Skip to content

Free courses

Courses that end with something you can use

Each course is broken into short modules with a quiz, and finishes with a final assessment. Pass it and you receive a certificate with a public verification ID. Everything is free, with no paid tier.

Foundation4 hours8 modulesCertificate included

Global Data Privacy Fundamentals

Learn the essential principles of data protection and understand how major global privacy frameworks affect everyday business activities.

  • Recognise personal and sensitive data in real business systems
  • Apply the core privacy principles shared by global frameworks
  • Explain how GDPR, US state laws and India's DPDP Act differ in practice
  • Handle individual rights requests confidently
View course
Intermediate4 hours9 modulesCertificate included

Practical Privacy Program Implementation

Learn how to create data inventories, processing records, assessments, policies, request workflows, retention processes and measurable privacy controls.

  • Structure a privacy program that fits your organisation's size
  • Run a data discovery exercise and build a usable inventory
  • Produce records of processing activities from real inputs
  • Design a data subject request workflow that meets deadlines
View course
Intermediate4 hours9 modulesCertificate included

AI Privacy and Data Readiness

Learn how to identify sensitive-data risks, assess AI tools, reduce unsafe data exposure and build practical AI-governance controls.

  • Explain how AI adoption changes an organisation's data risk profile
  • Detect and reduce sensitive data flowing into AI systems
  • Assess AI vendors on privacy and data-handling grounds
  • Apply minimisation, redaction and anonymisation appropriately
View course
Intermediate5 hours9 modulesCertificate included

GDPR Operational Practitioner

Move from GDPR awareness to defensible day-to-day implementation across data use, rights, assessments, vendors, transfers and incident response.

  • Determine when the GDPR applies and identify controller, joint-controller and processor responsibilities
  • Select and document lawful bases and special-category conditions
  • Operate transparent rights-request, ROPA and DPIA processes
  • Govern processors, security controls and international transfers
View course
Intermediate5 hours9 modulesCertificate included

EU AI Act Practitioner for Privacy Teams

Translate the EU AI Act into an operational inventory, role map, classification method, evidence set and implementation plan for privacy and governance teams.

  • Identify whether an organisation is acting as provider, deployer, importer, distributor or another regulated actor
  • Classify AI uses and recognise prohibited, transparency and high-risk obligations
  • Connect AI Act controls with privacy, security, procurement and product governance
  • Prepare appropriate evidence for transparency, human oversight, data governance and monitoring
View course
Intermediate5 hours9 modulesCertificate included

CCPA/CPRA and US State Privacy Operations

Build a repeatable US state privacy operating model using California as the anchor and reusable controls for rights, opt-outs, sensitive data, vendors and assessments.

  • Determine when major US state consumer privacy laws may apply without assuming one universal threshold
  • Implement notices and consumer-rights workflows that support jurisdictional differences
  • Operationalise sale, sharing, targeted-advertising and profiling opt-outs, including recognised preference signals where required
  • Govern sensitive data, children's data, service providers, contractors and third parties
View course
Intermediate4 hours9 modulesCertificate included

Global Data Breach Response

Build and rehearse a cross-border personal-data breach process covering containment, harm assessment, notification decisions, communications and defensible evidence.

  • Distinguish a personal-data breach from a broader security or availability incident
  • Establish a rapid intake, containment and decision workflow with clear ownership
  • Assess harm and notification duties across affected jurisdictions without assuming one universal threshold or deadline
  • Coordinate controllers, processors, vendors, specialists and communications teams
View course
Intermediate5 hours9 modulesCertificate included

Asia-Pacific Privacy Practitioner

Apply a practical regional privacy operating model across major Asia-Pacific frameworks without treating the region as one uniform legal system.

  • Determine which regional privacy frameworks may apply to a processing activity and record the basis
  • Compare notice, consent, rights, accountability, transfer and breach requirements across selected major jurisdictions
  • Adapt shared privacy controls while preserving jurisdiction-specific thresholds and terminology
  • Build operational matrices for rights, vendors, transfers and notification duties
View course
Advanced4 hours9 modulesCertificate included

Vendor Risk, Data Processing Agreements and International Transfers

Build a risk-based vendor and transfer lifecycle covering due diligence, contracts, subprocessors, security evidence, transfer mechanisms, monitoring and exit.

  • Map vendor data flows and distinguish controller, processor, service-provider and independent-recipient roles
  • Apply proportionate due diligence and document risk decisions
  • Negotiate and operate practical data-processing terms
  • Select and assess lawful international-transfer mechanisms without treating contracts as a complete risk solution
View course

Not sure which course to take?

The Privacy Readiness Assessment takes about ten minutes and tells you which categories are weakest in your organisation. Each result links to the course and templates that address it directly.

Take the assessment