By the end
What you'll build
- Identify personal data and special-category data in the records you handle day to day
- Explain in plain language why a given piece of processing needs a purpose and a lawful basis
- Apply data minimisation and retention thinking to a routine task such as a report, an export or a mailing list
- Recognise when an activity crosses a border or a regional overlay and needs specialist input
- Describe the individual rights people commonly hold over their data and where to route a request
Curriculum
What's inside
8 modules · 50 lessons
- 01
What personal data actually is
6 lessons- Personal data, pseudonymised data and anonymous data: telling them apart in real records
- Identifiers, quasi-identifiers and the re-identification problem
- Special-category and sensitive data: why it is treated differently
- Walkthrough: classifying the fields in a customer record
- Where personal data hides: logs, backups, screenshots and shared drives
- + 1 more lesson
- 02
Why the rules exist
6 lessons- From harm to rule: the real-world damage privacy law is trying to prevent
- A short history of data protection thinking
- Privacy as a human interest, not just a compliance cost
- How privacy, security and confidentiality differ
- Reputational and operational consequences of getting it wrong
- + 1 more lesson
- 03
The principles you work to
7 lessons- Purpose limitation in practice: the question to ask before you collect anything
- Lawfulness, fairness and transparency in everyday wording
- Data minimisation: collecting less on purpose
- Accuracy and keeping records current
- Storage limitation and why retention schedules exist
- + 2 more lessons
- 04
Lawful bases and consent
7 lessons- Consent is not the default: choosing an appropriate basis for processing
- The common lawful bases and what each one demands
- What makes consent genuine: freely given, specific, informed, withdrawable
- Legitimate interests and the balancing thinking behind it
- Contract and legal obligation as bases
- + 2 more lessons
- 05
People's rights over their data
6 lessons- The rights map: access, correction, erasure, objection, portability and restriction
- How a request usually reaches an organisation
- Your role: recognise, log, escalate — not decide
- Timelines and why speed matters
- Common traps: verbal requests, social-channel requests, third-party requests
- + 1 more lesson
- 06
Regional overlays without the jargon
6 lessons- Same activity, different rules: how location changes your obligations
- Where the people are, not where the server is
- Cross-border transfers in one page
- Sector overlays: health, finance, children, employment
- How to find out which rules apply to a project
- + 1 more lesson
- 07
Privacy in your working day
7 lessons- Ten desk habits that reduce the most common privacy incidents
- Email, attachments and the reply-all problem
- Screen sharing, screenshots and demo data
- Shadow copies: personal drives, notes apps and spreadsheets
- Talking about people's data in open spaces and on calls
- + 2 more lessons
- 08
Practice and check
5 lessons- What people say, and the right they are usingmatch pairs
- Before you add one more question to a formsequence order
- Getting the basics exactly rightfill blank
- The message in the shared inboxscenario
- Course quizquiz
The shape of it
How this course works
Short lessons
50 lessons across 8 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
