RGPD and corporate training: what HR Directors need to know about learner data
Online training platforms (LMS) collect personal data on learners: identity, progress in modules, assessment results, time spent on each piece of content, connection data. These data are subject to the General Data Protection Regulation (RGPD) (GDPR). Companies deploying an LMS have specific obligations regarding lawful basis, retention period, learners' rights and transparency. The CNIL has issued several formal notices in this area since 2022.
What data do LMS collect?
A standard LMS collects several categories of data on each learner.
Identification data: surname, first name, professional email address, HRIS (Human Resources Information System) identifier, department, role, manager.
Pedagogical behaviour data: connection date and time, time spent on each module, progress rate, number of attempts on assessments, score achieved, answers to questions (in systems that retain them individually).
Performance data: post-test results, learning summaries obtained, progression on the skills framework, training history.
In LMS with AI features, additional data may be collected: navigation pattern analysis, inferences about learner gaps, personalised recommendations generated.
The applicable legal framework
The RGPD (GDPR) (Regulation (EU) 2016/679) applies to any collection and processing of personal data concerning natural persons established in the European Union, regardless of the processor's location (LMS vendor). Prior CNIL formalities were abolished by the RGPD, but substantive obligations are strengthened.
Lawful basis. For employee training data, the most commonly invoked lawful bases are the employer's legitimate interest (Article 6(1)(f) RGPD) or performance of the employment contract (Article 6(1)(b)). For mandatory regulatory training, the lawful basis is legal obligation (Article 6(1)(c)). The lawful basis must be documented in the processing register.
Record of processing activities. Any company employing 250 or more employees must keep a processing register. Companies with fewer than 250 employees must also keep it where processing is likely to pose a risk, is not occasional, or concerns sensitive data.
Retention periods. Training data must not be kept longer than necessary. A common reference is duration of employment plus 5 years for evidence, but this must be justified and documented.
Learners' rights. Employees must be informed of processing, its purpose, lawful basis, retention period and their rights (access, rectification, objection). Any AI-based assessment that produces legal or similarly significant effects must be explainable.
Practical checklist
Map LMS data flows, document lawful bases, set retention rules, inform employees, sign a data processing agreement with the vendor, and ensure hosting within the EU or with adequate safeguards.