Course Outline
Day 1
I. Selecting a Data Protection Management Model?
1. Prerequisites for an effective data protection system
2. Existing data protection governance models
3. Division of roles and responsibilities in data protection processes.
II. Duties and Responsibilities of the Data Protection Officer (DPO)
1. Mandatory appointment of a Data Protection Officer
2. Optional appointment of an Auditor
3. Essential knowledge for a DPO
4. Sources for gaining knowledge
5. Qualifications to act as an Auditor
6. Employment forms for the Supervisor
7. Enhancing the DPO role
8. DPO tasks
III. Data Flows
1. What a DPO needs to know about data flows
2. Competencies expected of a DPO
3. Relevant tasks of the DPO in this context.
IV. Preparing and Conducting an Audit
1. Audit preparatory activities
2. Audit plan preparation
3. Appointment and assignment of tasks to the audit team
4. Creation of working documents
5. Audit checklist
6. Case study: The auditing process.
V. Assessing the Degree of Compliance
1. Key considerations:
2. Security of processing
3. Grounds for processing
4. Principle of consent
5. Principle of data minimization
6. Principle of transparency
7. Entrustment of processing
8. Transfer of data to third countries and international transfers.
VI. Audit Reporting
1. How to prepare an audit report
2. Components of an Audit Report
3. Areas requiring special attention
4. Case study
5. Cooperation with employees – building employee awareness
6. Verifying Controller warranty.
VII. Maintaining Compliance
1. Employee awareness – a critical issue
2. Data Protection Policy
3. Essential documentation
4. Continuous monitoring
Day 2
VIII. Introduction to Risk Management
1. Organizing the risk assessment process
2. Selected risk assessment practices
3. Essential elements of a DPIA
IX. Examining the Context of Personal Data Processing
1. Contextual research exercises
2. External context
3. Internal context
4. Common mistakes
X. Data Protection Impact Assessment (DPIA)
1. Purpose of execution
2. When is a DPIA obligatory or not?
3. Necessary elements of the process
4. Inventory of processing activities
5. Identification of processing resources, particularly those with high risk
XI. Risk Analysis Exercises
1. Estimating the probability of a hazard occurring
2. Identification of vulnerabilities and existing security measures
3. Identification of effectiveness
4. Estimating consequences
5. Risk identification
6. Determining the level of risk
7. Determining the threshold of risk acceptability
XII. Asset Identification and Security Exercises
1. Determining the process risk value for the resource
2. Estimating the probability of the hazard occurring
3. Vulnerability identification
4. Identification of existing safeguards
5. Estimating consequences
6. Risk identification
7. Determining the risk acceptability threshold
Requirements
Target Audience
- Individuals serving as or aspiring to be Data Protection Officers
- Professionals interested in expanding their knowledge in this field
Testimonials (1)
The variety of the information shared and the clarity to explain terms in plain English.