In light of the rise in data breaches reported by the CNIL in the first quarter of 2026 and the announced tightening of oversight, we take stock of the protection of data collected by the Foundation with Frédéric Thu, Data Protection Officer (DPO) at CentraleSupélec.
What is your role as DPO at CentraleSupélec?
“As the DPO at CentraleSupélec, I am responsible for protecting people’s data—primarily students, but also employees, job applicants, guest speakers, and, of course, donors.” Protecting data naturally involves technical audits of applications, specific clauses in contracts with our suppliers, and verifying their reliability in the age of SaaS; it also involves working with the departments of the“A program to minimize the amount of data collected and retention periods, reduce the number of Excel spreadsheets sent via email, and raise awareness among all stakeholders about cybersecurity risks.”
What data does the Foundation collect?
“Together with the Foundation, we have applied the principle of data minimization: the data collected and processed is limited to the minimum necessary, such as the donation amount or the donor’s address. I also helped the Foundation carefully select partners who assist it in enriching its databases, always taking care to respect individuals’ wishes regarding whether or not they wish to be contacted. This is a requirement of the GDPR—but it’s also common sense and basic courtesy! I also verified that its service providers are, at a minimum, based in Europe, and if possible, in France: the GDPR considers that individuals’ data is less well protected outside the European Union, and geopolitical tensions only reinforce these sovereignty-based decisions.”
What specific measures are in place to ensure the security of the data collected by the Foundation?
“When it comes to security, only authorized individuals have access to the Foundation’s data: the more sensitive the data, the better it is protected.” The Foundation does not even have access to the most sensitive data, such as financial transaction details (credit card numbers). Access to the Foundation’s software is strictly tracked and subject to two-factor authentication, protected by up-to-date firewalls, intrusion detection systems, and other security measures; all service providers were required to accept the additional technical and contractual measures we imposed on them.
“Ultimately, it takes a lot of behind-the-scenes work to define, implement, and document these measures—and to ensure that they do not affect the people who place their trust in the School and the Foundation.”
___________________________________________________________________________________________________________________________________
Protecting the personal data of our supporters is an integral part of our commitments. Through rigorous practices in the areas of security, transparency, and GDPR compliance, the CentraleSupélec Foundation ensures the responsible and secure use of the data entrusted to it.
