
Explore the GDPR overview, detailing the regulation's scope, data subject rights, and data controller roles. Understand how any business processing EU data or citizens' information must comply with the regulation.
Discover how the General Data Protection Regulation standardizes EU data privacy, protects natural persons, governs personal data processing, and enforces cross-border data rules with harmonization.
Explore the general data protection regulation overview part 2, detailing data subject rights, the roles of controllers and processors, cross-border scope, and safeguards like pseudonymization, encryption, and the CIA triad.
Explore the data protection officer role under the GDPR, including breach notification, controller-processor accountability, and privacy by design in large-scale data processing.
The GDPR requires explicit, freely given consent for specific purposes and recipients, and guarantees data subjects rights to access, rectify, erase, port data, withdraw consent, and complain to supervisory authorities.
Learn how GDPR governs data breaches, including 72-hour notifications, data subject rights, and exceptions for encryption and risk-mitigation actions. Understand data subject access requests, data retention, and downstream processor responsibilities.
Examine the GDPR principles, grounded in Article 5, outlining lawful processing, purpose limitation, data minimization, accuracy, retention, and the accountability of controllers and processors.
Delve into lawful processing under the GDPR, examining Article 6 bases, consent requirements, and exceptions for special data categories and member state additions.
Learn consent under the GDPR, and the controller and processor roles, with key definitions from articles 4 and 8, including children's data and age of consent.
Explore the eight GDPR individual rights, including the right to be informed, right of access, rectification, erasure, restriction, data portability, objection, and protections against automated decision making.
Learn how the right to be informed requires transparent, concise, and accessible information about processing, modalities for communication, and the duties of controllers to respond within 30 days.
Understand the GDPR right of access (Article 15): data subjects can verify processing and obtain details of their personal data, with timelines and possible refusals.
Explore the right to rectification under the GDPR, enabling data subjects to have inaccurate personal data corrected by the controller without undue delay, and notify data recipients of changes.
Explore the right to erasure under the GDPR Article 17, including when data must be deleted, exceptions, direct marketing limits, and special considerations for children's data and downstream sharing.
Discover the right to restrict processing under the GDPR, allowing data subjects to pause processing when data is inaccurate, unlawfully processed, or needed for legal claims.
Explain the right to data portability under article 20: receive your personal data in a machine-readable format (CSV) and move it to another controller, where technically feasible, at no charge.
Explore the GDPR right to object under article 21, how data subjects halt processing (including direct marketing) and when compelling grounds or supervisory authority override objections.
Explore GDPR article 22 on automated decision making and profiling, uncovering the data subject's right to human intervention, explanation, and challenges, with safeguards and contract exemptions.
Explore accountability and governance under the GDPR, detailing the controller’s obligation to demonstrate compliance, appoint a data protection officer, and maintain records of processing activities.
Learn how the GDPR regulates transfers of personal data to third countries or international organizations under articles 44 to 49, using adequacy decisions, safeguards, consent, and binding corporate rules.
The gdpr breach notification requires notifying the supervisory authority within 72 hours and data subjects when risk is high. Encryption may exempt; fines up to 20 million euros or 4%.
Learn how GDPR national derogations allow states to carve exemptions while balancing security, public interest, and data rights. The section also emphasizes transparency and notifying the commission of changes.
In April of 2016, the European Commission published a data protection package to reform, modernize and harmonize European data protection law. The cornerstone of the package is the General Data Protection Regulation (GDPR) which will replace the 1995 Data Protection Directive and, in the UK, the Data Protection Act 1998. This overview highlights the key themes of the General Data Protection Regulation (GDPR) to help organizations understand the new legal framework in the EU. It is for those who have day-to-day responsibility for data protection.
The General Data Protection Regulation (GDPR) Fundamentals course is designed to provide a comprehensive understanding of the principles and requirements of the GDPR, which is a legal framework governing data protection and privacy within the European Union (EU) and the European Economic Area (EEA).
It is important to note that the GDPR is a complex legal framework, and seeking legal advice or consulting specialized professionals is recommended for comprehensive and tailored guidance related to GDPR compliance in specific contexts or industries.
While no specific prerequisite is mandatory, to effectively engage with and benefit from the General Data Protection Regulation (GDPR) course, participants should ideally have a basic understanding of data protection concepts, privacy principles, and the legal framework surrounding data privacy.
The General Data Protection Regulation (GDPR) course is relevant to a wide range of individuals and professionals who handle or are responsible for the processing of personal data within organizations.