GDPR Data Protection Leader

Get to know GDPR practically

Requirements:
  • GDPR DPO certification

Data Protection Leader (DPL) is intended for graduates of the basic 2-day Data Protection Officer (DPO) course, or in the Czech legislative environment: Personal Data Protection Officer

Target audience:

  • Privacy Officers

  • Statutory bodies, procurators and directors

  • Lawyers, corporate lawyers, HR professionals

  • Public administration employees, non-profit organizations

  • Employees in the sales department, but also in marketing

  • Administrators of data, databases, operators. Head of IT, security

What will you learn

More information
  • Know-how from 1,000+ large and small projects
  • 2 years of key experience in 2 interactive days
  • 140 decisions of European courts and data protection authorities
  • Tips for GDPR implementation, ISO 27701 certification and control by PDPO

Terms

Currency
Term
Place
Length
Language
Price without VAT

No results match the specified filters

Loading...

Do you want this course individually?

Let us know!

This course can be customized - either as an individual training 1:1 or for your team. Just leave us your contact and we will contact you with options tailored to your needs.

Successfully sent

We will contact you.

Timeline

1st Day

09:00 – 10:30 Data flow mappingThe audit identifies areas covered by the GDPR.How to map correctly
  • Form, outputs
  • Consent is not always required
  • Developing an analysis of purposes and titles
Mapping at the level of
  • Data flows
  • Separate processes
Mapping by topic
  • Roles, IS/IT
  • Processes, approvals
  • Mapping of documentation
10:30 – 10:45 Coffee Break
10:45 – 12:15 GAP analysis - procedure
Impact of EU Regulation 679/2016 on the organisationData definition
  • Method of keeping them
  • Assessment of the position of the Trustee
  • Necessary interventions (IT, Legal, HR...)
GAP Analysis - Outputs
  • Appointment of the DPO
  • ICT and necessary changes
  • Law and necessary changes
  • Controlled documentation and changes
  • GDPR's impact on the organisation
12:15 – 13:15 Lunch Break
13:15 – 15:00 GDPR Risk Analysis
  • Characteristics of the incident
  • GDPR threats and vulnerabilities
  • Asset identification and valuation
  • Qualitative and quantitative estimates -Risk analysis (determination) procedures
Reporting
  • How to make a management report
  • List of risks by size and characteristics
  • Evaluating and reporting the results
Risk treatment methods
  • reduction
  • tolerance (acceptance)
  • risk avoidance and risk transfer
15:00 – 15:15 Coffee Break
15:15 – 17:00 GDPR Risk Management
  • GDPR risk management context
  • The opportunities and benefits of comparing with other risks in the organisation to make the necessary decisions.
DPIAData Protection Impact Assesment - Data Protection Impact AnalysisPrinciples
  • When the risk is acceptable
  • Legal requirements for DPIA
  • Guidance from regulatory authorities
  • Data Protection Assessment Principles
DPIA Assesment
  • How to create DPIA procedures
  • Practical risk analysis models
  • Generic threats and vulnerabilities
  • Risk derivation and assessment

2nd Day

09:00 – 10:30 ISO certification
  • Principles, Processes
  • ISO 27001, ISO 27701
ISO 27702
  • IT security
  • Physical Security
  • Personnel security
  • Organisational security
  • Upgrade for data controllers
  • Upgrade for data processors
10:30 – 10:45 Coffee Break
10:45 – 12:15 GDPR and ISO 27701
  • Regulation 679/2016Rules for the work of the auditor according to ISO 27701
ISO 27701 CertificationHow we got certified in data protection and you can too!
  • Microsoft case study
  • GDPR Compliance procedure
12:15 – 13:15 Lunch Break
13:15 – 15:00 Office for Personal Data Protection - inspection day3 incentives for control
  • attack by competitors
  • hacker attack on data
  • use and processing of data in the cloud
15:00 – 15:15 Coffee Break
15:15 – 17:00 Audit progress
  • Incidents
  • Inspection of the Office for Personal Data Protection
  • What, how and why to document Audit process
  • Block length 90
  • Teaching hours 16
  • Refreshments Yes
  • Exam Yes

Knowledge of the General Data Protection Regulation and the Czech implementing regulation is already widely known, as are the procedures and techniques for implementing the GDPR in an organisation, we have prepared a course of a different kind.

It is considerably difficult to keep track of the current opinions of the Office for Personal Data Protection, WP 29 or case law of the Court of Justice in the field of personal data. It is a lengthy and demanding job, which we have decided to make easier and more enjoyable for you.

We have prepared an overview of the last 2 years in the field of GDPR in the scope of the just mentioned opinions, important case law in the field of data protection, an overview of the situation within the EU and at home, fines, control and supervision activities and news.

In the scope of 2 days, we will prepare a range of up-to-date information with implications for the exercise of your profession, including a discussion with other participants.

The course is particularly unique in its topicality, where it seeks to keep professionals at the centre of the action and provide valuable suggestions for further improvement of their work, both from the lecturer and through mutual exchange of information and experience.

We hope to combine space for your development in personal data issues with fun in an interesting group of Trustees.

The certification exam takes place on the last day of the course. Candidates attending the course as a virtual class will also take the certification exam online.

Prestigious certification included

GDPR Data Protection Leader

Authorized according to the European e-Competence Framework. Accredited content according to the e-Competence Framework (e-CF) is a guarantee of appropriate expertise especially for the roles listed below.

Issuance of the certificate is in accordance with ISO/IEC 17024 General requirements for bodies operating certification of persons and The General Data Protection Regulation (GDPR Regulation EU 2016/679), or Personal data protection officer, according to Article 37 of the Regulation of the European Parliament and of the Council, including relevant other legal regulations and e-CF.

Certification instructions

Exam format

No. of questions: 30

Time limit: 60 min.

Exam language: Czech

Pass mark: 20 marks

Frequently asked questions

All questions

What is GDPR?

The General Data Protection Regulation represents a revolution in personal data protection. The new EU General Data Protection Regulation (GDPR) changes the rules of personal data processing and introduces huge penalties. Up to 4% of worldwide turnover, or €20,000,000

Regulation GDPR 679/2016 is valid in the territory of the Union with higher legal force at the level of an international treaty. In the event of a conflict with No. 101/2000 Coll., the GDPR then has a higher legal force and therefore the GDPR will apply. The GDPR itself does not repeal the law, but in a certain sense it supercharges and supplements it where they are in conflict.

What is ePrivacy?

ePrivacy is the Regulation on the protection of privacy in electronic communications and the legal framework of the European Union, which concerns the protection of privacy and security of personal data in the field of electronic communications.

ePrivacy aims to strengthen consumer confidence in the online environment by regulating the way personal data is processed when using electronic communication services such as email, text messages, phone calls and internet browsers.

How does ePrivacy impact Data Protection Officers?

Although ePrivacy indirectly affects the protection of personal data, DPO may have an obligation to monitor compliance with the relevant provisions of ePrivacy, especially if the organization carries out electronic communications.

The DPO can play an important role in the implementation and compliance of privacy and personal data legislation within the organization, including ePrivacy compliance, which may include reviewing and updating electronic communications and privacy policies and procedures.