By the end
What you'll build
- Design a privacy governance structure with clear roles, escalation and independence
- Maintain records of processing and a data map across multiple jurisdictions and business units
- Lead an impact assessment from threshold check through mitigation and sign-off
- Direct a breach response, including assessment, notification recommendations and post-incident review
- Build a transfer and vendor oversight model that survives audit and regulator scrutiny
- Report privacy risk and programme performance to a board or executive audience
Curriculum
What's inside
8 modules · 54 lessons
- 01
The role, its independence and its remit
7 lessons- Independence, conflict of interest and reporting lines that let the role work
- What organisations typically expect of the role
- Designation triggers and where to verify them for your jurisdiction
- Resourcing, seniority and access to leadership
- Conflicts: roles that cannot sit alongside this one
- + 2 more lessons
- 02
Standing up the programme
7 lessons- A twelve-month privacy programme plan you can defend to leadership
- Maturity assessment and honest baselining
- Policy architecture and ownership
- Privacy champions and the federated model
- Budget, tooling and build-versus-buy reasoning
- + 2 more lessons
- 03
Records, mapping and inventory at scale
7 lessons- Keeping a data map accurate across business units and jurisdictions
- Federated data collection and quality control
- Legacy systems, unsanctioned tools and acquired estates
- Retention schedules and defensible disposal at scale
- Linking records to assessments, transfers and vendors
- + 2 more lessons
- 04
Impact assessment practice
7 lessons- Running an assessment on a high-risk project without stalling the business
- Threshold assessment and when a full assessment is required
- Stakeholder interviews and eliciting real processing detail
- Risk to individuals: severity, likelihood and evidence
- Mitigation negotiation and residual-risk sign-off
- + 2 more lessons
- 05
Breach leadership
7 lessons- Directing a live breach: assessment, decisions and the notification recommendation
- Incident command and the roles around you
- Assessing risk to individuals under time pressure
- Notification thresholds and how they vary by jurisdiction
- Communicating with affected people and with the business
- + 2 more lessons
- 06
Vendors, transfers and cross-border operations
7 lessons- One programme, several regimes: designing an operating model for regional overlays
- Transfer mechanisms and the assessment behind them
- Government-access and onward-transfer questions
- Vendor tiering and proportionate due diligence
- Contractual terms and the audit rights you will actually use
- + 2 more lessons
- 07
Assurance, regulators and leadership reporting
7 lessons- Handling a regulator enquiry: preparation, posture and follow-through
- Aligning with an information security management system, and what certification of an organisation does and does not prove
- How an independent attestation report about a supplier should be read
- Internal audit, second-line assurance and evidence packs
- Complaint handling and the escalation path to a regulator
- + 2 more lessons
- 08
Practice and check
5 lessons- Who actually decidesmatch pairs
- Directing a live breachsequence order
- The practitioner's precise wordingfill blank
- Friday, 16:40scenario
- Course quizquiz
The shape of it
How this course works
Short lessons
54 lessons across 8 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
