Learning Options
- Online Video-Based Learning
- Flexible Schedule
- Expert Trainers with Industry Experience
- High Pass Rates
- 24/7 Personalised Support
- Interactive Learning Materials
- Live Online Classes
- Expert Trainers with Industry Experience
- Live Assessment and Feedback
- Interactive Learning Materials
- Networking Opportunities
- High Pass Rates
Overview
This Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner course is essential for organisations to ensure compliance with GDPR regulations. As data protection laws continue to evolve, this course helps learners understand the core principles and practicalities of GDPR, allowing them to implement effective data protection strategies and mitigate risks.
The course is ideal for professionals in data protection, compliance, legal, or IT roles. By completing this course, learners will gain expertise in GDPR implementation and compliance, positioning themselves as valuable assets within their organisations, and enhancing their career prospects in data protection and regulatory compliance fields.
This course provided by MPES is designed for professionals looking to deepen their understanding of GDPR. With a practical approach, it covers both foundational and advanced concepts, ensuring learners can immediately apply their knowledge to real-world scenarios. This certification demonstrates competence in GDPR compliance, giving learners a competitive edge in the ever-growing data protection landscape.
Course Objectives
- Understand the principles of data protection under GDPR
- Learn how to apply GDPR in practice
- Identify key obligations for data controllers and processors
- Assess and manage GDPR risks and compliance
- Gain insights into data protection impact assessments
- Understand the role of Data Protection Officers (DPO)
- Be able to manage data breaches and response protocols
Learners will be equipped with the skills and knowledge to implement GDPR compliance strategies effectively, ensuring data protection and regulatory adherence within their organisation. They will also be prepared to lead GDPR-related projects and contribute to ongoing compliance efforts, safeguarding personal data and mitigating risks.
Average completion time
4 Monthwith unlimited support
100% onlineStart anytime
Study At Your Own PaceCourse Includes
Course Details
Develop your understanding of essential financial, business and management accounting techniques with ACCA Applied Knowledge. You'll learn basic business and management principles and the skills required of an accountant working in business.
Entry Requirements
- Educational Background: There are no specific educational requirements for this course.
- Language Proficiency: Learners should have a good command of English, as all course materials, assessments, and discussions are conducted in English.
- Interest in EU GDPR: This course is ideal for individuals with a keen interest in learning EU’s data protection law - GDPR
Learning Outcomes
- Understanding GDPR Principles: Learners will grasp the core principles of GDPR, including data protection rights, lawful processing, and accountability for compliance.
- Implementing GDPR Compliance: Learners will develop the ability to apply GDPR regulations within their organisation, ensuring data processing activities are compliant with legal requirements.
- Managing Data Protection Risks: Learners will gain the skills to assess and manage risks associated with personal data, protecting against breaches and ensuring data security.
- Leading GDPR Initiatives: Learners will be equipped to lead data protection projects, implementing strategies to ensure continuous compliance and maintaining GDPR standards.
Target Audience
- Data Protection Officers
- Compliance Managers
- IT Security Professionals
- Legal Advisors
- Risk Managers
- HR Managers
- Data Analysts
This course is ideal for professionals seeking to enhance their knowledge of GDPR and strengthen data protection practices within their organisation, ensuring regulatory compliance.
Course content
- GDPR in a Nutshell
- Generate Customer Confidence
- Focus of GDPR
- What is Personal Information?
- Who has PII?
- Lawful Processing of Personal Data
- Introduction
- Scope
- UK ICO’s View of the Scope
- Processing GDPR Definition
- Who Processes PII?
- What is Special Data?
- Legal Framework
- Timeline and Derogations
- Some Key Areas for Derogation
- Data Breaches/Personal Data Breach
- Consequences of Failure
- Governance Framework
- Key Roles
- Data Set
- Subject Access Request (SAR)
- Data Protection Impact Assessments (DPIA)
- What Triggers a Data Protection Impact Assessment?
- DPIA is Not Required
- Processes to be Considered for a DPIA
- Responsibilities
- DPIA Decision Path
- DPIA Content
- How Do I Conduct a DPIA?
- Signing Off the DPIA
- Mitigating Risks Identified by the DPIA
- Privacy by Design and Default
- External Transfers
- Profiling
- Pseudonymisation
- Principles, User Rights, and Obligations
- One Stop Shop
- Parts of the GDPR
- Format of the Articles
- Articles
- Introduction
- Legality Principle
- How the Permissions Work Together ?
- Lawfulness of Processing Conditions
- Lawfulness for Special Categories of Data
- Criminal Offence Data
- Consent
- Transparency Principle
- Fairness Principle
- Rights of Data Subjects
- Purpose Limitation Principle
- Minimisation Principle
- Accuracy Principle
- Storage Limitation Principle
- Integrity and Confidentiality Principle
- Accountability Principle
- Demonstrating Compliance with the GDPR
- Impact of Compliance Failure
- Administrative Fines
- What Influences the Size of an Administrative Fine?
- Joint Controllers
- Processor Liability Under GDPR
- Demonstrating Compliance
- Protecting PII is Only Half the Job
- What must be Recorded?
- Additional Ways of Demonstrating Compliance
- Demonstrating a Robust Process
- PIMS (Personal Information Management System)
- Cyber Essentials
- ISO 27017 Code of Practice for Information Security Controls
- Risk Management
- What is a Personal Data Breach?
- Notification Obligations
- What Breaches Do I Need to Notify the Relevant Supervisory Authority About?
- What Information Must Be Provided to the SA?
- How do I Report a Breach to the SA?
- Notifying Data Subjects
- What Should I do to Prepare for Breach Reporting?
- Updating Policies and Procedures
- Breach Reporting and Responses
- Ways to Minimise the Breach Impact
- What does the GDPR Makes Businesses Responsible For?
- Difference Between a Data Controller and a Data Processor
- How the Roles Split?
- Controllers and Processors
- Main Obligations of Data Controllers
- Demonstrate Compliance
- Joint Controllers and EU Representative
- Controller-Processor Contract
- Maintain Records and Keeping Records for Small Businesses
- Cooperation with Supervisory Authorities
- Keeping PII Secure
- Data Breach Transparency
- Role of the Data Processor
- Controller-Processor Contract
- Main Obligations of the Processor
- Perform Only the Data Processing Defined by the Data Controller
- Update the Data Controller
- Sub-Process or Appointment
- Keep PII Confidential
- Maintaining Records
- Cooperate with Supervisory Authorities
- Security
- Appoint a DPO – If Necessary
- Transferring Data Outside the EU
- Role of a Data Protection Officer
- Involvement of the DPO
- Main Responsibilities of the DPO
- Working Environment for the DPO
- Must We Have A DPO?
- Public Body
- What does Large Scale mean?
- Systematic Monitoring
- Who Can Perform the Role of DPO?
- Skills Required
- Monitoring Compliance
- Training and Awareness
- Data Protection Impact Assessments (DPIAs)
- Risk-Based Approach
- Business Support for the DPO
- DPO Independence
- DPO – Conflict of Interest
- Key Differences Between the Data Protection Act and the GDPR
- Highlights from the Data Protection Bill
- Definition of Controller
- Health, Social Work, Education, and Child Abuse
- Age of Consent
- Exemptions for Freedom of Expression
- Research and Statistics
- Archiving in the Public Interest
- Specific Permission
- Privacy by Design
- Data Portability
- Right to be Forgotten
- Definitive Consent
- Information in Clear Readable Language
- Limits on the Use of Profiling
- Everyone Follows the Same Law
- Adopting Techniques
- Subject Access Requests (SAR)
- Dealing with SAR
- Recognise the Request
- Understand the Time Limitations
- Dealing with Fees and Excessive Requests
- Identify, Search, and Gather the Requested Data
- Learn about What Information to Withhold
- Developing and Sending a Response
- Must I Always Obey a Right?
- Rights and Third Parties
- Requests Made on Behalf of Other Data Subjects
- Guidelines for Children's Maturity
- Responding to a Rights Request
- What is a Month?
- Rights Request Flow Chart
- Right to be Informed
- When Should Information Be Provided?
- Best Practice Guidance
- Right of Access
- Right to Rectification
- Right to Erasure
- When can I Refuse to Comply with a Request for Erasure?
- Erasing Children's Data
- Right to Restrict Processing
- When Processing Should be Restricted?
- Protecting PII
- Other Issues about Restricting Processing
- Right to Data Portability
- Right to Object
- Complying with the Right to Object
- Rejecting the Right to Object
- Processing for Direct Marketing Purposes
- Processing for Research Purposes
- Rights Related to Automated Decision Making and Profiling
- When does the Right not apply?
- When does the Right not apply?
- Provenance
- Overview: SARs
- SAR is an Activity, Not a Title
- How can a SAR be Submitted?
- What Information Should the Response to a SAR Contain?
- Additional Information
- Replying to a SAR
- Confirming a Data Subject’s Identity
- Scope
- Electronic Records
- Non-Electronic Records
- SARs Involving 3rd Party PII
- Fees
- Refusing a Subject Access Request
- Access Requests from Employees
- Credit Reference Agencies
- Best Practice for SARs
- Lawful Processing: A Reminder
- User Rights Change Depending on the Justification
- Lawfulness of Processing Conditions
- Lawfulness for Special Categories of Data
- UK ICO Tool
- Consent
- Key Points About Consent
- Affirmative Action and Explicit Consent
- Introduction of Affirmative Action
- What is Not Affirmative Action?
- Examples of Affirmative Action from the ICO
- Introduction of Explicit Consent
- Explicit Statement
- Obtaining Explicit Consent
- ICOs View of a Poor Form of Explicit Consent
- Obtaining Consent for Scientific Research Purposes
- Getting Consent
- What Should Go into the Consent Request?
- Consent Granularity
- Right to Withdraw Consent
- Children
- Consent Records
- ICOs Examples of Record Keeping
- Key Points When Establishing Consent
- Legitimate Interests
- Getting the Balance Right
- Consent or Legitimate Interest?
- What Lawful Basis Can be Used for Processing Marketing PII?
- Cross Border Transfers
- Transfer Mechanisms
- Derogations
- Adequacy
- Adequate Ways to Safeguard Transfers of PII
- Consent
- One-Off or Infrequent Transfers
- Who is Responsible?
- Transferring PII Between EEA Members
- Adequate Countries Outside of the EEA
- Binding Corporate Rules (BCR)
- What a BCR Must Cover?
- Authorisation for BCRs
- EU-US Privacy Shield
- Privacy Shield Overview
- Privacy Shield: Mechanics
- Model Clauses
- Public Authority Agreements
- Need to Secure
- What is Appropriate?
- Protecting PII – 3 Key Areas
- Coverage
- Defensive Design
- Single Point of Failure (SPOF)
- Incident Response
- Data Breach Reporting Requirements
- Incident Response Team
- Introduction
- What Triggers a Data Protection Impact Assessment?
- Cases Where DPIA is Not Required
- Benefits of DPIA
- Processes to be Considered for a DPIA
- Responsibilities
- DPIA Decision Path
- DPIA Content
- How Do I Conduct A DPIA?
- Signing Off the DPIA
- Mitigating Risks Identified by the DPIA
- Overview
- Need-Want-Drop: Concept Diagram
- Need-Want-Drop: Categorising Data
- Need/Want/Drop Methodology
- What is Cloud Computing?
- Myths of Cloud
- Cloud Challenges
- Controller-Processor Contract
- Checklist
- Data Controller - Summary
- Brexit and its Impact on the GDPR
- Adequacy
- What does this Mean in Practice?
- EU and in the United Kingdom Representatives
- Exemption Rule
- One-Stop Shop
- Lawful, Fair, and Transparent Processing
- Limitation of Purpose, Data and Storage
- Data Subject Rights
- Consent
- Personal Data Breaches
- Privacy by Design
- Data Protection Impact Assessment
- Data Transfers
- Data Protection Officer
- Awareness and Training
- Lawfulness, Fairness, and Transparency
- Purpose Limitation
- Data Minimisation
- Accuracy
- Storage Limitation
- Integrity and Confidentiality
- Common Data Security Failures
- Consequences
- Fines Relating to Data Breaches
- Litigation from Customers Relating to Data Breaches
- Directors, Officers, and Professional Advisors
- Reputational Damage
- Lesson Learned
- Knowing When and How to Communicate with Affected Individuals is Not Easy
- GDPR is Important, as are Other Legal Frameworks
Module 1: Introduction to the GDPR
Module 2: Binding Corporate Rules
Module 3: GDPR Terminology and Techniques
Module 4: Structure of the Regulation
Module 5: Principles and Rights
Module 6: Demonstrating Compliance
Module 7: Incident Response and Data Breaches
Module 8: Understanding the Principle Roles
Module 9: Role of the DPO
Module 10: UK Implementation
Module 11: Key Features
Module 12: Subject Access Requests and How to Deal with them?
Module 13: Data Subject Rights
Module 14: Subject Access Requests
Module 15: Lawful Processing
Module 16: Third Country Data
Module 17: Introduction to Protecting Personal Data
Module 18: Data Protection Impact Assessments (DPIA)
Module 19: Need Want Drop
Module 20: Dealing with Third Parties and Data in the Cloud
Module 21: Practical Implications: GDPR
Module 22: Legal Requirements of the GDPR
Module 23: Privacy Principles in GDPR
Module 24: Common Data Security Failures, Consequences, and Lessons to be Learnt
MPES Support That Helps You Succeed
At MPES, we offer comprehensive support to help you succeed in your studies. With expert guidance and valuable resources, we help you stay on track throughout your course.
- MPES Learning offers dedicated support to help you succeed in Accounting and Finance courses.
- Get expert guidance from tutors available online to assist with your studies.
- Check your eligibility for exemptions with the relevant professional body before starting.
- Our supportive team is here to offer study advice and support throughout your course.
- Access a range of materials to help enhance your learning experience. These resources include practice exercises and additional reading to support your progress.
Career Growth Stories
MPES Learning offers globally recognised courses in accounting,
Arvy Pasanting
As a qualified accountant, studying with MPES has been very rewarding experience. Its team of passionate and dedicated mentors gave me the confidence and knowledge I needed to not just at excel in my current role as an auditor, but also inspired me to expand my horizons. I am very grateful of the support I was given where the skills I gained extended beyond just passing exams and learning about accounting principles - it allowed me to take on roles that benefit the wider community.
Arvy PasantingDavid Ford
I was recommended MPES after searching for a way to pursue a career in the accounting profession, I have studied with them throughout my journey utilising both their “in class” and online learning opportunities that fit around the needs of my employer, I have found them to be consummate professionals delivering first class accounting courses with support always available.
David FordAaron Allcote
As a finance officer, MPES has been a huge help in understanding the process of recording and processing transactions from all different perspectives. The courses are very easy to follow, and the training they provide can be applied to real-life scenarios. The courses have been a huge help for me, and I would highly recommend them.
Aaron AllcoteBob Beaumont
I completed all of my ACA studies with MPES and I think you would struggle to find a better training provider anywhere in the British Isles. MPES' tutors are excellent both at delivering training and giving individualised feedback and coaching. the supporting materials and the out of class support are also great.
Bob BeaumontGeorge Evans
The Financial Risk Management Course at MPES was invaluable in deepening my understanding of risk assessment and mitigation strategies. The hands-on learning approach allowed me to apply new concepts directly to my work. I highly recommend it for professionals in finance.
George EvansJames Robinson
As a financial consultant, I am always seeking ways to enhance my expertise. The Investment Analysis Course at MPES exceeded my expectations, offering practical skills and knowledge that I can apply immediately in my consulting work. It's an outstanding choice for professionals in finance.
James RobinsonLaura Bennett
The Corporate Finance Course I attended at MPES was transformative. The depth of knowledge shared by the instructors and the relevance of the topics covered have directly impacted on our financial strategy. I strongly endorse this program for anyone in a leadership position in finance.
Laura BennettEmma Johnson
The Financial Modeling and Valuation Course at MPES was incredibly insightful. The practical applications and real-world examples helped solidify my understanding of complex concepts. I highly recommend this course to anyone looking to enhance their financial acumen.
Emma JohnsonNeed help with your ACCA course?
Our course advisors are here to help guide you and ensure that you choose the right course for you and your career journey.
Have Questions? We’ve Got You
If you have any questions, we’re here to help. Find the answers you need in the MPES detailed FAQ section.
Q. What will I learn in the Certified EU GDPR Foundation and Practitioner course?
In this course,
you will learn about the key principles of GDPR, its practical application in
compliance, the roles of data controllers and processors, and how to manage
data protection risks. You'll also gain insights into conducting data
protection impact assessments and how to handle data breaches and compliance
challenges effectively within an organisation.
Q. How will this course help me in my career?
Completing this
course will enhance your expertise in data protection, making you an asset in
organisations seeking to ensure GDPR compliance. It will provide you with the
knowledge needed to oversee data protection processes and contribute to
compliance strategies, significantly boosting your career prospects in data
protection and regulatory compliance roles.
Q. Is this course suitable for non-technical professionals?
Yes, this course
is designed for both technical and non-technical professionals. It covers the
foundational principles of GDPR and focuses on practical application, making it
accessible for learners from diverse backgrounds, including legal, compliance,
and managerial roles. It equips you with the skills to implement data
protection measures without requiring advanced technical knowledge.
Q. Can I apply this course’s knowledge directly in my workplace?
Absolutely! The
course provides practical, real-world knowledge that you can immediately apply
to your organisation’s data protection processes. You will be able to assess
data handling practices, ensure GDPR compliance, and help mitigate data risks
within your workplace, all while building a strong compliance framework for
personal data processing.
Q. What is the difference between the Foundation and Practitioner levels of this course?
The Foundation
level introduces the fundamental concepts of GDPR, while the Practitioner level
delves deeper into its practical application, including compliance strategies,
risk management, and handling data breaches. The Practitioner course is ideal
for learners looking to apply advanced knowledge and lead GDPR compliance
initiatives within an organisation.
Related Course
Explore additional courses designed to complement your learning journey and enhance your professional skills. Expand your knowledge with these expertly curated options tailored to your career goals.
Resources
Access a wide range of free resources to support your learning journey. From blogs to news and podcasts, these valuable guides are available at no cost to help you succeed.
15 Reasons You Should Invest in Professional Development: Explained
Maria Thompson03-Jan-2025
What is Corporate Governance: Principles, Importance, and Examples
Maria Thompson23-Dec-2024
What Is Management Accounting? Types and Key Functions Explained
Maria Thompson18-Dec-2024
Accounting Secrets to Effective Budgeting: Proven Strategies for Creating Effective Budgets
Maria Thompson16-Dec-2024
Future-ready Accountants: Top Certifications to Bridge Skills Gaps in 2025
Maria Thompson04-Dec-2024
Course Schedule
£5995
Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner
10th June 2024
13th June 2024
(4 days)DELIVERY METHOD
Classroom£5995
Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner
4th November 2024
7th November 2024
(4 days)DELIVERY METHOD
ClassroomCourse Schedule
£2295
Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner
Mon 15th Jan 2024
Thu 18th Jan 2024
Duration - 4 Days
DELIVERY METHOD
Virtual£2295
Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner
Sat 10th Feb 2024
Tue 13th Feb 2024
Duration - 4 Days
DELIVERY METHOD
Virtual£2295
Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner
Mon 11th Mar 2024
Thu 14th Mar 2024
Duration - 4 Days
DELIVERY METHOD
Virtual£2295
Certified EU General Data Protection Regulation (EU GDPR) Foundation and Practitioner
Tue 7th May 2024
Fri 10th May 2024
Duration - 4 Days
DELIVERY METHOD
Virtual