Skip to content

Intermediate

GDPR Operational Practitioner

Move from GDPR awareness to defensible day-to-day implementation across data use, rights, assessments, vendors, transfers and incident response.

5 hours9 modules8 lessonsFree certificate

About this course

A practitioner course for people who already know what the GDPR is and now have to run it day to day. Each module produces an artefact you can put in front of an auditor or a supervisory authority: an accountability map, a lawful-basis register, a rights workflow, a ROPA and DPIA process, processor evidence, a transfer file, a breach decision record and a 90-day plan. Written for a global audience, because the GDPR reaches organisations far beyond the European Union.

What you will be able to do

  • Determine when the GDPR applies and identify controller, joint-controller and processor responsibilities
  • Select and document lawful bases and special-category conditions
  • Operate transparent rights-request, ROPA and DPIA processes
  • Govern processors, security controls and international transfers
  • Assess breaches, document notification decisions and retain accountability evidence

Course content

  1. 1

    Scope, roles and accountability

    Work out when the GDPR applies to an activity and who carries which duty as controller, joint controller or processor.

    • Scope, roles and accountability40 min

    4-question quiz

  2. 2

    Principles, lawful bases and special-category data

    Apply Articles 5, 6 and 9 to real processing, including legitimate-interests assessments and the limits of consent.

    • Principles, lawful bases and special-category data40 min

    4-question quiz

  3. 3

    Transparency and individual rights

    Run notices and a rights workflow under Articles 12 to 22 without over-applying exceptions.

    • Transparency and individual rights40 min

    4-question quiz

  4. 4

    ROPA, DPIAs and privacy by design

    Maintain Article 30 records and run Article 25, 35 and 36 assessments that actually change decisions.

    • ROPA, DPIAs and privacy by design40 min

    4-question quiz

  5. 5

    Processors, contracts and security

    Govern processors under Article 28 and set proportionate security under Article 32, with evidence.

    • Processors, contracts and security40 min

    4-question quiz

  6. 6

    International transfers

    Choose and document a Chapter V route, run a transfer assessment and apply supplementary measures.

    • International transfers35 min

    4-question quiz

  7. 7

    Personal data breaches

    Assess breaches against the Article 33 and 34 thresholds and document every notification decision.

    • Personal data breaches35 min

    4-question quiz

  8. 8

    Operational implementation workshop

    Turn the course into a 90-day action plan, control register, ownership model, metrics and review calendar.

    • Operational implementation workshop30 min

    4-question quiz

  9. 9

    Final AssessmentFinal assessment

    Confirm your understanding across the full course.

    10-question final assessment