Course Outline
Day 1
I. Selecting a Personal Data Protection Management Model?
1. Prerequisites for an effective data protection system
2. Existing data protection governance models
3. Allocation of roles and responsibilities in data protection processes.
II. Duties and Responsibilities of the Data Protection Officer (DPO)
1. Mandatory appointment of a DPO
2. Optional appointment of an Inspector
3. Knowledge requirements for the DPO
4. Sources for acquiring knowledge
5. Qualifications for acting as an Inspector
6. Employment forms for the Supervisor
7. Professional development of the DPO
8. DPO tasks
III. Data Flows
1. Data flow knowledge required for the DPO
2. Capabilities expected of a DPO
3. DPO tasks in this area.
IV. Preparing and Conducting an Audit
1. Pre-audit activities
2. Audit plan preparation
3. Appointment and task assignment for the audit team
4. Creation of working documents
5. Audit checklist
6. Case study: The auditing process in action.
V. Assessing the Degree of Compliance
1. Key considerations:
2. Security of processing
3. Legal bases for processing
4. Consent principle
5. Data minimization principle
6. Transparency principle
7. Delegation of processing
8. Transfers of data to third countries and international transfers.
VI. Audit Reporting
1. Preparing the audit report
2. Key components of the Audit Report
3. Areas requiring special attention
4. Case study
5. Collaboration with employees – building employee awareness
6. Verifying CPU warranty status
VII. Maintaining Compliance
1. Employee awareness – a critical factor
2. Data Protection Policy
3. Essential documentation
4. Continuous monitoring
Day 2
VIII. Introduction to Risk Management
1. Organizing the risk assessment process
2. Selected risk assessment practices
3. Key elements of a DPIA
IX. Examining the Context of Personal Data Processing
1. Contextual research exercises
2. External context
3. Internal context
4. Common errors
X. Data Protection Impact Assessment (DPIA)
1. Purpose of execution
2. Mandatory vs. optional DPIA scenarios
3. Essential process elements
4. Inventory of processing activities
5. Identification of processing resources, particularly high-risk ones
XI. Risk Analysis Exercises
1. Estimating the likelihood of hazards
2. Identifying vulnerabilities and existing security measures
3. Evaluating effectiveness
4. Estimating consequences
5. Identifying risks
6. Determining risk levels
7. Setting risk acceptability thresholds
XII. Asset Identification and Security Exercises
1. Determining process risk value for resources
2. Estimating hazard likelihood
3. Identifying vulnerabilities
4. Identifying existing safeguards
5. Estimating consequences
6. Identifying risks
7. Defining risk acceptability thresholds
Requirements
Target Audience
- Individuals serving as Data Protection Officers
- Anyone interested in expanding their knowledge in this field
Testimonials (1)
The variety of the information shared and the clarity to explain terms in plain English.