Course Outline
Understanding the GDPR
- Defining personal and sensitive data
- Assembling your project team
- Clarifying key GDPR terminology
- Implementing privacy by design and privacy by default
Establishing a Team Structure
- Selecting personnel to support GDPR initiatives (legal, marketing, IT, HR)
- Identifying the need for a Data Protection Officer (DPO)
Access Permissions and Controls
- Determining what constitutes personal data
- Defining who has access to data
- Managing data storage methods, whether electronic or paper-based
- Ensuring data security
Rights and Obligations
- Understanding the rights of Data Subjects
- Outlining the Controller’s obligations
- Defining the Processor’s obligations
- Managing data subject requests
- Navigating international data transfers
- Identifying what constitutes a data breach
- Reviewing potential fines and penalties
- Evaluating third-party services
- Addressing cross-border data transfers
Formulating Policies and Procedures (Legal Considerations)
- Drafting data privacy policies for employees and clients
- Documenting the legal basis for data processing
- Establishing codes of conduct for data collection and handling
- Reviewing third-party contracts with external suppliers
Ongoing Maintenance
- Regularly updating data to ensure accuracy
- Revising privacy notices and procedures in response to GDPR updates
- Amending contracts as necessary
Requirements
No specific prerequisites are required to participate in this course.
Testimonials (3)
The variety of the information shared and the clarity to explain terms in plain English.
Arisbe Mendoza - Fairtrade International
Course - GDPR Workshop
The training was very informative and relevant to the realities of what we are dealing with. It was very eye-opening to understand how to deal with data of UE residents. The trainer was very informed and prepared on the subject.
Isaac Rewa - Fairtrade International
Course - GDPR Workshop
I generally enjoyed the knowledge of the trainer.