
Explore the role and components of GDPR, including data controller, data processor, and data protection officer, and review the seven principles, penalties, and why trust matters in data protection.
Explore how GDPR principles govern lawful, fair, and transparent processing. Learn to apply purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability in data handling.
Learn how the UK GDPR governs personal data within the UK and for UK entities. Explore the roles of data controllers and processors, consent, transparency, and cross-border safeguards.
Identify the six GDPR lawful bases for processing: consent, contract, legal obligation, vital interests, public task, and legitimate interest, and learn to select and document the right basis.
Identify data subjects under GDPR and explain EU territorial scope. Summarize the eight rights, including access, rectification, erasure, restriction, portability, objection, and data subject access rights.
Explore the eight data subject rights under the GDPR, including rights to be informed, access, rectification, erasure, restriction, data portability, objection, and automated decision making.
Explain the GDPR data subject access right (DSR), including how to submit a DSR, the 30-day response rule, and electronic data delivery, with notes on fees and credit reference agencies.
Define the roles of data controller and data processor, and explain how joint controllers share responsibility and oversight. Describe the subprocessor duties and accountability for data breaches.
Learn how controllers, processors, and joint controllers must meet GDPR obligations, including lawful processing, transparency, accountability, data processor agreement, records, international transfers, and shared liability.
Examine processor obligations under GDPR, guaranteeing technical and organisational measures, pseudonymisation, encryption, confidentiality, integrity, restorability, and testing. Learn breach notification, processor-subprocessor consent, and safeguards under article 44.
Understand liabilities under the gdpr, including data controllers' and processors' duties and the possibility of remaining liable for processor breaches. Learn how to pursue claims against processors.
Apply data protection by design and by default across the processing life cycle under the GDPR, minimize data, protect data subjects, and ensure transparency and security.
Conduct a data protection impact assessment (DPIA) to identify processing risks, consult the Data Protection Officer, evaluate necessity and proportionality, and mitigate high-risk processing under GDPR article 35.
Explore the role and responsibilities of the data protection officer (DPO) under GDPR article 39 for data controllers and processors, including compliance, internal audits, Dpia involvement, and reporting.
Explore data security under Article 32, focusing on confidentiality, integrity, and availability of personal data. Learn to identify data assets, enforce least privilege, use pseudonymization, and ensure backups and resilience.
Explain Article 32 obligations to implement appropriate technical and organizational measures, considering state of the art, risks to individuals, encryption or pseudonymisation, resilience, and security frameworks like ISO 27001 and SOC 2.
Identify and value data assets to secure data under GDPR, assess both hard copy and electronic data, classify data for need-to-know access, and assign an information asset owner.
Identify data assets, assign value, and layer security controls across technical, procedural, personnel, and physical domains. Regularly test and assess controls to prove risk management and GDPR compliance.
Learn what counts as a data breach under GDPR, including unauthorized destruction, loss, alteration or access, plus real-world scenarios like misdirected emails, lost devices, phishing and ransomware.
Categorize breaches into confidentiality, integrity, and availability, noting they can occur simultaneously; examples include accidental deletions, lost decryption keys, and service disruptions.
Assess data breaches under the GDPR by determining if a breach occurred and evaluating its probability and severity on individuals' rights and freedoms, guiding notifications to authorities and data subjects.
Examine how data breaches threaten individuals' rights under GDPR recital 85, with risks like loss of control, discrimination, identity theft, financial loss, and reputational damage if not addressed promptly.
Learn how the GDPR defines when you become aware of a data breach and initiate the notification countdown, with examples from data loss, unauthorized disclosure, network intrusion, and cybercrime.
Begin a rapid breach investigation as soon as you become aware of a security incident or potential data breach, determine breach certainty, and trigger the 72 hour notification period.
Determine if a data breach affects individuals' rights and freedoms and decide on notifying authorities and data subjects, then implement a breach response plan with analysis, containment, reporting, and PR.
Maintain internal records of data breaches, including notification status, breach facts, effects, remedial actions, and investigation; note GDPR article 33(5) obligations, training needs, and notify banks, insurers, police, and others.
Understand why employee data is sensitive under GDPR, including special category data such as health and racial background, and how consent and legitimate purposes ensure secure storage and appropriate use.
Explore lawful grounds for processing employee data: consent, contractual necessity, legal obligation, and legitimate interests. Apply balancing test and legitimate interests assessment across employees, candidates, former staff, and pension matters.
Draft an employee privacy notice detailing how employment data is collected, used, transferred, retained, and protected, including special category data and criminal convictions, as well as data subject rights.
Learn how to balance legitimate business interests with employee privacy through GDPR-aligned monitoring, transparency, purpose limitation, data minimization, and proportionality, including CCTV and biometric considerations.
Explore the GDPR’s gold standard for data protection and how transfers outside the EU and outside the EEA require safeguards. Learn who counts as recipients, including organisations, individuals, and affiliates.
Explore how GDPR article 45 permits data transfers through adequacy findings with Andorra, Argentina, Faroe Islands, Guernsey, Israel, Japan, New Zealand, Switzerland, Uruguay, and Canada; US has no adequacy.
Examine data transfer after Brexit, where the UK is a third country with an EU adequacy finding, subject to review, possible revocation, and transitional arrangements.
Learn how data in transit and onward transfers are regulated under the GDPR, including direct transfers outside the EEA and indirect transfers via third parties.
Understand standard contractual clauses (SCCs) with European Commission approved wording to govern transfers, including controller-to-controller and controller-to-processor transfers, plus Schrems II implications for non-EU destinations.
Learn how binding corporate rules (BCR) enable secure cross-border data transfers among group companies with enforceable data subject rights, audits, and service agreements binding all members.
Explore derogations for international transfers when no adequacy finding, BCRs, or standard contractual clauses exist. Use them as a last resort, or rely on data subject consent with risks explained.
Are you interested in gaining a concrete GDPR understanding and becoming a successful Data Protection professional? So, here is our comprehensive Data Protection and Security course to make you an expert in this attractive profession.
When conducting business within EU member states, enterprises are required by GDPR to respect EU individuals' personal information and privacy. The General Data Protection Regulation (GDPR) ensures public data security.
Throughout the course, you will learn everything there is to know about GDPR. If you’re in a profession that demands you to have a concise knowledge of GDPR, we'll walk you through the scope, principles, and application of GDPR, which is critical to understanding. Aside from that, we'll explain the data subject, data processor and data controllers, etc. Understanding these are essential for getting expertise in data protection and data security.
But that's not all! We will go beyond the basics and delve into the legislation surrounding data security, teaching you how to conduct regular testing and assessments to ensure foolproof protection. We'll also discuss data breaches and the importance of GDPR in workplace data protection.
By the end of the course, you’ll have a solid foundation in data security and compliance.
Don’t miss out on the chance to gain knowledge on General Data Protection Regulation (GDPR) from our exclusive Data Protection and Security course and get lifetime access.
This course comes with the following Sections:
Introduction to GDPR: In this section, we will learn about the fundamentals of the General Data Protection Regulation (GDPR). GDPR is a set of regulations that were passed by the European Union in 2018. It is designed to give individuals more control over their data security.
Principles of GDPR: To have a solid idea of GDPR, one needs to learn about the principles of GDPR. In this section, we’ll discuss the core principles of GDPR. We’ll also discuss why these principles are necessary, we will also discuss their importance.
Lawful Basis for Processing: We will discuss the lawful basis for processing in this section, which is one of the most important components of GDPR/data protection. In addition to discussing legal obligations, we'll show you how to choose an appropriate lawful basis for processing.
Rights of Data Subject: This section focuses on individuals' rights regarding their data, commonly known as data subjects. We will explore various aspects of data subjects such as the definition and significance of data subjects, the extent of their rights, and several related topics.
Data Controller and Data Processor: It is important that you understand how data controllers and data processors work in order to ensure data protection and security. This section will help you have a solid understanding of different data controllers and data processors.
Data Protection: This section of our GDPR-focused course fully concentrates on the concept of data protection. Data Protection by Design and Default and its fundamentals as well as Data Protection Impact Assessment (DPIA), its process, risk mitigation, and much more will be discussed.
Security of Data: We will explore all aspects of data security, including how you secure, store, and process the personal data you collect, store, and process as a data controller or data processor in this section.
Data Breaches: A data breach occurs when sensitive, confidential, or private data is copied, transmitted, viewed, stolen, or used by unauthorized individuals. In this section, we will learn about assessing data breaches, investigating breaches, and more.
Workplace and GDPR: The focus of this section is on the proper legal bases for processing employee data, and legal bases for processing the data of former workers. Additionally, we’ll discuss the principles of employee monitoring.
Transferring Data Outside of EEA: The Standard Contractual Clause, data transfer and Brexit, and data transfer outside the European Economic Area will be discussed in this section. It is essential to understand how binding corporate rules can be established to ensure compliance with data protection requirements, which will also be discussed in this section.
Exemptions: This section aims to familiarise you with exemption fundamentals, including how they operate. Through this section, you will also explore and apply specific exemptions to real-world scenarios.