Intermediate
Global Data Breach Response
Build and rehearse a cross-border personal-data breach process covering containment, harm assessment, notification decisions, communications and defensible evidence.
About this course
A practitioner course for privacy, security, legal and communications teams who have to make notification decisions under pressure and defend them afterwards. It builds an intake and containment workflow, a harm-assessment method, a jurisdiction and notification map, a communications pack, vendor and forensic coordination steps, a defensible evidence set and a tabletop exercise. Deadlines and thresholds differ by jurisdiction and by role; there is no single global rule.
What you will be able to do
- Distinguish a personal-data breach from a broader security or availability incident
- Establish a rapid intake, containment and decision workflow with clear ownership
- Assess harm and notification duties across affected jurisdictions without assuming one universal threshold or deadline
- Coordinate controllers, processors, vendors, specialists and communications teams
- Preserve a defensible incident record and turn lessons learned into control improvements
Course content
- 1
What counts as a personal-data breach
Separate a security incident from a notifiable privacy breach across confidentiality, integrity and availability.
- What counts as a personal-data breach30 min
4-question quiz
- 2
The first 24 hours
Stand up incident command, contain, preserve evidence and establish who owns the notification clock.
- The first 24 hours30 min
4-question quiz
- 3
Risk and harm assessment
Assess likely consequences for affected people and record how you reached each threshold decision.
- Risk and harm assessment30 min
4-question quiz
- 4
Jurisdiction and notification mapping
Map duties across the frameworks that reach the incident instead of assuming a single deadline.
- Jurisdiction and notification mapping30 min
4-question quiz
- 5
Regulator and affected-person communications
Draft accurate phased notices in plain language, with practical mitigation advice and no speculation.
- Regulator and affected-person communications25 min
4-question quiz
- 6
Vendors, processors and forensic coordination
Get reporting, evidence preservation and subprocessor chains working under contract and under pressure.
- Vendors, processors and forensic coordination25 min
4-question quiz
- 7
Evidence, decisions and regulatory readiness
Keep a breach register, timeline and decision record that stand up to regulator and board scrutiny.
- Evidence, decisions and regulatory readiness30 min
4-question quiz
- 8
Tabletop exercise and recovery
Run a scenario end to end, capture gaps with owners and deadlines, and close the loop on controls.
- Tabletop exercise and recovery25 min
4-question quiz
- 9
Final AssessmentFinal assessment
Confirm your understanding across the full course.
10-question final assessment