GDPR Risk & DPIA

Data Protection Impact Assessment

Requirements:
  • Knowledge of GDPR at a basic implementation level

Risk analysis is another obligation according to Articles 24 and 25 of the EU GDPR Regulation. If you want to learn how to do Risk Assessment, this is the fastest way to do it.

The methodology is based on risk management according to the MoR standard. As part of the purpose of the workshop, it is nostrified in the Czech legislative environment.

You will learn the practical aspects of risk analysis and management in an organization in the context of personal data protection. And this throughout the entire life cycle: from identification, through classification, to the application of principles and measures (pseudonymization, modification of guidelines, access restrictions).

The most common graduates include:

  • Members of the GDPR project team

  • Graduates of the Personal Data Protection Officer course

  • Interested parties who want to learn impact analysis from the point of view of GDPR requirements

What will you learn

More information
  • Eliminate the risks of non-compliance with the GDPR
  • Personal Data Protection Impact Assessment as an example
  • Prepare a risk analysis in the sense of EU GDPR Articles 24, 25
  • Perform an impact analysis, evaluate outputs and implement measures

Terms

Currency
Term
Place
Length
Language
Price without VAT

No results match the specified filters

Loading...

Do you want this course individually?

Let us know!

This course can be customized - either as an individual training 1:1 or for your team. Just leave us your contact and we will contact you with options tailored to your needs.

Successfully sent

We will contact you.

Timeline

1st Day

09:00 – 10:30 Basics of risk management
  • Management of Risk
  • ISO 27005, ISO 31000
  • Information Security Risk Management Process
Risk Analysis
  • How to proceed with risk analysis (determination)
  • Qualitative and quantitative risk estimates
  • Identification and evaluation of assets
  • GDPR threats and vulnerabilities
  • Incident characteristics
10:30 – 10:45 Coffee break
10:45 – 12:15 Reporting
  • How to compile a management report
  • List of risks by size and characteristics
Evaluating and reporting the results
  • How to work with outputs
  • Good practices and risk acceptance criteria from a manager's perspective
12:15 – 13:15 Lunch break
13:15 – 14:45 Risk treatment methods
  • Reducing
  • Tolerance (acceptance)
  • Risk avoidance and risk transfer
GDPR Risk Management
  • Context with the GDPR risk management system
  • Opportunities and benefits of comparing with other risks in the organisation in order to make the necessary decisions
DPIA Principles
  • Principles of data protection assessment
Legal requirements for DPIA
  • Guidance from regulatory authorities
14:45 – 15:00 Coffee break
15:00 – 17:00 How to conduct a DPIA
  • When the risk is acceptable
DPIA Assessment
  • How to develop DPIA procedures
  • Audit results and next steps
Workshop - practical exercises
  • Practical risk analysis models
  • Generic threats and vulnerabilities
  • Risk derivation and assessment
Conclusion
  • Block length 90
  • Teaching hours 8
  • Refreshments Yes
  • Exam No

Learn risk analysis and DPIA of personal data directly from a GDPR Lead Auditor!

This updated course will teach you how to identify, analyze, evaluate and implement risk measures in the area of data protection and cybersecurity.

Risk analyses and DPIAs alone, even with interesting results, are of little use if the identified risks are not systematically managed (treated).

You will learn how to implement GDPR and DPIA analysis in the overall context of risk management.

You will be able to plan and specify the requirements for a detailed and problem-oriented risk analysis. An experienced auditor will introduce you to different approaches and methodologies, their pitfalls and recommend appropriate solutions.

Frequently asked questions

All questions

What is GDPR?

The General Data Protection Regulation represents a revolution in personal data protection. The new EU General Data Protection Regulation (GDPR) changes the rules of personal data processing and introduces huge penalties. Up to 4% of worldwide turnover, or €20,000,000

Regulation GDPR 679/2016 is valid in the territory of the Union with higher legal force at the level of an international treaty. In the event of a conflict with No. 101/2000 Coll., the GDPR then has a higher legal force and therefore the GDPR will apply. The GDPR itself does not repeal the law, but in a certain sense it supercharges and supplements it where they are in conflict.

Can I get an ISO company certification from TAYLLORCOX?

Yes. At Taylorcox, we have developed a unique three-phase certification process that allows us to proceed with unrivaled speed and efficiency.

We will train your employees, prepare a package of complete documentation for you and conduct an internal audit, on the basis of which you will receive confirmation that your company processes comply with strict international standards.