Highlights
- This course will provide you with the foundational knowledge to think as a (employee of a) data controller who is responsible and liable for processing personal data
- Based on more than 25+ years of practical experience as a data protection professional (as business manager and lawyer)
- Unlimited access
Objectives
- Make a clear distinction between privacy and data protection,
- Apply 10 different GDPR principles of processing personal data,
- Distinguish between all important data subject rights,
- Contribute to quality GDPR debates at work and in your personal life
Program
Introduction
- Privacy and Data Protection, Certified GDPR Compliance Overview
- Brief Introduction to Privacy and Data Protection
- Introduction to Data Protection Compliance
- The main practical compliance difference between privacy and data protection
- Three levels of training
- Course Goals: finding clarity from theory to practice
- Success factors for finishing this course
- Additional GDPR Useful Resources for Self-Study (non-mandatory) | EC & EDPS
Section 2 GDPR Work Plan: From Theory to Practice
- Privacy and Data Protection, Certified GDPR Compliance Overview
- GDPR compliance lines of defence
- GDPR Compliance requirements and controls
- What is a GDPR compliance Work Plan?
- Basic design of a GDPR Work Plan
- Wrap Up & Evaluation Section 2
- What is a GDPR compliance line of defence?
Section 3 Principles of Processing: From Theory to Practice
- Privacy and Data Protection, Certified GDPR Compliance Overview
- Lawfulness, Fairness and Transparency
- Purpose Limitation, Data Minimisation
- Practical exercise to apply the requirement of purpose specification
- Necessity, Storage Limitation, Integrity and Confidentiality
- Accountability and Administrative Fines
- Wrap Up & Evaluation Section 3
- Work sheet Application of Principles
- Additional GDPR Useful Resources for Self-Study (non-mandatory) | EDPS
Section 4 Data Subjects Rights Compliance: From Theory to Practice
- Privacy and Data Protection, Certified GDPR Compliance Overview
- Data Subject Rights, Right to Information
- Right to Access, Rectification & Right to be Forgotten
- Right to Restriction, Notification and Portability
- Right to Object, Object to Direct Marketing and Automated Decision Making (ADM)
- Wrap Up & Evaluation Section 4
- Right to erasure (Right to be forgotten)
- Additional GDPR Useful Resources for Self-Study (non-mandatory)| EDPS
Section 5 GDPR Compliance Mechanisms: From Theory to Practice
- Privacy and Data Protection, Certified GDPR Compliance Overview
- Definition of Compliance Mechanisms
- Auditing(Planning & Reporting) & Monitoring
- Data Protection Impact Assessment (DPIA)
- Data Protection Officer (DPO)
- Wrap Up & Evaluation Section 5
- Definition of GDPR Compliance Measures
- Additional GDPR Useful Resources for Self-Study (non-mandatory) | EDPB & EDPS
Section 6 Technical and Organisational Measures: From Theory to Practice
- Privacy and Data Protection, Certified GDPR Compliance Overview
- Definition of Technical and Organisational Measures (TOMs)
- Test of Appropriateness of TOMs
- Scope of technical and organisational measures
- Risk Based Approach (GDPR Risk Matrix)
- Information Security Compliance
- Wrap Up & Evaluation Section 6
- Difference between technical and organisational measures in the GDPR
- Additional GDPR Useful Resources for Self-Study (non-mandatory) | CNIL & EDPS
Section 7 Transfer of Personal Data to Third Countries: From Theory to Practice
- Privacy and Data Protection, Certified GDPR Compliance Overview
- General principle for transferring personal data outside the EU and Adequacy
- Appropriate Safeguards
- Binding Corporate Rules (BCRs) and Processor Binding Corporate Rules (PBCR's)
- Not Authorised Transfers and Specific Situations (and Exemptions)
- Wrap Up & Evaluation Section 7
- Transfer of personal data of EU citizens from the EU to the United States
- Additional GDPR Useful Resources for Self-Study (non-mandatory) | EDPS
Section 8 Damages compensation, Fines and Work Plan Design
- Privacy and Data Protection, Certified GDPR Compliance Overview
- Damages and Liability for not being GDPR compliant
- Data Protection Authority (DPA) & Role of European Data Protection Board (EDPB)
- 6 Steps of a Basic GDPR Work Plan Design
- Wrap Up, Closure & Continuing Learning
- Purpose of a GDPR Gap-analysis
- Additional GDPR Useful Resources for Self-Study (non-mandatory) | EDPS
Bonus Lecture
Targeted audience
Students (legal, and non-legal) who want to get a proper, well-structured introduction to basic compliance obligations of the data controller, learn key terms and concepts used in the European General Data Protection Regulation (GDPR)
Reviews
Anna Platonova Wonderful course! The way how the information is presented (with visual support and in a very clear manner) makes me feel very energized to study. All the basic and necessary information is clearly provided, all you need to know for basic understanding of GDPR and how to follow it. I am really enjoying the course and find it very useful.
Madhura Mohan Nikalje This was definitely one of the most informative courses on GDPR and the certification is the icing on the cake.
Amit Narayan Prasad The details are quite precise and well explained in totality.