Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Overview

Course syllabus

Who it’s for

What’s included

Exams

FAQs

Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Course Outline

Module 1: Introduction to GDPR

  • GDPR in a Nutshell
  • Generate Customer Confidence
  • Focus of GDPR
  • What is Personal Information?
  • Who has PII?
  • Lawful Processing of Personal Data

Module 2: GDPR Terminology and Techniques

  • Key Roles
  • Data Set
  • Subject Access Request (SAR)
  • Data Protection Impact Assessments (DPIA)
  • What Triggers a Data Protection Impact Assessment?
  • A DPIA is Not Required in the Following Cases
  • Processes to be Considered for a DPIA
  • Responsibilities
  • DPIA Decision Path
  • DPIA Content
  • How Do I Conduct A DPIA?
  • Signing Off the DPIA
  • Mitigating Risks Identified By the DPIA
  • Privacy by Design and Default
  • External Transfers
  • Profiling
  • Pseudonymisation
  • Principles, User Rights, Obligations
  • One Stop Shop

Module 3: Structure of the Regulation

  • The Parts of the GDPR
  • Format of the Articles
  • Quick Quiz

Module 4: Principles and Rights

  • Introduction
  • Legality Principle
  • How the Permissions Work Together
  • Lawfulness of Processing Conditions
  • Lawfulness for Special Categories of Data
  • Criminal Offence Data
  • Consent
  • Transparency Principle
  • Fairness Principle
  • Rights of Data Subjects
  • Purpose Limitation Principle
  • Minimisation Principle
  • Accuracy Principle
  • Storage Limitation Principle
  • Integrity & Confidentiality Principle

Module 5: Demonstrating Compliance

  • Demonstrating Compliance with the GDPR
  • Impact of Compliance Failure
  • Administrative Fines
  • What Influences the Size of an Administrative Fine?
  • Joint Controllers
  • Processor Liability Under GDPR
  • Demonstrating Compliance
  • Protecting PII is Only Half the Job!
  • What must be Recorded?
  • Additional Ways of Demonstrating Compliance
  • Demonstrating a Robust Process
  • PIMS (Personal Information Management System)
  • Cyber Essentials
  • ISO 27017 Code of Practice for Information Security Controls
  • Risk Management

Module 6: Incident Response & Data Breaches

  • What is a Personal Data Breach?
  • Notification Obligations
  • What Breaches Do I Need to Notify the Relevant Supervisory Authority About?
  • What Information Must Be Provided to the SA?
  • How Do I Report a Breach to the SA?
  • Notifying Data Subjects
  • What Should I do to Prepare for Breach Reporting?
  • Updating Policies and Procedures
  • Breach Reporting and Responses
  • Ways to Minimise the Breach Impact

Module 7: Understanding the Principle Roles

  • What the GDPR Makes Businesses Responsible For?
  • Difference Between a Data Controller and a Data Processor
  • How the Roles Split
  • Controllers and Processors
  • Controllers: Key Points
  • Main Obligations of Data Controllers
  • Demonstrate Compliance
  • Joint Controllers
  • Representative
  • Controller-Processor Contract
  • Maintain Records
  • Keeping Records for Small Businesses
  • Cooperation with Supervisory Authorities
  • Keeping PII Secure
  • Data Breach Transparency
  • Role of the Data Processor
  • Controller-Processor Contract
  • Main Obligations of the Processor
  • Perform Only the Data Processing Defined by the Data Controller
  • Update the Data Controller
  • Sub-Processor Appointment
  • Keep PII Confidential
  • Maintaining Records
  • Cooperate with Supervisory Authorities
  • Security
  • Notify Breaches
  • Appoint a DPO – If Necessary
  • Transferring Data Outside
  • Note: If You Have Staff You Will be a Data Controller
  • Data Processors Key Points

Module 8: The Role of the DPO

  • The Role of a Data Protection Officer
  • Involvement of the DPO
  • Main Responsibilities of the DPO
  • Working Environment for the DPO
  • Must We Have A DPO?
  • Public Body
  • What does Large Scale mean?
  • Systematic Monitoring
  • Who Can Perform the Role of DPO?
  • Skills Required
  • Training and Awareness
  • Monitoring Compliance
  • Data Protection Impact Assessments (DPIAs)
  • Risk-Based Approach
  • Business Support for the DPO
  • DPO Independence
  • DPO – Conflict of Interest

Module 9: UK Implementation

  • Key Differences Between the Data Protection Act and the GDPR
  • Definition of Controller
  • Highlights from the Data Protection Bill
  • Health, Social Work, Education, and Child Abuse
  • Age of Consent
  • Exemptions for Freedom of Expression
  • Research and Statistics
  • Archiving in the Public Interest

Module 10: Key Features

  • Key Features of GDPR
  • Specific Permission
  • Privacy by Design
  • Data Portability
  • Right to be Forgotten
  • Definitive Consent
  • Information in Clear Readable Language
  • Limits on the Use of Profiling
  • Everyone Follows the Same Law
  • Adopting Techniques

Module 11: Subject Access Requests and How to Deal with them?

  • Subject Access Requests (SAR)
  • Dealing with SAR
  • Recognise the Request
  • Understand the Time Limitations
  • Dealing with Fees and Excessive Requests
  • Identify, Search, and Gather the Requested Data
  • What Information to Withhold?
  • Developing and Sending a Response

Module 12: Data Subject Rights

  • Must I Always Obey a Right?
  • Rights and Third Parties
  • Requests Made on Behalf of Other Data Subjects
  • Guidelines for Children's Maturity
  • Responding to a Rights Request
  • What is a Month?
  • Rights Request Flow Chart
  • Right to Be Informed
  • Right of Access
  • Right to Rectification
  • Right to Erasure
  • Right to Restrict Processing
  • Right to Data Portability
  • Right to Object
  • Rights Related to Automated Decision Making and Profiling
  • Rights Related to Automated Decision Making and Profiling

Module 13: Subject Access Requests

  • Provenance
  • Overview: SARs
  • A SAR is an Activity, not a Title
  • How Can a SAR be Submitted?
  • What Information Should the Response to a SAR Contain?
  • Additional Information
  • Replying to a SAR
  • Confirming a Data Subject’s Identity
  • Scope
  • Electronic Records
  • Non-Electronic Records
  • SARs involving 3rd Party PII
  • Fees
  • Refusing a Subject Access Request
  • Access Requests from Employees
  • Credit Reference Agencies
  • Best Practice for SARs

Module 14: Lawful Processing

  • Lawful Processing: A Reminder
  • User Rights Change Depending on the Justification
  • Lawfulness of Processing Conditions
  • Lawfulness for Special Categories of Data
  • UK ICO has a Tool
  • Consent
  • Other Key Points about Consent
  • Affirmative Action & Explicit Consent
  • What is not Affirmative Action?
  • Examples of Affirmative Action from the ICO
  • Explicit Consent
  • The Explicit Statement
  • Obtaining Explicit Consent
  • ICOs View of a Poor Form of Explicit Consent
  • Obtaining Consent for Scientific Research Purposes
  • Getting Consent
  • What Should go into the Consent Request?
  • Consent Granularity
  • Right to Withdraw Consent
  • Children
  • Consent Records
  • ICOs Examples of Record Keeping
  • Key Points when Establishing Consent
  • Legitimate Interests
  • Getting the Balance Right
  • Consent or Legitimate Interest?
  • What Lawful Basis can be used for Processing Marketing PII?

Module 15: Third Country Data Transfers

  • Cross Border Transfers
  • Transfer Mechanisms
  • Derogations
  • Adequacy
  • Adequate Ways to Safeguard Transfers of PII
  • Consent
  • One-Off or Infrequent Transfers
  • Who is Responsible?
  • Transferring PII Between EEA Members
  • Adequate Countries Outside of the EEA
  • Binding Corporate Rules (BCR)
  • What a BCR Must Cover
  • Authorisation for BCRs
  • Privacy Shield
  • Privacy Shield Overview
  • Privacy Shield: Mechanics
  • Model Clauses
  • Public Authority Agreements

Module 16: Introduction to Protecting Personal Data

  • The Need to Secure
  • What is Appropriate?
  • Protecting PII – 3 Key Areas
  • Coverage
  • Defensive Design
  • Single Point of Failure (SPOF)
  • Incident Response
  • Data Breach Reporting Requirements
  • Incident Response Team

Module 17: Data Protection Impact Assessments (DPIA)

  • Data Protection Impact Assessments
  • What Triggers a Data Protection Impact Assessment?
  • A DPIA is Not Required in the Following Cases
  • Benefits of DPIA
  • Processes to be Considered for a DPIA
  • Responsibilities
  • DPIA Decision Path
  • DPIA Content
  • How Do I Conduct A DPIA?
  • Signing Off the DPIA
  • Mitigating Risks Identified by The DPIA

Module 18: Need Want Drop

  • Need-Want-Drop
  • Need-Want-Drop: Concept Diagram
  • Need/Want/Drop Methodology

Module 19: Dealing with Third Parties and Data in the Cloud

  • What is Cloud Computing?
  • The Myths of Cloud
  • Cloud Challenges
  • The Controller-Processor Contract
  • Checklist
  • Data Controller – Summary

Module 20: Practical Implications: GDPR

  • Brexit and its Impact on the GDPR
  • One-Stop Shop

Module 21: Legal Requirements of the GDPR

  • Legal Requirements
  • Lawful, Fair, and Transparent Processing
  • Limitation of Purpose, Data and Storage
  • Data Subject Rights
  • Consent
  • Personal Data Breaches
  • Privacy by Design
  • Data Protection Impact Assessment 
  • Data Transfers
  • Data Protection Officer
  • Awareness and Training

Module 22: Privacy Principles in GDPR

  • Privacy Principles in the GDPR
  • Lawfulness, Fairness, and Transparency
  • Purpose Limitation is the Second Principle
  • One Should Refer to Data Minimisation
  • Accuracy is the Fourth Principle
  • The Fifth Principle is the Storage Limitation
  • Sixth Principle of Integrity and Confidentiality

Module 23: Common Data Security Failures, Consequences, and Lessons to be Learnt

  • Common Data Security Failures
  • Consequences
  • Lesson Learned
Show more blue-arrow

Who Should Attend this General Data Protection Regulation Foundation and Practitioner Training Course?

This General Data Protection Regulation Foundation and Practitioner Training Course is designed for professionals who handle, manage, or oversee personal data and are responsible for ensuring compliance with data protection regulations. It is particularly beneficial for:

  • Data Protection Officer (DPO)
  • Compliance Manager
  • Information Security Analyst
  • Privacy Consultant
  • Legal and Regulatory Advisor
  • IT Risk and Governance Specialist
  • Data Governance Manager

Prerequisites for the General Data Protection Regulation Foundation and Practitioner Training Course

There are no formal prerequisites to attend this General Data Protection Regulation Foundation and Practitioner Training Course.

Certified General Data Protection Regulation Foundation and Practitioner Course Overview

The Certified General Data Protection Regulation (GDPR) Foundation and Practitioner course provides comprehensive knowledge of data protection principles, legal requirements, and practical implementation of GDPR. This course is important as it ensures organisations understand and comply with data protection laws while safeguarding personal data.

It benefits organisations by reducing compliance risks, improving data governance, and strengthening customer trust. It benefits individuals by enhancing their understanding of data protection responsibilities and practical compliance approaches. It supports career development by building expertise in data privacy, governance, and regulatory compliance roles.

Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Course Objectives

  • To understand the fundamentals of GDPR legislation
  • To comprehend the rights and responsibilities of data controllers and processors
  • To learn how to conduct data protection impact assessments (DPIAs)
  • To develop expertise in data subject consent and management
  • To gain insights into GDPR compliance and risk assessment
  • To master cross-border data transfer regulations
  • To learn best practices for data breach management and reporting
  • To acquire practical skills for implementing GDPR compliance within your organisation

After successfully completing this General Data Protection Regulation Foundation And Practitioner, delegates will possess a comprehensive understanding of GDPR regulations and adherence. They will acquire the abilities necessary to evaluate, execute, and sustain GDPR conformity within their respective companies, guaranteeing the fulfilment of data protection and privacy criteria.

Show more blue-arrow

What’s Included in this Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Course?

  • Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Examination
  • World-Class Training Sessions from Experienced Instructors
  • Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Certificates
  • Digital Delegate Pack
Show more blue-arrow

GDPR Foundation Exam Information

To achieve the Certified General Data Protection Regulation (GDPR) Foundation, candidates will need to sit for an examination. The exam format is as follows: 

  • Question Type: Multiple Choice 
  • Total Questions: 45 
  • Total Marks: 45 Marks 
  • Pass Mark: 65%, or 29/45 Marks 
  • Duration: 60 Minutes 
  • Open Book/ Closed Book: Closed Book
Show more blue-arrow

Train Your Workforce

Looking for Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in-house or onsite training in Dunfermline? We specialise in corporate group training and bulk bookings for organisations of all sizes in Dunfermline. Our trainers deliver tailored sessions at your premises, online, or hybrid, with best price guarantee, group discounts and flexible scheduling to train your team.

Our Dunfermline venue

Includes..

Free Wi-Fi

To make sure you’re always connected we offer completely free and easy to access wi-fi.

Air conditioned

To keep you comfortable during your course we offer a fully air conditioned environment.

Full IT support

IT support is on hand to sort out any unforseen issues that may arise.

Video equipment

This location has full video conferencing equipment.

Dunfermline is a town located in Fife, Scotland, about three miles away from the north shore of the Firth of Forth. It was the capital of Scotland until the 17th Century. Dunfermline has a population of around 50,000 people making it the tenth largest town in Scotland. Dunfermline is a business hub for west Fife, providing vast amounts of employment from the likes of BSKYB, Amazon, Best Western and Nationwide. There are four secondary schools and fourteen primary schools in Dunfermline. There is also a private school and a school for children who have learning disabilities. Fife College is the one institute in Dunfermline which provides further education. It was founded in 1899 and merged with a textile school in 1910 and became a technical college in 1951. It caters to around 10,000 students a year.

Nearby Locations include:

  • Oakley
  • Crombie
  • Saline
  • Charlestown
  • Rosyth
  • Dalgety Bay
  • Culross
  • Comrie
  • Hillend
  • Limekilns
  • Crossford
  • Cairneyhill
  • Newmills
  • Halbeath
  • Townhill
  • Torryburn
  • High Valleyfield
  • Kingseat
  • Blairhall
  • Carnock

Show moredown

Ways to take Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in Dunfermline

Online Instructor-Led Learning

Online Self-Paced Learning

Classroom Based Learning

Onsite Learning

Experience live, interactive learning from home with The Knowledge Academy's Online Instructor-led Certified General Data Protection Regulation (GDPR) Foundation and Practitioner. Engage directly with expert instructors, mirroring the classroom schedule for a comprehensive learning journey. Enjoy the convenience of virtual learning without compromising on the quality of interaction.

classes

Live classes

Join a scheduled class with a live instructor and other delegates.

interactive

Interactive

Engage in activities, and communicate with your trainer and peers.

degree

Global Pool of the Best Trainers

We handpick from a global pool of expert trainers for our Online Instructor-led courses.

expertise

Expertise

With 10+ years of quality, instructor-led training, we equip professionals with lasting skills for success.

global

Scalable Training Delivery

Access Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in Dunfermline delivered by one of the largest training providers, with scalable instructor-led classes, accessible worldwide.

Master Certified General Data Protection Regulation (GDPR) Foundation and Practitioner with a flexible yet structured approach that combines live, expert-led sessions and self-paced study. With Weekly one-to-one tutor support and consistently high pass rates, you’ll receive tailored guidance and achieve real results.

trainer

Structured Yet Flexible Learning

Take part in scheduled, instructor-led sessions with real-time feedback, while enjoying the freedom to study independently. Interactive resources and progress tracking tools help you stay motivated and on target.

venue

Engaging & Interactive Training

Join dynamic live sessions featuring discussions, practical activities, and peer collaboration. Learn from Certified General Data Protection Regulation (GDPR) Foundation and Practitioner industry experts and reinforce your knowledge with self-paced modules—plus, connect with professionals in your field.

classes

Expert-Led Course

Gain valuable insight from experienced trainers during live sessions, and revisit course materials anytime to deepen your understanding. This method offers the ideal balance between expert guidance and independent learning.

money

Global Training Accessibility

Access top-quality training across time zones—anytime, anywhere. Whether at home or on the go, our expert-led sessions and flexible study materials support your goals, and help you on the journey towards the certification.

Learn Certified General Data Protection Regulation (GDPR) Foundation and Practitioner through The Knowledge Academy’s Online Self-Paced Learning. This flexible and structured format supports your training goals and enables every professional to build skills with confidence.

flexiblelearning

Flexible Learning

Access Certified General Data Protection Regulation (GDPR) Foundation and Practitioner resources 24/7 to maintain steady progress, complete regular assessments or tasks, and upskill effectively alongside work commitments.

expert-developed

Expert-Developed Content

Our Online Course content is designed by experienced trainers to ensure accuracy, relevance, and practical value.

global-access

Global Training Provider

Access Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in Dunfermline from a trusted global training provider delivering consistent learning to professionals worldwide.

cost-effective

Cost-Effective Training

Benefit from the cost-effective Certified General Data Protection Regulation (GDPR) Foundation and Practitioner that delivers high-quality course content without compromising learning outcomes.

interactive-lms

Interactive LMS

Track performance, download resources, and receive AI-enabled support through The Knowledge Academy’s dedicated Learning Management System.

Experience the most sought-after learning style with The Knowledge Academy's Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Course. Available in 490+ locations across 190+ countries, our hand-picked Classroom venues offer an invaluable human touch. Immerse yourself in a comprehensive, interactive experience with our expert-led Certified General Data Protection Regulation (GDPR) Foundation and Practitioner sessions.

trainer

Highly experienced trainers

Boost your skills with our expert trainers, boasting 10+ years of real-world experience, ensuring an engaging and informative training experience

venue

State of the art training venues

We only use the highest standard of learning facilities to make sure your experience is as comfortable and distraction-free as possible

classes

Small class sizes

Our Classroom courses with limited class sizes foster discussions and provide a personalised, interactive learning environment

money

Great value for money

Achieve certification without breaking the bank. Find a lower price elsewhere? We'll match it to guarantee you the best value

Streamline large-scale training requirements with The Knowledge Academy’s In-house/Onsite Certified General Data Protection Regulation (GDPR) Foundation and Practitioner Course at your business premises. Experience expert-led classroom learning from the comfort of your workplace and engage professional development.

tailored

Tailored learning experience

Leverage benefits offered from a certification that fits your unique business or project needs

budget

Maximise your training budget

Cut unnecessary costs and focus your entire budget on what really matters, the training.

building

Team building opportunity

Our Certified General Data Protection Regulation (GDPR) Foundation and Practitioner offers a unique chance for your team to bond and engage in discussions, enriching the learning experience beyond traditional classroom settings

monitor

Monitor employees progress

The course know-how will help you track and evaluate your employees' progression and performance with relative ease

Package deals for Certified General Data Protection Regulation (GDPR) Foundation and Practitioner

Our training experts have compiled a range of course packages on a variety of categories in Certified General Data Protection Regulation (GDPR) Foundation and Practitioner, to boost your career. The packages consist of the best possible qualifications with Certified General Data Protection Regulation (GDPR) Foundation and Practitioner, and allows you to purchase multiple courses at a discounted rate.

GDPR Training | GDPR Foundation And Practitioner in Dunfermline FAQs

What is the purpose of GDPR?

GDPR aims to protect individuals’ personal data and ensure organisations handle it lawfully, fairly, and transparently.

Who are Data Controllers and Data Processors?

A Data Controller decides the purpose and means of processing, while a Data Processor processes data on behalf of the controller.

What is a DPIA and when is it required?

A DPIA is used to identify and reduce data protection risks and is required for processing activities that pose high risks to individuals.

What rights do data subjects have under GDPR?

Key rights include access, rectification, erasure, restriction of processing, data portability, and the right to object.

What is a personal data breach and what are the requirements?

It involves unauthorised access, loss, or disclosure of data, and must be reported to authorities within 72 hours if required.

What is lawful processing of personal data?

Processing must be based on a legal ground such as consent, contract, legal obligation, or legitimate interest.

How does GDPR regulate international data transfers?

Transfers outside the EEA require safeguards such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules.

What is the cost/training fees for Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in Dunfermline?

The training fees for Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in Dunfermline starts from £2295

Which is the best training institute/provider of Certified General Data Protection Regulation (GDPR) Foundation and Practitioner in Dunfermline?

The Knowledge Academy is one of the Leading global training provider for Certified General Data Protection Regulation (GDPR) Foundation and Practitioner.

What are the best GDPR Training courses in Dunfermline?

Please see our GDPR Training courses available in Dunfermline

Show more blue-arrow

Customers Reviews

Request For Pricing

WHO WILL FUNDING THE COURSE?
+44

Corporate Training

Unlock tailored pricing and customised training solutions for your team’s needs.

Request your quote today!

Why choose The Knowledge Academy

price

Best price in the industry

You won't find better value in the marketplace. If you do find a lower price, we will beat it.

learning

Many delivery methods

Flexible delivery methods are available depending on your learning style.

resources

High quality resources

Resources are included for a comprehensive learning experience.

Our Clients

"Really good course and well organised. Trainer was great with a sense of humour - his experience allowed a free flowing course, structured to help you gain as much information & relevant experience whilst helping prepare you for the exam"

Joshua Davies, Thames Water
santander barclays bmw google thames-water deloitte bupa tesla
cross

Upgrade Your Skills. Save More Today.

superSale Unlock up to 40% off today!

WHO WILL BE FUNDING THE COURSE?

close

close

Thank you for your enquiry!

One of our training experts will be in touch shortly to go over your training requirements.

close

close

Press esc to close

close close

Back to course information

Thank you for your enquiry!

One of our training experts will be in touch shortly to go overy your training requirements.

close close

Thank you for your enquiry!

One of our training experts will be in touch shortly to go over your training requirements.