
Learn the fundamentals of GDPR and data protection, the privacy versus data protection distinction, and beginner-level compliance steps across the three training levels and nine chapters.
Explore the GDPR framework, define personal data and processing, and outline data subject rights, roles (data controller, processor, data protection officer), and principles of data protection by design and default.
Clarify GDPR data protection compliance by outlining obligations to inform data subjects, and protect personal data as a fundamental right under Article 8, with clear duties for data controllers.
Understand the three training levels—foundations, advanced, and expert—and focus on who, what, where, and evaluation. Apply foundations skills to restate, convert, and list elements, and follow slides with readings later.
Distinguish privacy from data protection, identify data subject rights, and outline six steps and mechanisms to help data controllers achieve GDPR compliance.
Stay on track with the course by scheduling sufficient study time, using the ppt slides to answer questions, and focusing on the bigger picture rather than all details.
Explore non-mandatory GDPR resources for self-study, including overviews, infographics, terms and definitions, guides, guidelines, and official EU texts accessible via the resources button.
Explore the GDPR work plan architecture and the lines of defences for GDPR compliance. Understand the main elements, requirements, and controls, and why GDPR compliance matters, with a concluding quiz.
Explore how GDPR compliance uses lines of defence and mechanisms—DPO, DPIA, risk assessments, audits, and certification—across floor and department levels, with data security ensuring confidentiality, integrity, availability, and resilience.
Discover GDPR compliance requirements and controls, including lawful processing under Article 5, smart actions, data life-cycle management, and safeguards such as cryptography and two-factor authentication.
Develop and implement a GDPR compliance work plan that outlines goals and processes to help data controllers and the DPO achieve GDPR obligations and provide evidence for accountability.
Explore a basic GDPR work plan architecture based on IBM's framework, covering assessment with roadmap, design with implementation plan, transform, conformance, and ongoing monitoring for an operational framework.
Evaluate the GDPR compliance system’s defences, explain compliance requirements and controls, and review the GDPR work plan’s design, then complete section 2 via the ppt slides and quiz.
Explore the GDPR processing principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability, plus penalties for non-compliance.
Understand GDPR's lawfulness, fairness, and transparency principles, including Article 6 grounds for processing, and how privacy by design and default embed seven core principles across the data life-cycle.
Apply the purpose limitation, data minimization, and accuracy principles to GDPR processing by specifying legitimate purposes, collecting only necessary data, and maintaining accurate records, with rights to rectification and erasure.
Investigate the necessity, storage limitation, and integrity and confidentiality principles of the GDPR; ensure data accuracy, enforce minimum retention via retention policies, and apply pseudonymization and security measures.
Explain the accountability principle under article 5 second section, and how data controllers demonstrate compliance to avoid administrative fines up to 4% of worldwide turnover.
Review section 3 concepts on processing personal data: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, confidentiality, and GDPR accountability, and prepare for section 4 with the evaluation.
Discover non-mandatory GDPR self-study resources curated by EDPS, including overviews, infographics, terms and definitions, guides, guidelines, and official EU texts accessible via the resources button.
Explore GDPR data subject rights, including information, access, rectification, erasure, and objections to direct marketing and automated decision making, and connect to Chapter III sections on transparency and information access.
Explore the right to information under GDPR, detailing transparency requirements for data collected from data subjects and for data not obtained from subjects, including article 12 and 13.
Explore data subject rights: the right to access, rectification, and erasure (the right to be forgotten). Understand the data, purposes, recipients, and conditions for deletion.
Explore GDPR data subject rights like restriction of processing, notification information, and data portability, including how controllers communicate changes to recipients.
Understand the general right to object to processing, the right to object to direct marketing, and the right not to be subjected to automated decision making (AIDM) under GDPR.
Cover section 4 concepts on data subject rights, including information, access, rectification, and the right to object to direct marketing and AIDM, and outline data controller compliance measures.
Explore additional, non-mandatory GDPR resources for self-study, including overviews, infographics, terms and definitions, guides, guidelines, and official EU texts accessed via the resources button.
Explore GDPR compliance mechanisms, including certification, auditing, and monitoring, and examine the data protection impact assessment and the role of the data protection officer for data controllers.
Explore how GDPR compliance mechanisms drive evidence-based acting per obligations, including metrics, audits, DPIAs, and certifications, to demonstrate data protection across systems and personnel.
Plan and conduct a GDPR audit, report risks, and monitor ongoing compliance by updating TOMs and following recommendations to raise GDPR maturity.
Understand the data protection impact assessment (DPIA) as a GDPR mechanism that evaluates high-risk processing, requires DPO input, and follows a structured method guided by CNIL’s free open-source tools.
Explore the data protection officer role under GDPR, detailing tasks to inform and advise, monitor compliance, provide DPIA guidance, ensure independence, and direct reporting to top management.
Review section five on compliance mechanisms, certification, auditing, monitoring, DPIA, and the data protection officer, and prepare for section six on technical and organizational measures and GDPR obligations.
Access a curated, non-mandatory set of GDPR resources, including infographics, terms and definitions, guides, and official EU texts. Use the resources button to access all of these.
Explore technical and organisational measures (TOMs) for GDPR compliance, apply a risk-based approach to information security, and assess your understanding through a quiz.
Explore the definition and rationale of technical and organizational measures (TOMs), including examples such as pseudonymisation, encryption, access control, risk assessment, and GDPR governance.
Define the test of appropriateness and what constitutes appropriate measures under article 24 GDPR, guided by 2019 EDPB guidelines, and apply state-of-the-art privacy by design to mitigate risks.
Understand the GDPR risk-based approach, assess risk management components, and map risks by severity and likelihood to protect data subject rights.
Explore GDPR information security concepts, the CIA triad, and risk management for personal data processing, including breach assessment, ENISA guidelines, and DPO oversight.
Evaluate section 6 by reviewing technical and organizational measures (toms), the test of appropriateness, and risk-based thinking behind GDPR, and prepare for section 7 on data transfers outside the eu.
Access non mandatory extra readings and official EU texts through the resources button, including overviews, infographics, terms and definitions, guides, and guidelines for self-study.
Explore how to transfer personal data outside the EU, including adequacy decisions, appropriate safeguards, binding corporate rules, delegations, and exemptions, and test your understanding with a quiz.
Discover the general principle for transfers outside the EU and the six transfer mechanisms under GDPR to ensure adequacy criteria and protection.
Explore how the GDPR governs transfers to third countries with appropriate safeguards, including contractual clauses, binding corporate rules, standard data protection clauses, codes of conduct, and the consistency mechanism.
Explore binding corporate rules for international data transfers, including BCRs and PBCRs, their minimum specifications, supervisory approval, and integration with the SLA under article 28.
Understand not authorised transfers under EU law, derogations for specific situations, and Article 49 exemptions, including consent, contract necessity, public interest, legal claims, and occasional transfers.
Recap the international transfer of personal data outside the EU, including adequacy decisions, standard contractual clauses, approved code of conduct, and binding corporate rules, plus derogations and supervisory authority approvals.
Access a curated set of additional GDPR resources for self-study, including overviews, infographics, terms and definitions, guides, guidelines, and official EU texts, accessible via the resources button.
Explore GDPR damages, liability, and enforcement, and learn the roles of data protection authorities and the EDPB. Preview the basic GDPR work plan and a bonus EU certificate.
Explore damages, compensation, and liability under article 82 GDPR, including non-compliance exemptions and the controller and processor responsibilities for processing-related damage.
Explore how data protection authorities and the European Data Protection Board ensure GDPR compliance through cooperation, consistency, and remedies for data subjects.
Execute a six-step GDPR work plan—data mapping, baseline, gap analysis, implementation, evaluation, and accountability report—driven by the PDCA cycle, with a focus on data life-cycle obligations and Article 13 disclosures.
Wrap up the GDPR data protection course by recapping the six-step work plan, data subject rights, DPIA considerations, and ongoing learning opportunities for deeper privacy expertise.
Access non-mandatory GDPR resources for self-study, including overviews, infographics, terms and definitions, guides, guidelines, and official EU texts via the resources button.
Unique course, instructed by Top EU Expert (Chairman EU Certification Committee of EADPP), made available for larger audience at affordable cost (commercial EU value of this course is € 3,500 ex VAT). In this resourceful course, beginners in the fields of privacy and data protection will learn the foundations of privacy and data protection compliance key concepts and the 6 components of a basic GDPR work plan in plain English for career boosting and personal development. With this course, students can opt for official EU certification and registration.
Why this course?
Competition in today’s job market is fierce. Regardless of the industry, those who can clearly and immediately illustrate their knowledge and expertise will have a distinct advantage over other potential job applicants. In the field of European Data Protection, nothing shows your qualifications better than official EU certification sought by top employers.
Secure your place in the data protection economy. Show off your knowledge and skills by adding an official certificate to your CV. Everybody on this planet is directly or indirectly connected to subjects of privacy and data protection and needs to know the foundations of data protection in our modern digital society.
There is an ever growing internationally recognized demand and need for employees of companies (data controllers) to know at least the basics of privacy and data protection and the meaning of this in daily practices. This applies for everyone, not only in his/her role as an employee, but also as a ‘citizen’ and as a private individual (parent, child). The EU General Data Protection Regulation (GDPR) will be explained from a practical lens of the data controller who needs to implement appropriate measures to protect personal data. The GDPR is influential for data protection practices around the globe.
Based on more than 25+ years of practical experience as a data protection professional (as business manager and lawyer), the instructor – who has been involved in many European initiatives in the field – will guide you through the main pillars of the GDPR (at introductory level 1) which will help to boost your insights, right from the start.
Unlike many other courses in the field of GDPR data protection, in this course the instructor, a seasoned professor and advisor both in academia and in practice (at private, public and semi—public EU institutes) maintains a very practical hands-on approach of ‘FAIR’ and ‘EASY’ learning.
Although privacy and data protection are relevant for our daily lives and can be used in many practical ways, in literature and in many publications by so called ‘top specialists’ these concepts are usually presented as ‘vague and complex’. In practice this leads to many misunderstandings or miscommunications. How to fix this? Part of the solution is to provide clear answers to fundamental questions. That is basically the philosophy behind this course.
This course will provide you with the foundational knowledge to think as a (employee of a) data controller who is responsible and liable for processing personal data.
This introductory course will start with a solid, clear understanding of the key concepts (such as the difference between privacy and data protection, privacy by design and default, technical and organisational measures et cetera) as used in the GDPR (and most other international data protection best practices) and what a data controller is supposed in order to comply with GDPR obligations.
Requirements
You don't need to have any prior knowledge of privacy and data protection
Some of the provided materials you may wish to print
Unique learning: FAIR and EASY
This foundation course is designed to encourage students to get a proper and sound understanding of the EU General Data Protection Regulation (GDPR) based on two learning techniques.
FAIR as an acronym for ‘Fast learning by Asking Iterating Relevance’ by repeatedly asking the question of ‘why?’.
EASY as an acronym for ‘Educated Answers Suit You’ by repeated asking the question of ‘what does this mean in practice’?
Paramount technique for this is using the SMART check for any action in practice which should be (Specific, Measurable, Accepted, Realistic and Time restricted)
Fair and easy learning has been developed and applied by the instructor during his 25+ years of experience in education and training of many privacy and data protection professionals providing for:
Demystification of complex issues
Learning to be aware of distinguishing between ‘facts’ and ‘opinions’
Discussing bare essentials (by sticking to the core rationales)
Structured overviews for comprehensive understanding
The course content is based on the learning principles of the European Institute for Privacy Audit, Compliance and Certification (EIPACC) and is agnostic of disciplinary backgrounds of students (law, IT, security or any other discipline) and will discuss certain terms and definitions using ‘lay men language.’ In this way, we will get to the bare essentials of what is discussed.
Unique course resources for Udemy students
Free online access to relevant parts of GDPR Resources (official GDPR related texts), value: € 100
Discount VIP code (10%) for several GDPR online learning materials (upon availability) with a value of: € 100
Course Goals
At the end of the course, students will be able to:
Make a clear distinction between privacy, data protection and data subject rights compliance
List the most important ways (mechanisms) for data controllers to become compliant
Check if implemented data protection measures are ‘appropriate’
Clarify 6 steps to become data protection compliant (work plan basic design)
Target Students and Starting Practioners
Primarily meant for students (legal, and non-legal) and starting practitioners who want to get a proper, well-structured introduction to basic compliance obligations of the data controller, learn key terms and concepts used in the European General Data Protection Regulation (GDPR) and learn about a GDPR Work Plan Design in plain English and want to get an official European Certification for this to boost their careers.
Throughout this course references are made to the legal text of the GDPR (attached as course material) and is explained in ‘layman terms.’
This course is especially interesting for students and starting practitioners for businesses:
Students who want to bolster their general privacy and GDPR data protection knowledge.
Students who want to scan the field of privacy and data protection for future careers
Students who want to refresh and check their present state of data protection knowledge.
Students who want to get familiar with key concepts like privacy and data protection.
Students who are not yet active in the field of GDPR data protection and looking for practical guidance as how to set up a basic design of a GDPR compliance work plan to be used as work.
Students who do not want to spend much time to understand the key rationales behind different ‘principles for processing personal data’.
Students who want to get explained (in layman terms) what ‘data subject rights’ are.
Students who want to obtain insights in different compliance mechanisms.
Students who want to get explained (in layman terms) what the main difference is between technical and organizational compliance measures.
Students who want to get explained (in layman terms) what the main methods are for transfer of international data outside the European Union.
Students who feel overwhelmed (or even maybe intimidated) by GDPR terms and definitions and want to this to get demystified.
This introductory course is especially interesting for starting practitioners for businesses:
Starting specialists in the field of privacy and data protection
Starting privacy officers
Starting data protection officers
Starting compliance specialists
Starting privacy and data protection compliance managers
Starting data protection specialists (Law, IT, Security, Compliance & Ethics)
Starting information managers
Starting privacy and data protection representatives
Starting privacy and data protection auditors
Starting privacy and data protection managers
Starting privacy and data protection project managers
Starting privacy and data protection risk officers
Starting privacy and data protection security officers
Starting privacy and data protection auditor
Starting general managers who need to know the basics of privacy and data protection compliance
Anyone else who (professionally or privately) wants to grow his/her basic knowledge of certified privacy and data protection and wants to get certified in these fields (as holder of an official EU certificate).
Pursued level of training for this course
This course is designed to acquire basic knowledge and comprehension (level 1) to get the student familiarized with theoretical and practical key compliance concepts and definitions used in the European General Data Protection Regulation (GDPR).
Disclaimer
Although this course is based on official EU or EU related primary resources (such as official texts, official guidelines and official certification schemes) the course instructor might share practical insights based on more than 25+ years of practical experience that may not exactly be in line with these primary resources. However, students who complete this course are eligible for official certification and registration in the European Union.
Any Queries?
In case of any queries, please feel free to send an email to the instructor.
About the Instructor
Professor mr drs Romeo F. Kadir MA MSc LLM LLM (Adv) EMBA EMoC - Chairman of the EU Certification Committee of the European Association of Data Protection Professionals (EADPP) and Chairman of the Academic Quality Management Board (AQMB) of the European Institute for Privacy Audit, Compliance and Certification (EIPACC)- is a much respected European industry expert in the field of privacy and data protection. Based on his vast practical experience in the European Union – Professor Kadir has trained many data protection professionals and advanced their careers, based on one ideological passion: sharing practical expert knowledge in the field of privacy and data protection with as many as people as possible. Why? As an ideologist (founder of several EU foundations and associations) combined with more than twenty years of corporate compliance experience he firmly believes in the quintessential role of knowledge-sharing with masses to bring across the societal value of fundamental privacy and data protection principles for which companies are responsible (and liable). Professor Romeo Kadir has one practical compliance passion throughout his data privacy compliance career. How to reduce complex issues to practical solutions? Are you also excited to experience this? Welcome to a unique classroom designed for your interesting learning curves.