close

close

Thank you for your enquiry!

One of our training experts will be in touch shortly to go over your training requirements.

close

close

Press esc to close

close close

Back to course information

Thank you for your enquiry!

One of our training experts will be in touch shortly to go overy your training requirements.

close close

Thank you for your enquiry!

One of our training experts will be in touch shortly to go over your training requirements.

GDPR Training

Online Instructor-led (4 days)

Classroom (4 days)

Online Self-paced (32 hours)

Official EU General Data Protection Regulation (EU GDPR) Foundation Exam

General Data Protection Regulation Course Outline

This GDPR Foundation & Practitioner course covers the following topics:

GDPR Foundation

This 2-day General Data Protection Regulation (GDPR) Foundation course provides a complete introduction to the EU GDPR and an overview of the key implementation and compliance activities.

  • Introduction to the GDPR
  • Key GDPR terminology
  • An introduction to the GDPR’s structure - the legal articles and recitals
  • Main differences between the Data Protection Act and the EU GDPR
  • Principles of the GDPR
  • Key roles and features of the GDPR
  • The rights of Data subjects
  • Lawful processing of personal data
  • Subject access requests and how to deal with them
  • Complying with the EU GDPR
  • Privacy by design
  • Binding Corporate Rules
  • Data protection impact assessments (DPIA)
  • Breach reporting and responses
  • The role of the DPO

GDPR Practitioner

The 2-day General Data Protection Regulation (GDPR) Practitioner course enables delegates to fulfil the role of data protection officer (DPO) under the EU GDPR and covers the Regulation in depth. This includes implementation requirements and the necessary policies and processes, in addition to acquiring knowledge concerning important elements of effective data security management. This GDPR Practitioner course covers the following topics:

  • Demonstrating compliance with the GDPR
  • Planning for compliance - privacy compliance frameworks and gap analysis
  • Legal requirements of the GDPR
  • Lawful Processing - rights and consent
  • Data Processing for Marketing purposes
  • Subject Access Requests
  • Common data security failures, consequences, and lessons to be learnt
  • Privacy principles in the GDPR
  • Data Protection Impact Assessments
  • Personal Information Management Systems (PIMS)
  • Data Breach reporting requirements
  • Dealing with third parties and data in the Cloud
  • International transfers & the EU-US Privacy Shield
  • Practical Implications of GDPR
  • Notification Obligations
  • Protecting personally identifiable information
  • Penalties for non-compliance
  • The rights of data subjects
  • Data controllers and processors - roles and responsibilities

Show moredown

Who Should Attend this GDPR Training Course?

This GDPR Foundation and Practitioner course is intended for:

  • Information Security Professionals
  • Compliance Officers
  • Data Protection Officers
  • Risk Managers
  • Privacy Managers
  • IT Security Professionals

Prerequisites

There are no pre-set formal qualifications required prior to sitting this course - it is designed for individuals looking to enhance their knowledge of GDPR and implement a compliance programme within their business.

General Data Protection Regulation Course Overview

This 4-day EU General Data Protection Regulation (GDPR) training course provides a detailed introduction to the EU GDPR, and a full overview regarding how to plan and implement a continuous compliance programme. It enables delegates to fulfil the knowledge requirements of a Data Protection Officer (DPO) – a position that is now a legal requirement in EU Organisations with a central data storage and processing function. The Knowledge Academy's GDPR course consists of the EU GDPR Foundation (two days) and GDPR Practitioner (two days) training courses.

The EU General Data Protection Regulation (GDPR) is a new directive that provides a singular data protection law for the European Union - creating a reference and basis upon which security platforms can be initiated, to prevent the loss of Personally Identifiable Information (PII) as a consequence of security breaches. The GDPR will enforce stringent data protection requirements for all organisations that possess or process PII, and/or monitor the behaviour of EU citizens. Noncompliance with the directive can and already has resulted in organisations facing substantial and financially catastrophic fines of up to 4% of their global turnover or €20 million, depending on the severity of the breach and the deemed “tier” of the offence.

The GDPR replaces the Data Protection Act and ensures that data protection laws are up to date with the “internet age” and are responsive to the ever-elevating threat of security breaches and cyber-attacks. The GPDR is prescriptive and is intended to help reassure European citizens that their personal data is safe - enhancing their confidence and interaction with online services. The regulation puts the security of EU citizens at the forefront of all processing activities - including granting individuals new legal rights concerning access and data erasure and holding organisations accountable for any obligations that they fail to adhere to. The UK is also subject to a latest version of the Data Protection Act, the DPA 2018, which complements the GDPR and features additional structures for data processing in law enforcement. The Knowledge Academy also offers a course on Law Enforcement Processing under the new DPA. For both laws, it is imperative that individuals involved in, and responsible for, data protection and processing, have a comprehensive appreciation for the meticulous details of the GDPR - obtained through undertaking this all-inclusive GDPR Foundation and Practitioner course.

The Role of a Data Protection Officer

This EU General Data Protection Regulation (GDPR) training course will guide you through the actions and responsibilities of a Data Protection Officer so you can be expertly prepared to demonstrate full compliance with the GDPR. The newly qualified GDPR DPO can be a current staff member or a contractor, however, the role must be designated based on professional qualities, and expert knowledge of data protection laws. DPOs must adhere to the GDPR requirements, as listed in Article 39:

  • Inform and advise the controller or the processor and the employees who are processing personal data of their obligations pursuant to this Regulation
  • Monitor compliance with this Regulation, including the assignment of responsibilities, awareness-raising, and training of staff involved in the processing operations, and the related audits
  • Provide advice where requested regarding the data protection impact assessment and monitor its performance pursuant to Article 35
  • Cooperate with the supervisory authority (the ICO)
  • Act as the contact point for the supervisory authority on issues related to the processing of personal data

Show moredown

What's included in this EU GDPR Training Course?

The following is included in our GDPR Foundation & Practitioner training course:

  • The GDPR Foundation examination
  • The GDPR Practitioner examination
  • The Knowledge Academy GDPR Foundation and Practitioner Manual
  • Certificate
  • Experienced GDPR instructor
  • Refreshments 

 

Show moredown

EU GDPR Foundation Exam Information

The GDPR Foundation exam tests a candidate's knowledge of the principles of GDPR, subject rights, and the underpinning background of the GDPR. The exam consists of:

  • Type: Multiple choice questions
  • Duration: 60 minutes
  • Pass mark: 65%
  • Open Book: No

EU GDPR Practitioner Exam Information

The GDPR Practitioner exam assesses a candidate’s knowledge of compliance mechanisms, cloud and third-party processing, the stipulations of the GDPR, Data Protection Impact Assessments, security breaches, and the expectations of GDPR-mandated roles. The exam consists of:

  • Type: Multiple choice questions
  • Duration: 1 hour 30 minutes
  • Pass mark: 55%
  • Open Book: Yes

Show moredown

Online Instructor-led (1 days)

Classroom (1 days)

Online Self-paced (8 hours)

Certified Data Protection Officer Exam

Certified Data Protection Officer (CDPO) Course Outline

This CDPO training course will explore the following areas:

An Introduction

  • Introducing Data Protection
  • Why is Data Protection required?
  • Key Data Protection Approaches
  • Data Protection Regulations

The Role of a Data Protection Officer

  • Working with Personal Data
  • Processing Personal Data
  • The Rights of the Subject
  • Encountering Challenges

The Security Context

  • Data Breaches
  • Incident Response Plans
  • The Supervisory Authority
  • Recovering from Incidents
  • Recording Incidents

Performing a Personal Data Audit

  • What is a Personal Data Audit?
  • The DPO’s Role
  • Collecting PII
  • Securing Personal Data

Conducting a Data Protection Impact Assessment (DPIA)

  • What is a DPIA?
  • When are DPIAs required?
  • DPIAs and the DPO
  • DPIAs through the Life Cycle

Show moredown

Who should attend this Data Protection Training Course?

This certification is designed for anyone involved in a role whereby the processing of personal information is performed, or anyone looking to understand the role of a Data Protection Officer. Therefore, those within the following positions may benefit from this CDPO training course:

  • Data Protection Officers (Current and Aspiring)
  • Data Protection Professionals and Personnel
  • Information Officers
  • Compliance Officers
  • Human Resources Managers

Prerequisites

There are no formal prerequisites, but having some prior GDPR knowledge is recommended.

Certified Data Protection Officer (CDPO) Course Overview

On May 25th 2018, the General Data Protection Regulation came into force in European law. Consequently, most organisations within the public and private spheres are now legally required to appoint a Data Protection Officer, who is liable for activities such as tracking compliance, performing internal audits, and directing Data Protection tasks. The few businesses that are exempt from this provision are still likely to appoint DPOs, as they would find it expedient.

The penalties for breaching the GDPR can be and have already proven to be very severe, with fines up of to 20 million or 4% of an organisation's annual global turnover from the previous financial year. The appointment of a DPO is now crucial, as fines could become more severe the longer an organisation demonstrates noncompliance. Such serious punishments work as an incentive to appoint and resource the role of a Data Protection Officer. In order to comply with the GDPR, the DPO must fulfill specific responsibilities and possess a well-defined skill set. Therefore, our Certified Data Protection Officer training course will provide delegates with a thorough understanding of the role played by a DPO.

To begin, this course will ensure delegates attain an embedded knowledge of the principles of Data Protection. The term Data Protection will be defined, and Data Protection legislation will be acknowledged. Following this, a detailed exploration of the role of the Data Protection Officer will occur. During this section, the duty of processing personal data will be covered, and the rights of data subjects will be investigated. The challenges DPOs may encounter will also be an area of interest.

Furthermore, the DPO’s role regarding data breaches, incident response, and incident recovery is analysed. Likewise, the Data Protection Officer’s position in terms of Personal Data Audits and Data Protection Impact Assessments (or DPIAs) is thoroughly examined.

Show moredown

What’s Included in this Data Protection Training Course?

  • The Certified Data Protection Officer (CDPO) Examination
  • The Knowledge Academy’s CDPO Courseware Folder
  • A Completion Certificate
  • Experienced CDPO Instructor
  • Refreshments

Show moredown

Certified Data Protection Officer (CDPO) Training Exam

Total Marks – 40

Question Type Multiple Choice

Number of Questions – 40

Duration – 60 Minutes

Pass Marks – 26/40

Open Book – No

Show moredown

Online Instructor-led (2 days)

Classroom (2 days)

Online Self-paced (16 hours)

Official EU General Data Protection Regulation (EU GDPR) Foundation Exam

GDPR Foundation Course Outline

This 2-day General Data Protection Regulation (GDPR) Foundation course provides a comprehensive introduction to the EU GDPR and an overview of the key implementation and compliance activities required now that the GDPR is legally enforceable. This GDPR Foundation course covers the following topics:

  • Introduction to the GDPR
  • Key GDPR terminology
  • An introduction to the GDPR’s structure - the legal articles and recitals
  • Main differences between the Data Protection Act and the EU GDPR
  • Principles of the GDPR
  • Key roles and features of the GDPR
  • The rights of Data subjects
  • Lawful processing of personal data
  • Subject access requests and how to deal with them
  • Complying with the EU GDPR
  • Privacy by design
  • Binding Corporate Rules
  • Data protection impact assessments (DPIA)
  • Breach reporting and responses
  • The role of the DPO

Show moredown

Who should attend this GDPR Training Course?

This course is designed for individuals looking to elevate their knowledge of the GDPR. Individuals that would benefit from undertaking this course include:

  • Information Security Professionals
  • Compliance Officers
  • Data Protection Officers
  • Risk Managers
  • Privacy Managers
  • IT Security Professionals

Prerequisites

There are no prerequisites for this course – it is open to all individuals interested in enhancing their knowledge of the GDPR

GDPR Foundation Course Overview

This 2-day EU General Data Protection Regulation (GDPR) training course provides a comprehensive introduction to the GDPR’s structure, context terminology, and compliance mechanisms. Candidates will learn how to plan a continuous and longitudinal compliance programme, whilst appreciating the multifaceted role of a Data Protection Officer (DPO), Data Controller, and Data Processor under the GDPR.

The GDPR came into effect May 25th 2018 and stipulates that organisations that process, monitor, and store data belonging to EU citizens, must alter their marketing, system, and processing methods drastically to ensure the safety of data against cyber attacks and breaches. Hence, this course delineates the alterations required of an organisation by the GDPR in order to make their systems more functional and fully compliant. Candidates will learn to appreciate the necessity of the GDPR as a response to the development of technology and the proliferation of malicious cyber-attacks; in addition to developing their awareness of non-compliance fines: up to 4% of the previous year’s global turnover or €20 million, depending on the severity of the breach and the deemed offence “tier”.

The implementation of the prescriptive General Data Protection Regulation is an intentional step towards a much-needed unified data protection law across the European Union. The GDPR will elevate trust of citizens when interacting with online services, hence this course has a number of benefits for marketing and security-based organisations, as individuals will learn how to legally and optimally interact with their users.

The regulation puts the security of EU citizens at the forefront of all processing activities - including granting individuals new rights concerning access, portability, and data erasure, whilst holding organisations accountable for failing to adhere with the compliance requirements. Therefore, it is imperative that individuals responsible for data protection, storage, and processing, develop a comprehensive appreciation for the meticulous details of the impending GDPR - which can be obtained by undertaking this introductory, but extensive GDPR Foundation course.

Show moredown

What's included in this GDPR Training Course?

This GDPR Foundation course includes:

  • The GDPR Foundation exam
  • The Knowledge Academy GDPR Foundation Manual
  • Certificate
  • Experienced Instructor
  • Refreshments

Show moredown

EU GDPR Foundation Exam Information

The GDPR Foundation exam tests a candidate's knowledge of the principles of GDPR, subject rights, and the underpinning background of the GDPR. The exam consists of:

  • Type: Multiple choice questions
  • Duration: 60 minutes
  • Pass mark: 65%
  • Open Book: No

Show moredown

Online Instructor-led (2 days)

Classroom (2 days)

Online Self-paced (16 hours)

Official EU General Data Protection Regulation (EU GDPR) Practitioner Exam

GDPR Practitioner Course Outline

Module 1: Data Subject Rights

  • Rights of the Data Subject
  • Must I Always Obey a Right?
  • Rights and Third Parties
  • Requests Made on Behalf of Other Data Subjects
  • Guidelines for Children's Maturity
  • Responding to a Rights Request
  • What is a Month?
  • Rights Request Flow Chart
  • Right to Be Informed
  • Best Practice Guidance
  • Right of Access
  • Right to Rectification
  • Right to Erasure
  • When Can I Refuse to Comply with a Request for Erasure?
  • Erasing Children's Data
  • Right to Restrict Processing
  • When Processing Should be Restricted?
  • Protecting PII
  • Issues about Restricting Processing
  • Right to Data Portability
  • Right to Object
  • Complying with the Right to Object
  • Rejecting the Right to Object
  • Right to Object
  • Rights Related to Automated Decision Making and Profiling
  • When Does the Right Not Apply?

Module 2: Subject Access Requests

  • Provenance
  • SARs
  • SAR is an Activity, not a Title
  • How Can a SAR be submitted?
  • What Information Should the Response to a SAR Contain?
  • Replying to a SAR
  • Confirming a Data Subject’s Identity
  • Scope
  • Electronic Records
  • Non-Electronic Records
  • SARs involving 3rd Party PII
  • Fees
  • Refusing a Subject Access Request
  • Access Requests from Employees
  • Credit Reference Agencies
  • Best Practice for SARs

Module 3: Lawful Processing

  • Lawful Processing
  • User Rights Change Depending on the Justification
  • Lawfulness of Processing Conditions
  • Lawfulness for Special Categories of Data
  • Consent
  • Specific
  • Informed
  • Key Points about Consent
  • Affirmative Action and Explicit Consent
  • What is not Affirmative Action?
  • Explicit Consent
  • Explicit Statement
  • Obtaining Explicit Consent
  • ICOs View of a Poor Form of Explicit Consent
  • Obtaining Consent for Scientific Research Purposes
  • Getting Consent
  • What should go into the Consent Request?
  • Consent Granularity
  • Right to Withdraw Consent
  • Children
  • Consent Records
  • Key Points When Establishing Consent
  • Legitimate Interests
  • Getting the Balance Right
  • Consent or Legitimate Interest?
  • What Lawful Basis Can Be Used for Processing Marketing PII?

Module 4: Third-Country Data Transfers

  • Cross Border Transfers
  • Transfer Mechanisms
  • Derogations
  • Adequacy
  • Adequate Ways to Safeguard Transfers of PII
  • One-Off or Infrequent Transfers
  • Who is Responsible?
  • Transferring PII Between EEA Members
  • Adequate Countries Outside of the EEA
  • Binding Corporate Rules (BCR)
  • What a BCR Must Cover?
  • Authorisation for BCRs
  • Privacy Shield Overview
  • Model Clauses
  • Public Authority Agreements

Module 5: Introduction to Protecting Personal Data

  • Need to Secure
  • What is Appropriate?
  • Protecting PII
  • Coverage
  • Defensive Design
  • Single Point of Failure (SPOF)
  • Incident Response
  • Data Breach Reporting Requirements
  • Incident Response Team

Module 6: Data Protection Impact Assessments (DPIA)

  • Data Protection Impact Assessments Overview
  • What Triggers a Data Protection Impact Assessment?
  • Benefits of DPIA
  • Processes to Be Considered for a DPIA
  • Responsibilities
  • DPIA Decision Path
  • DPIA Content
  • How Do I Conduct a DPIA?
  • Signing Off the DPIA
  • Mitigating Risks Identified By the DPIA

Module 7: Need Want Drop

  • Need to Want Drop Overview
  • Concept Diagram
  • Need/Want/Drop Methodology

Module 8: Dealing with Third Parties and Data in the Cloud

  • What is Cloud Computing?
  • Myths of Cloud
  • Cloud Challenges
  • Controller-Processor Contract
  • Checklist
  • Data Controller

Module 9: Practical Implications: GDPR

  • Brexit and Its Impact on the GDPR
  • One-Stop Shop

Module 10: Legal Requirements of the GDPR

  • Legal Requirements of the GDPR Overview

Module 11: Privacy Principles in GDPR

  • Principles found in Article 5(1) GDPR

Module 12: Common Data Security Failures, Consequences, and Lessons to be Learnt

  • Common Data Security Failures
  • Consequences
  • Lesson Learned

Show moredown

Who Should Attend this GDPR Training Course?

Prerequisites

There are no formal prerequisites for attending this EU General Data Protection Regulation Practitioner Training course.

Audience

The EU General Data Protection Regulation (GDPR) Practitioner Training is designed for a range of professionals who handle personal data.

GDPR Practitioner Course Overview

EU General Data Protection Regulation (GDPR) is a comprehensive legislative framework that governs the processing of personal data in the European Union. It is important to implement technical and organisational measures to ensure data protection. Studying this training provides individuals with the knowledge and abilities required to guarantee that their organisations are in compliance with GDPR requirements. This training helps learners understand the importance of evaluating GDPR compliance and implementing changes to ensure ongoing compliance. Pursuing this training helps individuals get equipped with the necessary skills and techniques to enhance their career opportunities and ultimately increase their earnings.

In this 2-day EU General Data Protection Regulation Practitioner Training course, delegates will gain comprehensive knowledge about how to handle personal data in the European Union. During this training, delegates will learn to stay up-to-date with changes to GDPR requirements and adapt policies and procedures as needed. They will also learn about GDPR and develop the skills needed to ensure compliance within their organisations. The Knowledge Academy’s highly professional and knowledgeable tutor, who has years of teaching experience, will conduct this training. 

Course Objectives

  • To understand the rights of data subjects and how to handle their requests
  • To learn how to conduct a Data Protection Impact Assessment (DPIA)
  • To develop and implement effective data protection policies and procedures
  • To know the importance of continuous improvement in GDPR compliance
  • To gain knowledge of how to handle data subject requests and complaints
  • To provide a clear explanation of why and how you are processing AI

At the end of this training course, delegates will be able to develop and implement effective data protection policies. They will also be able to identify and assess the risks associated with the processing of personal data.

Show moredown

What's included in this GDPR Training Course?

Our GDPR Practitioner course includes:

  • The GDPR Practitioner exam
  • The Knowledge Academy GDPR Practitioner Manual
  • Certificate
  • Expert Instructor
  • Refreshments

Show moredown

EU GDPR Practitioner Exam Information

The GDPR Practitioner exam assesses a candidate’s knowledge of compliance mechanisms, cloud and third-party processing, the stipulations of the GDPR, Data Protection Impact Assessments, security breaches, and the expectations of GDPR-mandated roles. The exam consists of:

  • Type: Multiple choice questions
  • Duration: 1 hour 30 minutes
  • Pass mark: 55%
  • Open Book: Yes

Show moredown

Online Instructor-led (1 days)

Classroom (1 days)

Online Self-paced (8 hours)

EU General Data Protection Regulation Awareness Outline

This GDPR awareness course covers the following topics:

  • What is the GDPR?
  • Introduction to the GDPR
  • Key GDPR terminology
  • The GDPR’s structure - the articles and recitals
  • Differences between the Data Protection Act and the EU GDPR
  • Principles of the GDPR
  • Key roles and features of the GDPR
  • The rights of Data Subjects
  • Subject access requests and how to deal with them
  • Complying with the EU GDPR
  • Data protection impact assessments (DPIA)
  • Breach reporting and responses

Show moredown

Who Should Attend the GDPR Awareness Course?

This course is recommended for anybody who wishes to gain an understanding of GDPR. This could include but is not limited to:

  • Information security professionals
  • Compliance officers
  • Risk Managers
  • Privacy managers
  • IT security professionals
  • Senior staff
  • Managers and Directors

Prerequisites

The course is open to everyone and there are no formal prerequisites.

EU General Data Protection Regulation Awareness Overview

This 1-day GDPR Awareness course provides an introduction to the GDPR’s terminology and purpose. Candidates will learn how to appreciate the necessity of complying with the GDPR - ensuring that personal data is secure and that your organisation does not face a catastrophic fine of up to 20 million Euros or 4% of your annual global turnover. The multifaceted nature of the GDPR means that organisations need to have their systems reviewed and enhanced - which requires a number of individuals with specialist hard-skills. Hence, this course offers an introduction to the GDPR and enables candidates to enhance their knowledge of what their role will be in maintaining a programme of compliance.

Since it came into force on May 25th 2018, the GDPR has helped unify data protection methods across the European Union  - ensuring that organisations that process, store, or monitor data are taking preventative steps to safeguard data belonging to EU citizens. The ever-growing threat of data breaches and cyber attacks means that organisations must develop stringent systems-based operations, to ensure the safety of personal data - hence this course will educate candidates of the fundamental principles, articles, and regulations that underpin the GDPR as legislation.

The regulation places citizens at the forefront of data processing and in control of their own data with new rights. Consequently, the regulation has had large repercussions for organisations involved in marketing, cloud optimisation, and data storage - it is now essential that they obtain new consent from clients for data collection, set up legal contracts, and abolish their utilisation of unstable storage mechanisms. Therefore, this GDPR training course helps explain the requirements of the GDPR for organisations and teaches candidates about how the GDPR will affect them.

Show moredown

What's included in this GDPR Training Course?

The GDPR Awareness course includes:

  • The Knowledge Academy GDPR Awareness Manual
  • Certificate
  • Experienced GDPR Instructor
  • Refreshments

Show moredown

Online Instructor-led (1 days)

Classroom (1 days)

Online Self-paced (8 hours)

Dealing with Subject Access Requests (SAR) Course Outline

This Dealing with SARs course is designed to give delegates a specific, in-depth understanding of Subject Access Requests and Data Subjects’ Right of Access under GDPR legislation. The topics covered on the course include:

  • Introduction
    • The GDPR
    • The 8 Rights of Data Subjects
  • Recognising Subject Access Requests
    • What is a SAR?
    • SAR parameters
    • SAR formats
    • Requests on behalf of others
    • Verifying identity
    • Requests on behalf of children
    • Recording SARs
  • Responding to Subject Access Requests
    • What information is needed?
    • How should we provide it?
    • Fees
    • Timeframes
  • Extenuating Circumstances
    • Extending the response time
    • Refusing to comply
    • Special category data
  • Further Considerations
    • Fines
    • Changes from the Data Protection Act (1998)
    • The role of the Supervisory Authority

Show moredown

Who should attend this Data Protection Training Course?

This Dealing with SARs course is suitable for all delegates who wish to learn more about GDPR, specifically, those in customer- or client-facing roles where communicating with third parties is a common occurrence. This course may be particularly suited to Data Protection Officers (DPOs) who want to increase their GDPR knowledge base or organisations wishing to appoint a DPO. Examples of appropriate roles include but are not limited to:

  • Information security professionals
  • Compliance officers
  • Risk managers
  • Privacy managers
  • Senior staff

However, delegates in higher-level or executive roles may prefer our course Subject Access Requests: An Executive Briefing [link], which is tailored to C-level and upper management executives.

Prerequisites

There are no formal prerequisites for taking this course, meaning that anyone who wishes to gain a deeper understanding of SARs is welcome to attend.

Dealing with Subject Access Requests (SAR)​ Course Overview

This focused, 1-day course on Dealing with SARs, delivered by our experienced and knowledgeable trainers, is designed to give delegates a comprehensive, step-by-step understanding of how to respond to Subject Access Requests under the new General Data Protection Regulation legislation that came into force on May 25th 2018.

Knowledge of how to respond to Subject Access Requests, or SARs, is essential not just in enhancing customer relationships but also in guaranteeing that your organisation does not incur a fine of up to 20 million Euros (or 4% of your annual global turnover) for contravening the GDPR. Fortunately, with thousands of clients already trained in GDPR best practice, The Knowledge Academy provides outstanding and detailed tuition that has helped organisations around the world implement effective GDPR compliance.

This course will ensure that delegates are equipped to handle SARs in line with GDPR, covering crucial topics such as how to recognise, record, and respond to SARs, the timeframes in which you a response is required, and changes from previous legislation. Successfully completing this course will prove to employers and clients alike that delegates are trained in the appropriate procedure for responding to SARs, empowering them to comply with GDPR and enhance relationships with Data Subjects.

Show moredown

What’s Included in this Data Protection Training Course?

This Dealing with SARs course includes:

  • The Knowledge Academy’s Dealing with SARs Manual
  • Certificate of Completion
  • Tuition from an experienced GDPR instructor
  • Refreshments

Show moredown

Online Instructor-led (1 days)

Classroom (1 days)

Online Self-paced (8 hours)

Data Protection Act (DPA 2018) Course Outline

  • The Six Data Protection Principles
  • The DPA’s Alignment with GDPR
  • Conditions for Sensitive Processing
  • Safeguards for Sensitive Processing
  • Individual Rights Under the DPA 2018
  • Documenting and Logging Data
  • Categorising Individuals and Retaining Personal Data
  • Appointing a Data Protection Officer
  • Reporting and Responding to Data Breaches
  • International Data Transfers and Relevant Authorities

Show moredown

Who should attend this Data Protection Training Course?

As it deals with the Law Enforcement Processing section of the new Data Protection Act 2018, this course will be most helpful to individuals working in any form of law enforcement, or law enforcement organisations wishing to learn how to demonstrate compliance with the Act. However, those involved with the law in other capacities (e.g. solicitors) will also find this course helpful. For individuals wishing to learn about data protection and legislation without a specific focus on law enforcement, The Knowledge Academy is pleased to offer a wide range of GDPR training courses that have already proven useful to thousands of clients across a large variety of sectors.

Prerequisites

There are no formal prerequisites for attending this Law Enforcement Processing course, meaning that any individual with a relevant interest is welcome to attend.

Data Protection Act (DPA 2018) Course Overview

This focused one-day course on Law Enforcement Processing under the Data Protection Act 2018 covers the key points of Part 3 of the Act, teaching delegates how to demonstrate full and expansive compliance within their organisations. The course is intended to give delegates full theoretical knowledge of the Act so that they will be able to implement its requirements practically.

To this end, the course covers the whole scope of the new Law Enforcement Processing requirements, from the six basic data protection principles to the specifics of transferring data internationally for law enforcement purposes. As the new Data Protection Act is designed to complement and integrate with the EU General Data Protection Regulation, this course will also cover the key points at which the Act aligns with GDPR (in relation to law enforcement) as well as the points at which it diverges.

The implementation of the new Data Protection Act may mandate some changes to the current structure and operation of law enforcement agencies, such as the requirement to appoint a Data Protection Officer, but is ultimately designed to help law enforcement agencies become safer and more secure. By taking this course with The Knowledge Academy, delegates can rest assured that our expert trainers will be able to guide them through the Act’s complexities so that their agencies can fully realise the benefits of enhanced data protection.

Show moredown

What’s Included in this Data Protection Training Course?

This Law Enforcement Processing course includes:

  • The Knowledge Academy’s Law Enforcement Processing (DPA 2018) Manual
  • Certificate of Completion
  • Tuition from an experienced instructor
  • Refreshments

Show moredown

Online Instructor-led (2 days)

Classroom (2 days)

Online Self-paced (16 hours)

Dealing with Subject Access Requests (SAR) - An Executive Briefing Course Outline

This Dealing with SARs: An Executive Briefing course is designed to give delegates an understanding of how SARs work and how best for organisations to handle them under GDPR. The topics covered on this course include:

  • Recognising SARs
    • Defining Data Subjects
    • Data Subjects’ Rights
    • Purpose of an SAR
    • Employee SARs vs Customer SARs
    • What is an SAR?
    • Complying with an SAR
    • SAR parameters
  • Recording SARs
    • SAR formats
    • Verifying identity
    • Handling customer SARs
    • Handling internal SARs
    • Requests on behalf of others
  • Responding to SARs
    • What information is needed?
    • How should we provide it?
    • Fees
    • Timeframes
    • Extending the response time
  • Refusing SARs
    • Special category data
    • Unfounded or excessive requests
    • Fines

Show moredown

Who should attend this Data Protection Training Course?

This Dealing with SARs: An Executive Briefing course is designed for delegates at high-level positions who wish to learn about SARs in a short period of time. It is also suitable for individuals who wish to gain an understanding of the key points associated with SARs, although The Knowledge Academy runs a dedicated Dealing with SARs course, which we recommend for delegates who are not at the executive level or who may be handling SARs themselves.

Prerequisites

There are no formal prerequisites for taking this course, meaning that any individuals who wish to learn about Subject Access Requests may attend.

Dealing with Subject Access Requests (SAR) - An Executive Briefing Course Overview

This succinct and precise course on Dealing with SARs is intended to imbue executive delegates with an understanding of how to respond to Subject Access Requests under the new GDPR legislation that came into force on May 25th 2018.

Understanding how and when to respond to SARs is crucial for maintaining positive relationships with customers and even employees. In addition, knowledge of SARs and appropriate response procedures is essential in guaranteeing that your organisation does not incur a fine of up to 20 million Euros (or 4% of your annual global turnover) for contravening the GDPR. Fortunately, with thousands of clients already trained in GDPR best practice, The Knowledge Academy provides outstanding and detailed tuition that has helped organisations around the world implement effective GDPR compliance.

This course is designed to teach delegates how to recognise, record, and respond to SARs in line with GDPR. This course will also instruct delegates on the appropriate procedures and timeframes for responding to SARs, empowering them to demonstrate GDPR compliance and put customers first.

Subject Access Requests can come from any individual on whom your organisation holds data; these people are known as Data Subjects, and can be employees as well as customers. This course will help you to identify who should be considered a Data Subject, the basic rights of every Data Subject, and how to recognise and respond appropriately to SARs dependant on their origin. The course also explains the extenuating circumstances that may allow you to refuse an SAR. Finally, we will cover the penalties that can be imposed by Supervisory Authorities for not responding—and ensure that your organisation is not subject to them.

Show moredown

What’s Included in this Data Protection Training Course?

This Dealing with SARs: An Executive Briefing course includes:

  • The Knowledge Academy’s Dealing with SARs: An Executive Briefing Manual
  • Certificate of Completion
  • Tuition from one of our knowledgeable GDPR instructors
  • Refreshments

Show moredown

Online Instructor-led (1 days)

Classroom (1 days)

Online Self-paced (8 hours)

Personal Data Protection Bill Training​ Course Outline

Module 1: Introduction to Personal Data Protection Bill (PDP Bill)

  • What is PDP Bill?
  • Provisions of the Bill
  • What is the Need for the Bill?

Module 2: Obligations of Data Fiduciary

  • Prohibition of Processing of Personal Data
  • Limitation on Purpose of Processing of Personal Data
  • Limitation on Collection of Personal Data
  • Requirement of Notice for Collection or Processing of Personal Data
  • Quality of Personal Data Processed
  • Restriction on Retention of Personal Data
  • Accountability of Data Fiduciary
  • Consent Necessary for Processing of Personal Data

Module 3: Grounds for Processing of Personal Data Without Consent

  • Grounds for Processing of Personal Data Without Consent in Certain Cases
  • Processing of Personal Data Necessary for Purposes Related to Employment Etc.
  • Processing of Personal Data for Other Reasonable Purposes
  • Categorisation of Personal Data as Sensitive Personal Data
  • Processing of Personal Data and Sensitive Personal Data of Children

Module 4: Rights of Data Principal and Transparency and Accountability Measures

  • Right to
    • Confirmation and Access
    • Correction and Erasure
    • Data Portability
    • Be Forgotten
  • Privacy by Design Policy
  • Transparency in Processing of Personal Data
  • Security Safeguards
  • Reporting of Personal Data Breach
  • Classification of Data Fiduciaries as Significant Data Fiduciaries
  • Data Protection Impact Assessment
  • Maintenance of Records
  • Audit of Policies and Conduct of Processing, etc.
  • Data Protection Officer
  • Processing by Entities Other Than Data Fiduciaries
  • Grievance Redressal by Data Fiduciary

Module 5: Restriction on Transfer of Personal Data Outside India and Exemptions

  • Prohibition of Processing of Sensitive Personal Data and Critical Personal Data Outside India
  • Conditions for Transfer of Sensitive Personal Data and Critical Personal Data
  • Power of Central Government to Exempt Any Agency of Government from Application of the Act
  • Exemption of Certain Provisions for Certain Processing of Personal Data
  • Power of Central Government to Exempt Certain Data Processors
  • Exemption for Research, Archiving, or Statistical Purposes
  • Exemption for Manual Processing by Small Entities
  • Sandbox for Encouraging Innovation

Module 6: Data Protection Authority of India

  • Establishment of Authority
  • Composition and Qualifications for Appointment of Members
  • Terms and Conditions of Appointment
  • Removal of Chairperson or Other Members
  • Powers of Chairperson
  • Meetings of Authority
  • Officers and Other Employees of Authority
  • Powers and Functions of Authority
  • Power of Authority to Issue Directions, Call for Information and Conduct Inquiry
  • Action to Be Taken by Authority Pursuant to an Inquiry
  • Search and Seizure
  • Co-Ordination Between Authority and Other Regulators or Authorities

Module 7: Penalties, Compensation, and Appellate Tribunal

  • Penalties for Contravening Certain Provisions of the Act
  • Penalty for Failure to Comply with Data Principal Requests
  • Penalty for Failure to Furnish Report, Returns, Information, etc.
  • Penalty for Failure to Comply with Direction or Order Issued by Authority
  • Penalty for Contravention Where No Separate Penalty Has Been Provided
  • Appointment of Adjudicating Officer
  • Procedure for Adjudication by Adjudicating Officer
  • Compensation
  • Compensation or Penalties Not to Interfere with Other Punishment
  • Recovery of Amounts
  • Establishment of Appellate Tribunal
  • Qualifications, Appointment, Term, Conditions of Service of Members
  • Staff of Appellate Tribunal
  • Distribution of Business Amongst Benches
  • Appeals to Appellate Tribunal
  • Procedure and Powers of Appellate Tribunal
  • Orders Passed by Appellate Tribunal to Be Executable as a Decree
  • Appeal to Supreme Court
  • Right to Legal Representation
  • Civil Court Not to Have Jurisdiction

Module 8: Finance, Accounts, Audit, and Offences

  • Grants by Central Government
  • Data Protection Authority of India Funds
  • Accounts and Audit
  • Furnishing of Returns, etc., to Central Government
  • Re-Identification and Processing of De-Identified Personal Data
  • Offences to Be Cognisable and Non-Bailable
  • Offences by Companies and State 

Show moredown

Prerequisites

There are no formal prerequisites to attend this Personal Data Protection Bill Training course. 

Audience

This Personal Data Protection Bill Training course is ideal for anyone who wants to gain knowledge of the Personal Data Protection Bill.

Personal Data Protection Bill Training​ Course Overview

The Personal Data Protection Bill establishes the regulatory framework required to protect India's personal data. It provides individuals with a protection policy for their personal data. This bill grants the centre broad authority to exempt itself and its agencies from complying with the bill's provisions. Studying Personal Data Protection Bill (PDPB) Training will help learners to effectively know the PDPB framework. It assists organisations to secure their personal data from corruption, compromises, or loss. Pursuing this training will help individuals to gain the required knowledge, skills, and experience to enhance their career prospects.

This 1-day Personal Data Protection Bill Training course covers all necessary concepts to help delegates become thoroughly familiar with the Personal Data Protection Bill. During this training, they will learn about the processing of personal data and the sensitive personal data of children. They will also learn about the accountability of data fiduciary, reporting of a personal data breach, powers and functions of the authority, right to legal representation, grievance redressal by data fiduciary, and many more. Our highly professional trainer with years of experience in teaching such courses will conduct this training course and help delegates to gain a comprehensive understanding of the PDP Bill.

This training will cover various essential topics, such as:   

  • Limitation on a collection of personal data
  • Right to confirmation and access
  • Recovery of amounts
  • Staff of appellate tribunal
  • Appeal to the supreme court
  • Maintenance of records

After attending the Personal Data Protection Bill Training course, delegates will be able to classify data fiduciaries as significant data fiduciaries. They will also be able to maintain the records.

Show moredown

  • Delegate pack consisting of course notes and exercises
  • Manual
  • Experienced Instructor

Show moredown

Online Instructor-led (1 days)

Classroom (1 days)

Online Self-paced (8 hours)

Data Privacy Awareness Course Outline

Module 1: Introduction to Data Privacy

  • What is Data Privacy?
    • Physical Privacy
    • Social Privacy Norms
    • Privacy in a Technology-Driven Society
  • Doctrine of Information Privacy
    • Information Sharing Empowers the Recipient
    • Monetary Value of Individual Privacy
    • Model Data Economy
  • Notice and Choice Versus Privacy as Trust
  • Enforcement of Notice and Choice Privacy Laws
    • Broken Trust and FTC Enforcement
    • Notice and Choice Model Falls Short
  • Privacy as Trust: An Alternative Model
  • Additional Challenges in the Era of Big Data and Social Robots
    • What is a Social Robot?
    • Trust and Privacy
    • Legal Framework for Governing Social Robots
    • General Data Protection Regulation (GDPR)

Module 2: GDPR's Scope of Application

  • When Does GDPR Apply?
    • Processing of Data
    • Personal Data
    • Exempted Activities under GDPR
  • Key Players under GDPR
  • Territorial Scope of GDPR
  • Operation of Public International Law

Module 3: Technical and Organisational Requirements under GDPR

  • Accountability
  • Data Controller
  • Technical and Organisational Measures
  • Duty to Maintain Records of Processing Activities
  • Data Protection Impact Assessments
  • Data Protection Officer
  • Data Protection by Design and Default
  • Data Security During Processing
  • Personal Data Breaches
  • Codes of Conduct and Certifications
  • Data Processor

Module 4: Material Requisites for Processing under GDPR

  • Central Principles of Processing
  • Legal Grounds for Data Processing
  • International Data Transfers
  • Intragroup Processing Privileges
  • Cooperation Obligation on EU Bodies
  • Foreign Law in Conflict with GDPR

Module 5: Data Subjects Rights

  • Controller's Duty of Transparency
  • Digital Miranda Rights
  • Right of Access
  • Right of Rectification
  • Right of Erasure
  • Right of Restriction
  • Right to Data Portability
  • Rights to Automated Decision Making
  • Restrictions on Data Subject Rights

Module 6: GDPR Enforcement

  • In-House Mechanisms
  • Data Subject Representation
  • Supervisory Authorities
  • Judicial Remedies
  • Alternate Dispute Resolution

Module 7: Remedies

  • Allocating Liability
  • Compensation
  • Administrative Fines
  • Processing Injunctions
  • Specific Performance

Module 8: Creating a GDPR Compliance Department

Steps to Create a GDPR Compliance Department

Show moredown

Prerequisites

In this Data Privacy Awareness Training course, there are no formal prerequisites.

Audience

This Data Privacy Awareness is suitable for anyone willing to learn how to protect their data privacy and wants to learn about central principles of processing.

Data Privacy Awareness Course Overview

Data privacy (information privacy) is a part of data security concerned with precise data handling – notice, consent, and regulatory obligations. Data Privacy Awareness is crucial for everyone to make informed decisions about the disclosure of data and manage various possibilities of interruptions throughout their work. Many companies use data protection practices to build clients trust/loyalty with their private data and boost their Return on Investment (ROI). Today, data privacy requirements are growing swiftly as a huge amount of data is being created and stored daily. Professionals holding Data Privacy skills will help them protect their organisational data, which is highly demanded by many multinational companies.

Our 1-day Data Privacy Awareness training course aims to provide delegates with a comprehensive knowledge of data privacy. During this course, delegates will learn about the legal framework for governing social robots, the territorial scope of GDPR, and personal data breaches. Delegates will understand the legal grounds for data processing, data subject rights, supervisory authorities, allocating liability, steps to create a GDPR compliance department, etc. Our highly professional trainer with years of experience in teaching such courses will conduct this training course and will help you get a complete understanding of this course.

This training will also cover the following concepts:

  • Social privacy norms
  • Broken trust and FTC enforcement
  • Trust and privacy
  • Key players under GDPR
  • Data protection officer
  • Foreign law in conflict with GDPR
  • Data subject representation

At the end of this Data Privacy Awareness Training course, delegates will be able to create a GDPR compliance department effectively. They will be able to protect data while processing with the help of data security measures.

 

Show moredown

  • Delegate pack consisting of course notes and exercises
  • Experienced Instructor

Show moredown

Not sure which course to choose?

Speak to a training expert for advice if you are unsure of what course is right for you. Give us a call on 01344203999 or Enquire.

Package deals

Our training experts have compiled a range of course packages to compliment a variety of categories in order to help fast track your career. The packages consist of the best possible qualifications in each industry and allows you to purchase multiple courses at a discounted rate.

Swipe for more. Don’t miss out!

GDPR Training FAQs

FAQ's

GDPR stands for General Data Protection Regulation. The European Union (EU) passed the GDPR rule in May 2018 to bolster and standardise data protection for all EU citizens. The export of personal data outside the EU is also covered.
The GDPR came into effect May 25th 2018. It was initially adopted by the European Parliament on April 14th 2016.
The GDPR applies to all companies that are involved in the processing of data belonging to EU citizens, so it is vital that they can demonstrate full compliance.
DPO is an acronym for Data Protection Officer - a position that is mandatory and must be filled within businesses that have a core data processing operation.
Information that relates to a person who is already identified or can be identified from data such as ID numbers, location, IP address, biometric data, health files, cultural information, or economic data.
Any organisation or business that handles the personal data of persons inside the European Union (EU) is accountable for complying with the General Data Protection Regulation (GDPR).
Our GDPR courses typically cover topics such as the key principles of GDPR, the rights of data subjects, the role of data controllers and processors, data protection impact assessments, data breach reporting, and GDPR enforcement and penalties.
Anyone involved in processing the personal data of persons inside the European Union, including company owners, data protection officials, and staff members in charge of managing data, should take the GDPR course.
Yes, all GDPR courses have the exam fee included within the price and shall be taken on the final day of the relevant course. The GDPR Awareness course does not have any exams as it is purely an information-based course.
The exam(s), a comprehensive candidate pack consisting of exercises, guidance, the GDPR recitals and articles, the course slides, and tuition from a highly engaging instructor.
There are no prerequisites for the GDPR Foundation and Awareness courses. Completion of the GDPR Foundation course fulfils the prerequisites for the GDPR Practitioner course.
Yes, we provide GDPR training course suggestions depending on the learner's level of knowledge and learning objectives. Our website lists suggested courses when you look for GDPR courses based on user ratings, reviews, and relevancy to your search parameters.
Yes, if required, we can provide weekend classes for the GDPR Training course.
Yes, we provide online self-paced training, and online self-paced training lasts 32 hours.
Upon completion of a GDPR training course, you will typically receive a certificate of completion from us, either electronically or by mail, which confirms that you have successfully completed the course.
Our GDPR courses are structured to be accessible to learners with a basic understanding of data protection concepts and laws.
An event's commencement time and location should always be confirmed by consulting our course materials or event registration confirmation. It is preferable to contact the event organiser directly if you have any queries or worries about the event's logistics.
Yes, we offer support for their courses, including GDPR training courses. We provide a Q&A section on each course page where learners can ask questions related to the course, and the instructor or other learners can respond.
The duration of the GDPR course is online instructor-led (4 days), classroom duration for (4 days) and online self-paced 32 hours.
Generally, you should receive a course confirmation email or letter from our side immediately after registering for the course. If you have not received confirmation within a few hours, it's best to contact us.
Obtaining GDPR training can be worthwhile for individuals and organizations that process the personal data of individuals within the European Union. It can provide a better understanding of GDPR requirements, help ensure compliance, and minimize the risk of data breaches and potential fines.
You will have a better knowledge of GDPR's fundamental ideas and obligations after taking a GDPR course. This might assist you in making sure your company complies with the law and prevent possible penalties or legal problems.
Please see our GDPR Training courses available in the United Kingdom
The Knowledge Academy is the Leading global training provider for GDPR Training.
The price for GDPR Training certification in the United Kingdom starts from £.

Why we're the go to training provider for you

icon

Best price in the industry

You won't find better value in the marketplace. If you do find a lower price, we will beat it.

icon

Trusted & Approved

We are accredited by PeopleCert on behalf of AXELOS

icon

Many delivery methods

Flexible delivery methods are available depending on your learning style.

icon

High quality resources

Resources are included for a comprehensive learning experience.

barclays Logo
deloitte Logo
Thames Water Logo

"Really good course and well organised. Trainer was great with a sense of humour - his experience allowed a free flowing course, structured to help you gain as much information & relevant experience whilst helping prepare you for the exam"

Joshua Davies, Thames Water

santander logo
bmw Logo
Google Logo