By the end
What you'll build
- Map personal data flows through a process and identify the lawful basis question at each step
- Distinguish controller and processor responsibilities in a given arrangement
- Build and maintain a record of processing activities that stays current
- Apply privacy by design to a new feature or process before it is built
- Design an operational workflow for handling data subject requests within a deadline
- Prepare privacy evidence and risk decisions for internal audit or a customer assessment
Curriculum
What's inside
8 modules · 47 lessons
- 01
Privacy on top of security
6 lessons- How a privacy management system extends a security management system
- Personal data: what counts and what surprises people
- Privacy principles at a working level
- Controller, processor and joint arrangements
- Where security controls stop being enough
- + 1 more lesson
- 02
Knowing your processing
6 lessons- Building a record of processing activities that does not go stale
- Discovering shadow processing across the business
- Data flow mapping for a single business process
- Special category and sensitive data handling
- Purpose limitation and scope creep
- + 1 more lesson
- 03
Lawfulness, notice and consent
6 lessons- Choosing and documenting a basis for processing
- Writing a privacy notice people can understand
- Consent: capturing, evidencing and withdrawing
- Legitimate interests and the balancing exercise
- When marketing rules differ from general processing rules
- + 1 more lesson
- 04
Privacy by design
6 lessons- Running a privacy impact assessment on a new feature
- Data minimisation as a design constraint
- Pseudonymisation and anonymisation: the real difference
- Retention schedules that actually delete
- Default settings and their privacy consequences
- + 1 more lesson
- 05
Rights and requests
6 lessons- Designing a data subject request workflow that meets deadlines
- Identity verification without collecting more data
- Access, correction, deletion and portability in operation
- Handling a request that spans several systems
- Refusals, exemptions and documenting the reasoning
- + 1 more lesson
- 06
Third parties and transfers
6 lessons- Processor contracts and the assurance you need behind them
- Due diligence on a processor before signing
- Sub-processors and chained responsibility
- Cross-border transfer considerations in general terms
- Monitoring third parties after onboarding
- + 1 more lesson
- 07
Accountability and assurance
6 lessons- Demonstrating accountability instead of asserting it
- Privacy incident and breach handling workflows
- Internal audit of privacy controls
- Management review with privacy inputs
- Preparing for a customer privacy assessment
- + 1 more lesson
- 08
Practice and check
5 lessons- Why privacy work failsmatch pairs
- Handling a rights request in ordersequence order
- Getting the privacy vocabulary exactfill blank
- Two weeks to launchscenario
- Course quizquiz
The shape of it
How this course works
Short lessons
47 lessons across 8 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
