By the end
What you'll build
- Distinguish controller, joint controller and processor roles for a given processing activity
- Map a simple data flow from collection through use, sharing, storage and deletion
- Read a record of processing entry and spot what is missing or out of date
- Explain what a privacy notice must tell people and check one against an actual activity
- Identify the privacy questions to raise before a new vendor or system is brought in
- Apply retention and deletion thinking to a set of real records
Curriculum
What's inside
8 modules · 49 lessons
- 01
Who is responsible for what
6 lessons- Controller, processor and joint controller: deciding which one you are
- Purposes and means: the test that settles the question
- Processors who quietly become controllers
- Sub-processors and the chain behind your supplier
- Accountability: showing your work, not just doing it
- + 1 more lesson
- 02
Knowing what data you hold
6 lessons- Building a first data inventory from what your team already uses
- Records of processing: purpose, categories, recipients, retention
- Interviewing a team to surface undocumented processing
- Systems, spreadsheets and the long tail of small tools
- Keeping the inventory alive after the first pass
- + 1 more lesson
- 03
The data lifecycle
7 lessons- Following one record from collection to deletion
- Collection: forms, imports, observation and inference
- Use and secondary use: the compatibility question
- Sharing internally and externally
- Storage, backups and the copies you forgot
- + 2 more lessons
- 04
Telling people what you do
6 lessons- Writing a privacy notice section people can actually understand
- What a notice is expected to cover in most regimes
- Layered notices and just-in-time wording
- Changing your processing after the notice went out
- Notices when the data came from somewhere else
- + 1 more lesson
- 05
Third parties and vendors
7 lessons- The privacy questions to ask before signing anything
- Due diligence proportionate to the risk
- Processing terms: what the contract needs to fix
- International transfers and the extra step they add
- Ongoing oversight, not one-off approval
- + 2 more lessons
- 06
Controls that make it real
6 lessons- Access control and the least-privilege habit for personal data
- Role-based access and periodic review
- Pseudonymisation, masking and test data
- Logging and monitoring without over-collecting
- Encryption in transit and at rest, explained for non-engineers
- + 1 more lesson
- 07
Governance and keeping it going
6 lessons- How privacy work is organised: roles, forums and escalation paths
- Policies, standards and procedures: what belongs where
- Privacy by design as a checkpoint, not a memo
- Metrics that tell you the programme is working
- Refresher training as company policy, and why intervals vary
- + 1 more lesson
- 08
Practice and check
5 lessons- Role, term, controlmatch pairs
- Onboarding a supplier that will hold personal datasequence order
- Say it preciselyfill blank
- Approving a new survey toolscenario
- Course quizquiz
The shape of it
How this course works
Short lessons
49 lessons across 8 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
