Intermediate
GDPR Operational Practitioner
Move from GDPR awareness to defensible day-to-day implementation across data use, rights, assessments, vendors, transfers and incident response.
About this course
A practitioner course for people who already know what the GDPR is and now have to run it day to day. Each module produces an artefact you can put in front of an auditor or a supervisory authority: an accountability map, a lawful-basis register, a rights workflow, a ROPA and DPIA process, processor evidence, a transfer file, a breach decision record and a 90-day plan. Written for a global audience, because the GDPR reaches organisations far beyond the European Union.
What you will be able to do
- Determine when the GDPR applies and identify controller, joint-controller and processor responsibilities
- Select and document lawful bases and special-category conditions
- Operate transparent rights-request, ROPA and DPIA processes
- Govern processors, security controls and international transfers
- Assess breaches, document notification decisions and retain accountability evidence
Course content
- 1
Scope, roles and accountability
Work out when the GDPR applies to an activity and who carries which duty as controller, joint controller or processor.
- Scope, roles and accountability40 min
4-question quiz
- 2
Principles, lawful bases and special-category data
Apply Articles 5, 6 and 9 to real processing, including legitimate-interests assessments and the limits of consent.
- Principles, lawful bases and special-category data40 min
4-question quiz
- 3
Transparency and individual rights
Run notices and a rights workflow under Articles 12 to 22 without over-applying exceptions.
- Transparency and individual rights40 min
4-question quiz
- 4
ROPA, DPIAs and privacy by design
Maintain Article 30 records and run Article 25, 35 and 36 assessments that actually change decisions.
- ROPA, DPIAs and privacy by design40 min
4-question quiz
- 5
Processors, contracts and security
Govern processors under Article 28 and set proportionate security under Article 32, with evidence.
- Processors, contracts and security40 min
4-question quiz
- 6
International transfers
Choose and document a Chapter V route, run a transfer assessment and apply supplementary measures.
- International transfers35 min
4-question quiz
- 7
Personal data breaches
Assess breaches against the Article 33 and 34 thresholds and document every notification decision.
- Personal data breaches35 min
4-question quiz
- 8
Operational implementation workshop
Turn the course into a 90-day action plan, control register, ownership model, metrics and review calendar.
- Operational implementation workshop30 min
4-question quiz
- 9
Final AssessmentFinal assessment
Confirm your understanding across the full course.
10-question final assessment