Course Outline
Introduction to the GDPR
- Distinguishing between personal data and sensitive data
- Selecting your working team
- Interpreting key GDPR terminology
- Implementing privacy by design and privacy by default
Team Appointment and Structure
- Identifying stakeholders to assist with GDPR efforts (legal, marketing, IT, HR)
- Defining the role of a DPO and assessing the need for one
Permissions and Access
- Identifying personal data
- Managing data access permissions
- Determining data storage methods, whether electronic or paper-based
- Ensuring data security
Rights and Regulatory Obligations
- Data subjects and their corresponding rights
- Responsibilities of the data controller
- Responsibilities of the data processor
- Handling data subject requests
- Managing international data transfers
- Defining data breaches
- Understanding fines and penalties
- Overseeing third-party services
- Regulations on international data transfers
Policy and Procedure Development (Legal Considerations)
- Drafting data privacy policies for employees and clients
- Documenting the legal basis for data retention
- Establishing codes of conduct for data collection and handling
- Reviewing third-party contracts with external suppliers
Continuous Maintenance
- Ensuring the accuracy and currency of held data
- Updating privacy notices and procedures in response to GDPR changes
- Adjusting contracts as necessary
Requirements
No prior prerequisites are required to participate in this course.
Testimonials (3)
The variety of the information shared and the clarity to explain terms in plain English.
Arisbe Mendoza - Fairtrade International
Course - GDPR Workshop
The training was very informative and relevant to the realities of what we are dealing with. It was very eye-opening to understand how to deal with data of UE residents. The trainer was very informed and prepared on the subject.
Isaac Rewa - Fairtrade International
Course - GDPR Workshop
I generally enjoyed the knowledge of the trainer.