Choose your language
GDPR Data Protection Training
More than 2 million students worldwide

GDPR Data Protection Training

Get fully up to speed on GDPR compliance with a training program that covers everything from lawful bases and individual rights to breach management and international data transfers. Whether you're building a compliance program from scratch or strengthening an existing one, this course gives you the practical knowledge to protect your organization and stay on the right side of regulators.

Dedika for businesses

What you will learn:

You will master the seven core data protection principles and learn how to apply all six lawful bases to real processing activities. You will build compliant privacy notices, handle data subject rights requests within legal deadlines, and respond to personal data breaches under the 72-hour notification rule. The course also covers international data transfers, standard contractual clauses, and transfer impact assessments. You will learn how to embed privacy by design into product development and vendor procurement. Finally, you will develop the governance skills needed to build, audit, and continuously improve an organization-wide data protection compliance program.

How you study in practice GDPR Data Protection Training

How you practice GDPR Data Protection Training

For companies that want to train their team

With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Data Protection Law

  • Lesson 1 • Scope and Territorial Reach

    Defines which organizations and data types fall under protection obligations. Clarifies extraterritorial application relevant to global operations.

  • Lesson 2 • Key Roles and Accountability

    Distinguishes controllers, processors, and joint controllers and their respective duties. Sets up role-based responsibilities explored in later chapters.

  • Lesson 3 • Why Data Protection Matters

    Covers the harms caused by data misuse and the societal value of privacy. Grounds the chapter by connecting individual rights to organizational responsibility.

  • Lesson 4 • Core Regulatory Principles

    Introduces the seven foundational principles governing personal data processing. Provides the conceptual framework applied throughout the entire course.

Chapter 2See details

Lawful Bases for Processing Data

  • Lesson 1 • Contractual and Legal Obligations

    Covers processing necessary for contracts and legal compliance duties. Connects these bases to common HR, finance, and procurement scenarios.

  • Lesson 2 • Consent as a Lawful Basis

    Defines valid consent and distinguishes it from weaker forms of agreement. Teaches how to obtain, record, and withdraw consent correctly.

  • Lesson 3 • Legitimate Interests Assessment

    Teaches the three-part balancing test for legitimate interests. Learners will draft a legitimate interests assessment for realistic scenarios.

  • Lesson 4 • Overview of Lawful Bases

    Maps all six lawful bases and explains when each applies. Establishes a decision framework used throughout the chapter.

  • Lesson 5 • Special Category Data Conditions

    Identifies additional conditions required to process sensitive data categories. Builds on the core principles chapter by adding a stricter compliance layer.

Chapter 3See details

Individual Rights and How to Fulfill Them

  • Lesson 1 • Building a Rights Fulfillment Process

    Integrates all individual rights into a single operational workflow. Learners will map request intake, triage, response, and escalation steps.

  • Lesson 2 • Rights to Rectification and Erasure

    Addresses correcting inaccurate data and honoring deletion requests. Connects erasure conditions to lawful basis and retention policies.

  • Lesson 3 • Automated Decision-Making Rights

    Covers rights related to solely automated decisions with significant effects. Teaches safeguards, human review processes, and meaningful explanations.

  • Lesson 4 • Rights of Access and Portability

    Covers subject access requests and the right to receive data in a portable format. Teaches verification, response timelines, and exemption handling.

  • Lesson 5 • Rights to Restrict and Object

    Explains when individuals can pause processing or object to specific uses. Distinguishes restriction from erasure and covers direct marketing objections.

Chapter 4See details

Transparency and Privacy Notices

  • Lesson 1 • Mandatory Notice Content

    Lists every required element in a privacy notice under data protection law. Provides a checklist used in the notice audit exercise later in the chapter.

  • Lesson 2 • Updating and Versioning Notices

    Covers when and how to update privacy notices and communicate changes to users. Connects notice versioning to documentation and accountability obligations.

  • Lesson 3 • Writing for Clarity and Plain Language

    Applies plain-language principles to legal privacy text. Learners will rewrite dense legal clauses into accessible, accurate statements.

  • Lesson 4 • Layered and Just-in-Time Notices

    Introduces layered notice design and contextual disclosure at the point of collection. Teaches how to balance completeness with user comprehension.

Chapter 5See details

Data Protection by Design and Default

  • Lesson 1 • Data Minimization in System Design

    Applies the minimization principle to data architecture and feature development. Teaches techniques to collect only what is strictly necessary.

  • Lesson 2 • Privacy Impact Assessments

    Teaches when a formal privacy impact assessment is mandatory and how to conduct one. Learners will complete a structured assessment template for a realistic scenario.

  • Lesson 3 • Default Settings and User Controls

    Defines privacy-by-default and translates it into product configuration decisions. Teaches how to set the most protective option as the out-of-the-box default.

  • Lesson 4 • Privacy by Design Principles

    Introduces the seven foundational privacy-by-design principles and their engineering implications. Connects proactive privacy thinking to reduced compliance risk.

  • Lesson 5 • Privacy in Procurement and Vendor Selection

    Integrates privacy requirements into vendor evaluation and contract negotiation. Connects to processor obligations introduced in Chapter 1.

Chapter 6See details

Data Security and Breach Management

  • Lesson 1 • Identifying and Classifying Breaches

    Teaches how to recognize a personal data breach and assess its severity. Introduces a classification matrix used in the response planning section.

  • Lesson 2 • Regulatory Notification Requirements

    Covers mandatory timelines and content for notifying supervisory authorities. Distinguishes when individual notification is also required.

  • Lesson 3 • Breach Register and Documentation

    Explains the obligation to maintain an internal breach register regardless of notification threshold. Connects documentation to accountability and audit readiness.

  • Lesson 4 • Security Obligations Under Data Protection Law

    Defines the legal requirement for appropriate technical and organizational measures. Connects security obligations to the accountability principle from Chapter 1.

  • Lesson 5 • Breach Response Planning

    Builds a structured incident response plan covering detection through post-incident review. Learners will run a tabletop exercise simulating a realistic breach scenario.

Chapter 7See details

International Data Transfers

  • Lesson 1 • Binding Corporate Rules

    Introduces intra-group transfer rules approved by supervisory authorities. Covers the approval process and ongoing compliance obligations.

  • Lesson 2 • Standard Contractual Clauses

    Covers the use of approved contractual clauses as a primary transfer mechanism. Teaches how to implement, customize, and maintain these clauses.

  • Lesson 3 • Transfer Impact Assessments

    Teaches how to evaluate the legal landscape of a destination country before transferring data. Connects to the privacy impact assessment methodology from Chapter 5.

  • Lesson 4 • Derogations and Exceptional Transfers

    Covers limited exceptions permitting transfers without a formal mechanism. Teaches when derogations apply and how to document their use.

  • Lesson 5 • Restrictions on Cross-Border Transfers

    Explains why transfers to third countries require additional safeguards. Establishes the adequacy concept as the baseline for the chapter.

Chapter 8See details

Compliance Programs and Governance

  • Lesson 1 • Continuous Improvement and Review Cycles

    Embeds a plan-do-check-act cycle into the compliance program. Teaches how to use audit results, breach data, and regulatory updates to drive improvement.

  • Lesson 2 • Internal Audit and Compliance Monitoring

    Establishes a repeatable audit cycle to measure compliance maturity over time. Connects audit findings to remediation planning and management reporting.

  • Lesson 3 • Data Protection Officer Role

    Defines when a Data Protection Officer is mandatory and what the role entails. Covers independence requirements and the officer's relationship with senior management.

  • Lesson 4 • Records of Processing Activities

    Covers the obligation to maintain a comprehensive processing register. Teaches how to build, structure, and keep the register current.

  • Lesson 5 • Regulatory Engagement and Enforcement

    Prepares organizations to interact with supervisory authorities during investigations. Covers cooperation obligations, enforcement powers, and sanction mitigation.

  • Lesson 6 • Staff Training and Awareness Programs

    Designs role-based training programs that build a privacy-aware culture. Covers delivery formats, frequency, and effectiveness measurement.

Certification

Your valid completion certificate

This course is for you:

  • Compliance officer: needs structured GDPR knowledge to formalize existing ad hoc practices.

  • HR manager: handles employee data daily but lacks a clear regulatory framework.

  • Software developer: builds data-handling features and must understand privacy obligations by design.

  • Marketing professional: runs campaigns involving personal data and consent-based targeting.

  • Small business owner: processes customer data and faces the same legal duties as large enterprises.

  • Career changer: moving into privacy or data governance from an unrelated professional background.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in the United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course