852-4f0805327c72",[],{"id":809,"separator":9,"field":449,"operator":657,"value":463,"rules":810},"dccc3b6e-af68-49ad-87da-7397c7c50854",[],{"id":812,"separator":9,"field":449,"operator":657,"value":467,"rules":813},"6c39925d-9305-403b-bc97-4d55e8475567",[],{"id":815,"label":816,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":817,"displayConditions":818},"9328517c-dbb8-4804-bce5-92639a6a7ce9","Répertorier les transferts dans le registre des traitements","\u003Cp>Le registre du responsable de traitement doit recenser l’ensemble des traitements mis en œuvre par votre organisme.\u003C/p>\u003Cp>En pratique, une fiche de registre doit donc être établie pour chacune de ces activités.\u003C/p>\u003Cp>Ce registre doit comporter le nom et les coordonnées de votre organisme ainsi que, &nbsp;le cas échéant, de votre représentant, si votre organisme n’est pas établi dans l’Union européenne, et de votre délégué à la protection des données si vous en disposez.\u003C/p>\u003Cp>En outre, pour chaque activité de traitement, la fiche de registre doit comporter au moins les éléments suivants :\u003C/p>\u003Col>\u003Cli>\u003Cp>le cas échéant, le nom et les coordonnées du responsable conjoint du traitement mis en œuvre\u003C/p>\u003C/li>\u003Cli>\u003Cp>les finalités du traitement, l’objectif en vue duquel vous avez collecté ces données\u003C/p>\u003C/li>\u003Cli>\u003Cp>les catégories de personnes concernées (client, prospect, employé, etc.)\u003C/p>\u003C/li>\u003Cli>\u003Cp>les catégories de données personnelles (exemples&nbsp;: identité, situation familiale, économique ou financière, données bancaires, données de connexion, donnés de localisation, etc.)\u003C/p>\u003C/li>\u003Cli>\u003Cp>les catégories de destinataires auxquels les données à caractère personnel ont été ou seront communiquées, y compris les sous-traitants auxquels vous recourez\u003C/p>\u003C/li>\u003Cli>\u003Cp>les transferts de données à caractère personnel vers un pays tiers ou à une organisation internationale et, dans certains cas très particuliers, les garanties prévues pour ces transferts&nbsp;;\u003C/p>\u003C/li>\u003Cli>\u003Cp>les délais prévus pour l'effacement des différentes catégories de données, c’est-à-dire la durée de conservation, ou à défaut les critères permettant de la déterminer\u003C/p>\u003C/li>\u003Cli>\u003Cp>dans la mesure du possible, une description générale des mesures de sécurité techniques et organisationnelles que vous mettez en œuvre\u003C/p>\u003C/li>\u003C/ol>\u003Cp>\u003Cbr>Le registre du sous-traitant doit recenser toutes les catégories d'activités de traitement effectuées pour le compte de vos clients.\u003C/p>\u003Cp>En pratique, une fiche de registre doit donc être établie pour chacune de ces catégories d’activités (hébergement de données, maintenance informatique, service d’envoi de messages de prospection commerciale, etc.).\u003C/p>\u003Cp>Ce registre doit comporter le nom et les coordonnées de votre organisme ainsi que, &nbsp;le cas échéant, de votre représentant, si votre organisme n’est pas établi dans l’Union européenne, et de votre délégué à la protection des données si vous en disposez.\u003C/p>\u003Cp>Pour chaque catégorie d’activité effectuée pour le compte de clients, il doit contenir&nbsp;les éléments minimaux suivants :\u003C/p>\u003Col>\u003Cli>\u003Cp>le nom et les coordonnées de chaque client, responsable de traitement, pour le compte duquel vous traitez les données et, le cas échéant, le nom et les coordonnées de leur représentant\u003C/p>\u003C/li>\u003Cli>\u003Cp>le nom et les coordonnées des sous-traitants auxquels vous-même faites appel dans le cadre de cette activité\u003C/p>\u003C/li>\u003Cli>\u003Cp>les catégories de traitements effectués pour le compte de chacun de vos clients, c’est-à-dire les opérations effectivement réalisées pour leur compte (par exemple&nbsp;: pour la catégorie «&nbsp;service d’envoi de messages de prospection&nbsp;», il peut s’agir de la collecte des adresses mails, de l’envoi sécurisé des messages, de la gestion des désabonnements, etc.)&nbsp;\u003C/p>\u003C/li>\u003Cli>\u003Cp>les transferts de données à caractère personnel vers un pays tiers ou à une organisation internationale. Dans les cas très particuliers mentionnés au 2ème alinéa de l’article 49.1 (absence de décision d’adéquation en vertu de l’article 45 du RGPD, absence des garanties appropriées prévues à l’article 46 du RGPD et inapplicabilité des exceptions prévues au 1er alinéa de l’article 49.1), les garanties prévues pour encadrer les transferts doivent être mentionnées.\u003C/p>\u003C/li>\u003Cli>\u003Cp>dans la mesure du possible, une description générale des mesures de sécurité techniques et organisationnelles que vous mettez en œuvre.\u003C/p>\u003C/li>\u003C/ol>\u003Cp>Source : \u003Ca href=\"https://www.cnil.fr/fr/RGDP-le-registre-des-activites-de-traitement\">CNIL\u003C/a>\u003C/p>",{"id":819,"separator":656,"field":9,"operator":657,"value":9,"rules":820},"a0413f05-ae2e-4c2a-8a36-b98c10e504b7",[821,824,827],{"id":822,"separator":9,"field":471,"operator":657,"value":477,"rules":823},"73c5d5c0-2037-4c63-b89a-33701f752abc",[],{"id":825,"separator":9,"field":471,"operator":657,"value":481,"rules":826},"af504d9d-4f9b-410a-806c-9fe718f398a1",[],{"id":828,"separator":9,"field":471,"operator":657,"value":485,"rules":829},"82a0b00c-9a78-402e-a0d1-5f5be1fbf96a",[],{"id":831,"label":832,"variant":676,"variantIndex":11,"variantColor":677,"variantIcon":678,"variantText":679,"contentHtml":833,"displayConditions":834},"bba5fdad-25d8-4783-920b-76d08777c89e","Demandes complexes","\u003Cp>\u003Cstrong>Le responsable du fichier peut prolonger de deux mois le délai initial (trois mois au total)&nbsp;:\u003C/strong>\u003C/p>\u003Cul>\u003Cli>\u003Cp>Si votre demande est \"complexe\". Par exemple, dans le cadre d'une demande de droit d'accès, il doit vous communiquer de très nombreux documents qui nécessitent leur sortie des archives.\u003C/p>\u003C/li>\u003Cli>\u003Cp>A condition de vous en informer dans le délai d'un mois.&nbsp;\u003C/p>\u003C/li>\u003C/ul>\u003Cp>\u003Cstrong>A noter :\u003C/strong> dans tous les cas, vous devez avoir une réponse dans le délai d'un mois.\u003C/p>\u003Cp>\u003Cem>Source : \u003Ca href=\"https://www.cnil.fr/fr/cnil-direct/question/exercice-des-droits-informatique-et-libertes-dans-quel-delai-doit-me-repondre\">CNIL\u003C/a>\u003C/em>\u003C/p>",{"id":835,"separator":656,"field":9,"operator":657,"value":9,"rules":836},"78e00e59-653b-4bcc-b122-62f4f32c99fb",[837,840],{"id":838,"separator":9,"field":555,"operator":657,"value":561,"rules":839},"d4dc2074-d6c7-4471-8cef-4650b762f877",[],{"id":841,"separator":9,"field":555,"operator":657,"value":565,"rules":842},"e3aed2ce-e951-48d7-a7a3-8433036a547e",[],{"id":844,"label":845,"variant":846,"variantIndex":28,"variantColor":99,"variantIcon":847,"variantText":848,"contentHtml":849,"displayConditions":850},"f476a861-e403-45d9-bb69-831ba12431a4","Bravo !","Success","icon-checkmark","Succès","\u003Cp>Vous avez les bonnes réponses à toutes les questions ! \u003C/p>\u003Cp>Vous avez une très bonne connaissance des fondamentaux du RGPD. \u003C/p>",{"id":851,"separator":656,"field":9,"operator":657,"value":9,"rules":852},"2fe0fa3e-633f-45ba-98e0-567c2d073a47",[853],{"id":854,"separator":9,"field":855,"operator":657,"value":856,"rules":857},"31f9ccbb-00ba-42a4-ac8b-e5a0e9d2df1d","readiness","100",[],{"id":859,"label":860,"variant":846,"variantIndex":28,"variantColor":99,"variantIcon":847,"variantText":848,"contentHtml":861,"displayConditions":862},"d5c15f16-3fef-4ccf-b4ae-0737417cbd8b","Bien joué !","\u003Cp>Vous avez une bonne connaissance du RGPD mais vous pouvez encore atteindre la perfection !\u003C/p>\u003Cp>Encore un effort, on y est presque ! \u003C/p>",{"id":863,"separator":656,"field":9,"operator":657,"value":9,"rules":864},"47a9e8da-b383-4188-924c-fde244f66931",[865,870],{"id":866,"separator":9,"field":855,"operator":867,"value":868,"rules":869},"1475178d-ca27-405c-9092-32823df78e1d","greaterThan","74",[],{"id":871,"separator":9,"field":855,"operator":872,"value":856,"rules":873},"d29427ea-94fa-4a66-9e27-1b4d6c239fba","lessThan",[],{"id":875,"label":876,"variant":846,"variantIndex":28,"variantColor":99,"variantIcon":847,"variantText":848,"contentHtml":877,"displayConditions":878},"ec315d35-3682-4716-8510-78212066e4c2","Vous n'êtes pas loin !","\u003Cp>Vous avez une connaissance acceptable des notions du RGPD.\u003C/p>\u003Cp>Encore un effort ! On est pas loin.\u003C/p>",{"id":879,"separator":656,"field":9,"operator":657,"value":9,"rules":880},"8cbd9086-e0c5-48ee-a9e3-37fd7805547f",[881,885],{"id":882,"separator":9,"field":855,"operator":867,"value":883,"rules":884},"d42b21bd-c564-41c0-aa36-ab19dd3fc200","49",[],{"id":886,"separator":9,"field":855,"operator":872,"value":887,"rules":888},"b2cd08d5-32fd-4a0e-9615-eff46e457eee","75",[],{"id":890,"label":891,"variant":693,"variantIndex":694,"variantColor":695,"variantIcon":678,"variantText":696,"contentHtml":892,"displayConditions":893},"934b10ae-f889-4a2e-8a6d-19d3ea51e74a","A améliorer","\u003Cp>Ce n'était pas facile non plus. Mais vous pouvez passer la barre des 50 % en vous ressaisissant !\u003C/p>",{"id":894,"separator":656,"field":9,"operator":657,"value":9,"rules":895},"b02447b2-3a1c-4c05-b414-cb2bee254d4b",[896,900],{"id":897,"separator":9,"field":855,"operator":872,"value":898,"rules":899},"79233bb8-b5fa-4586-b5ee-00f12bb35c26","50",[],{"id":901,"separator":9,"field":855,"operator":867,"value":902,"rules":903},"67f57e30-a844-41e5-ab12-e0c62d13bd21","24",[],{"id":905,"label":906,"variant":907,"variantIndex":908,"variantColor":909,"variantIcon":910,"variantText":911,"contentHtml":912,"displayConditions":913},"b0439e5f-0170-4952-b7e5-3d215ccf73b8","On n'y est pas...","Danger",3,"#DC3545","icon-alert-triangle","Problème/danger","\u003Cp>Il faut certainement reprendre les notions essentielles. Ne désespérez pas, vous allez y arriver la prochaine fois !\u003C/p>",{"id":914,"separator":656,"field":9,"operator":657,"value":9,"rules":915},"33cd59c4-161f-4681-b169-ad69d284e465",[916],{"id":917,"separator":9,"field":855,"operator":872,"value":918,"rules":919},"e96205f0-7a1e-4441-bce9-b64b50b09764","25",[],"4c51f90a-abfd-4dc3-9a68-88a20b7f0cf3","1.0","Vérification des connaissances du RGPD","BhE83Y2TOJUmjeIPkS7sezWPNKTkEUDPZ8H8z33lXTzAdB1Vlv003qbrVCtA",9,"https://static.dastra.eu/tenant-3/audit/D3MmHAmuJ1dWnM/icon-audit500x-150.png","Testez vos connaissances sur le Règlement générale sur la protection des données (RGPD). \n\nA travers ce questionnaire, vous évaluez rapidement votre niveau de connaissance et participez à l'obligation de formation des personnes clés sur le sujet de la protection des données à caractère personnel. \n","2022-05-16T08:14:48.1269241","2024-08-30T13:55:15.1798857","Standard",{"id":931,"displayName":932,"familyName":933,"givenName":934,"email":935,"active":34,"color":936,"avatarUrl":937,"tenantId":11},69,"Dastro Naute","Naute","Dastro","contact@dastra.eu","#784000","https://static.dastra.eu/tenant-3/avatar/69/assistant-150.png",[939],{"id":940,"displayName":941,"familyName":942,"givenName":943,"email":944,"active":34,"color":945,"avatarUrl":946,"tenantId":11},31,"Jérôme de Mercey","de Mercey","Jérôme","jerome.demercey@dastra.eu","#99C691","https://static.dastra.eu/tenant-10/avatar/31/Zuh7XFZe5EnnTo/design-sans-titre-2-150.png",[948],{"id":949,"label":950,"type":951,"typeIndex":924,"typeColor":952,"typeIcon":953,"typeText":954,"color":955},"87b8e0f8-3e5f-435a-806f-f6011b1fa576","RGPD","AuditTemplate","#83d162","ds-icon-audit","Modèle de questionnaire","#6610f2",37]