
Learn how a single staff member protects personal data at work by applying GDPR principles, completing staff training, securing information, and managing breaches, consents, and data subject requests.
Assess your current data protection approach, identify breach risks and failure drivers like lack of guidance or training, and commit to a conscious, motivated effort to protect data.
Protecting data reduces staff liability from internal duties and unlawful processing, data sharing, and copying, while safeguarding your job, career, and reputation and cutting time and cost pressures.
Learn what constitutes personal data under GDPR by recognizing information relating to a natural person that can be identified in context and the means likely to identify them.
Identify personal data and explain how processing covers the full lifecycle from collection to erasure, including transmission risks and GDPR processing operations such as storage, retrieval, and destruction.
Identify and differentiate data protection roles such as controller, joint controller, processor, and further processor, and implement organization-wide measures to demonstrate GDPR compliance.
Discover how to apply the six data processing principles, including lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality.
Clarify roles and responsibilities in data protection across all staff, highlight that everyone forms the data protection system, and encourage raising questions to maintain current documentation and security practices.
Explore the data minimization and need to know principles to guide lawful data processing, focusing on minimizing data, checking permissions, and restricting access to relevant personal data.
Recognize your influence over data processing and assets, apply safeguards, and report changes, using GDPR by design to balance security with business needs.
Apply need-to-know access to all assets, safeguard devices, encrypt data, and handle remote work with pre-authorization; identify risks and report issues.
Identify and report personal data breaches, assess them internally, minimize damage, preserve evidence, notify the supervisory authority within 72 hours, and alert data subjects when risk is high.
Provide GDPR information on data processing to enable data subjects to exercise rights and understand collection sources, purposes, legal bases, and transfers outside the EEA, with safeguards.
Explain GDPR legal bases beyond consent (articles 6 and 9) and special categories of personal data. Learn when consent is appropriate and ensure it is freely given, specific, and explicit.
Explore what to include in controller-processor contracts under GDPR article 28, how joint controller agreements work, and how to manage data sharing with employees, associates, clients, contractors, and suppliers.
Identify a data subject request contact point and process access, erasure, or rectification requests under GDPR, regardless of form, replying within one month, notifying the subject of extensions if needed.
Assess how this training reshapes your understanding of data, processing operations, and data protection principles. Apply the need-to-know principle and promptly report doubts, incidents, and data subject requests.
In this training, you will learn how a single staff member should protect personal data at work. Next to industry, country or even culture-specific norms on privacy, there is a universal standard to follow when you are at work.
This standard is now being set by the GDPR, the European Union’s regulation that is increasingly followed all over the world. The regulation and similar laws in different states require to train employees and associates, as the level of data protection depends on all staff members, including you.
We will start from scratch to clarify your understanding of what are personal data, what it means to process them and on whose behalf you act. You will learn what principles to apply, how to secure information and how to act in case a breach occurs. I will also cover providing information, collecting consents and handling data subject requests.
Having worked at the supervisory authority and carried out many data protection projects in national and international firms, now I tell what an every single staff member needs to know and follow in daily work. There is no time for theory and data protection is probably not the most important part of your job. But it is a part you want to approach efficiently, so privacy is respected and breaches are not likely to happen.
In case of legal proceedings or an inspection, the authority examines if you and your organization applied adequate measures to protect data. Also your clients might require your company to provide them with guarantees. Complete this training and start taking right steps