Skip to content

Intermediate

Global Data Breach Response

Build and rehearse a cross-border personal-data breach process covering containment, harm assessment, notification decisions, communications and defensible evidence.

4 hours9 modules8 lessonsFree certificate

About this course

A practitioner course for privacy, security, legal and communications teams who have to make notification decisions under pressure and defend them afterwards. It builds an intake and containment workflow, a harm-assessment method, a jurisdiction and notification map, a communications pack, vendor and forensic coordination steps, a defensible evidence set and a tabletop exercise. Deadlines and thresholds differ by jurisdiction and by role; there is no single global rule.

What you will be able to do

  • Distinguish a personal-data breach from a broader security or availability incident
  • Establish a rapid intake, containment and decision workflow with clear ownership
  • Assess harm and notification duties across affected jurisdictions without assuming one universal threshold or deadline
  • Coordinate controllers, processors, vendors, specialists and communications teams
  • Preserve a defensible incident record and turn lessons learned into control improvements

Course content

  1. 1

    What counts as a personal-data breach

    Separate a security incident from a notifiable privacy breach across confidentiality, integrity and availability.

    • What counts as a personal-data breach30 min

    4-question quiz

  2. 2

    The first 24 hours

    Stand up incident command, contain, preserve evidence and establish who owns the notification clock.

    • The first 24 hours30 min

    4-question quiz

  3. 3

    Risk and harm assessment

    Assess likely consequences for affected people and record how you reached each threshold decision.

    • Risk and harm assessment30 min

    4-question quiz

  4. 4

    Jurisdiction and notification mapping

    Map duties across the frameworks that reach the incident instead of assuming a single deadline.

    • Jurisdiction and notification mapping30 min

    4-question quiz

  5. 5

    Regulator and affected-person communications

    Draft accurate phased notices in plain language, with practical mitigation advice and no speculation.

    • Regulator and affected-person communications25 min

    4-question quiz

  6. 6

    Vendors, processors and forensic coordination

    Get reporting, evidence preservation and subprocessor chains working under contract and under pressure.

    • Vendors, processors and forensic coordination25 min

    4-question quiz

  7. 7

    Evidence, decisions and regulatory readiness

    Keep a breach register, timeline and decision record that stand up to regulator and board scrutiny.

    • Evidence, decisions and regulatory readiness30 min

    4-question quiz

  8. 8

    Tabletop exercise and recovery

    Run a scenario end to end, capture gaps with owners and deadlines, and close the loop on controls.

    • Tabletop exercise and recovery25 min

    4-question quiz

  9. 9

    Final AssessmentFinal assessment

    Confirm your understanding across the full course.

    10-question final assessment