Module 1: Introduction to Data Protection and Privacy
By the end of the module, learners will understand:
- the drivers for privacy and data protection.
- the data protection framework and guiding principles (UK & EU).
- understand key definitions.
- Introduction to privacy & electronic communications.
Module 2: Data Protection (GDPR) Fundamentals and Principles
By the end of this module, learners will:
- understand what GDPR covers.
- understand the territorial and material scope of GDPR.
- have a good understanding of GDPR definitions used throughout the regulation.
- understand how data protection principles under GDPR.
- understand how accountability is defined under GDPR.
- understand what constitutes valid consent and why implicit consent is no longer compliant.
- understand the requirements for processing special category personal data under GDPR.
Module 3: Data Protection (GDPR) Rights of the Data Subject
By the end of this module, learners will:
- understand data subjects’ rights under GDPRs.
- be able to understand when restriction of processing should be applied and what that entails for an organisation.
- understand the obligations on controllers and processors to facilitate data subjects’ rights.
Module 4: Data Protection (GDPR) Controllers and Processors
By the end of this module, learners will:
- understand the obligations on controllers.
- understand what DP by design and default requires.
- understand what obligations processors must comply with
- understand the record keeping requirements that are obligated or best practice.
- have an awareness of the obligation to keep personal data secure.
- be able to describe the role and responsibilities of the Data Protection Officer.
- be aware of the breach reporting requirements.
Module 5: GDPR International Transfers
By the end of this module, learners will:
- understand the difference between EU data transfers, UK data transfers, and those to 3rd countries or international organisations.
- understand the obligations on controllers where adequacy decisions are not in place.
- understand the appropriate safeguards required for international transfers.
Module 6: GDPR Remedies, Liabilities, and Penalties
By the end of this module, learners will:
- have a good understanding of the different penalty regimes.
- be able to identify which breaches fall into the higher penalty regime and which fall to the lower regime.
- understand that other penalties and remedies may be incurred in cases of a breach.
Module 7: GDPR Supervisory Authorities, Cooperation, and Specific Situations
By the end of this module, learners will:
- be aware of the Supervisory Authority powers.
- understand specific provisions for other processing.
Module 8: Privacy in the workplace CCTV & Surveillance
By the end of this module, learners will:
- understand privacy in the workplace.
- discuss the link to CCTV & Surveillance.
Exams and assessments
There is no exam included in this foundation course. Learners seeking certification can progress to the Certified Data Protection Practitioner course, which prepares participants for an independent examination.
Hands-on learning
Learners participate in discussions, review questions, and practical reviews of GDPR concepts to reinforce understanding of rights, responsibilities, and compliance requirements. The course emphasises the application of legislative principles to real organisational contexts.