Choose your language
GDPR Training Course
More than 2 million students worldwide

GDPR Training Course

5

Master the full scope of GDPR compliance — from lawful bases and data subject rights to breach notification and international transfers. This course gives privacy professionals, compliance officers, and legal teams the practical tools to build and sustain a defensible data protection program. Stop guessing and start operating with confidence.

Dedika for businesses

What you will learn:

You will learn how to identify lawful bases for processing, respond to data subject rights requests, and draft compliant privacy notices. The course covers Data Protection Impact Assessments, breach management, and cross-border transfer mechanisms in detail. You will also learn how to build vendor oversight programs, embed privacy by design into development workflows, and manage employee data in HR contexts. By the end, you will have the knowledge to assess compliance gaps, reduce regulatory risk, and communicate privacy obligations clearly across your organization.

How you study in practice GDPR Training Course

How you practice GDPR Training Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Data Privacy Law

  • Lesson 1 • History of Privacy as a Right

    Traces privacy from a philosophical concept to a legally enforceable right. Provides context for understanding why comprehensive data protection regulation became necessary.

  • Lesson 2 • Core Principles of Data Protection

    Introduces the foundational principles that underpin modern privacy law. These principles recur throughout the course and govern every compliance decision.

  • Lesson 3 • Regulatory Authorities and Enforcement

    Introduces supervisory authorities, their powers, and the consequences of non-compliance. Sets realistic expectations for enforcement risk throughout the course.

  • Lesson 4 • Scope and Territorial Reach

    Defines which organizations and data activities fall under regulation. Students learn to assess whether their operations trigger compliance obligations.

  • Lesson 5 • Key Actors and Their Roles

    Distinguishes controllers, processors, and joint controllers and their distinct legal duties. Understanding these roles is essential before analyzing any compliance scenario.

Chapter 2See details

Lawful Bases for Processing Personal Data

  • Lesson 1 • Consent as a Lawful Basis

    Examines the strict conditions that make consent valid under data protection law. Students learn to design compliant consent mechanisms and recognize invalid consent.

  • Lesson 2 • Special Category Data and Criminal Records

    Addresses the heightened protection for sensitive data categories and the additional conditions required. Students apply these rules to health, biometric, and other sensitive data.

  • Lesson 3 • Legitimate Interests and Vital Interests

    Analyzes the balancing test for legitimate interests and the narrow vital-interests basis. Students conduct a three-part legitimate-interests assessment.

  • Lesson 4 • Overview of Lawful Bases

    Maps all six lawful bases and explains when each applies. Establishes a decision framework students will apply in later chapters.

  • Lesson 5 • Contractual and Legal Obligation Bases

    Covers processing necessary for contract performance or legal compliance. Students distinguish these bases from consent and apply them to common business scenarios.

Chapter 3See details

Data Subject Rights in Practice

  • Lesson 1 • Managing Rights Requests Operationally

    Builds an end-to-end request management process covering verification, logging, and escalation. Connects individual rights to the organization's broader compliance program.

  • Lesson 2 • Rights to Rectification and Erasure

    Covers the right to correct inaccurate data and the right to deletion under specific conditions. Students evaluate when erasure can be refused.

  • Lesson 3 • Right to Object and Automated Decisions

    Addresses objections to processing and rights against solely automated decision-making. Students build processes to handle objections and provide human review.

  • Lesson 4 • Right of Access and Transparency

    Explains the right to obtain a copy of personal data and the information that must accompany it. Students draft compliant subject access responses.

  • Lesson 5 • Rights to Restriction and Portability

    Teaches when processing must be restricted and how to fulfill data portability requests. Students implement technical solutions for structured data export.

Chapter 4See details

Transparency and Privacy Notices

  • Lesson 1 • Maintaining and Updating Notices

    Establishes a review cycle for keeping privacy notices accurate as processing changes. Students create a notice governance process tied to change management.

  • Lesson 2 • Notices for Indirect Data Collection

    Covers disclosure obligations when data is obtained from third parties rather than directly. Students identify when and how to deliver indirect notices.

  • Lesson 3 • Designing Layered Privacy Notices

    Introduces the layered notice model that balances legal completeness with readability. Students structure notices for web, mobile, and offline contexts.

  • Lesson 4 • Legal Requirements for Transparency

    Lists every mandatory disclosure element required at the point of data collection. Students map these elements to their organization's data flows.

Chapter 5See details

Data Protection by Design and by Default

  • Lesson 1 • Principles of Privacy by Design

    Introduces the seven foundational principles of privacy by design and their practical implications. Students evaluate existing systems against each principle.

  • Lesson 2 • Integrating Privacy into Development Cycles

    Shows how to embed privacy requirements into agile, waterfall, and DevOps workflows. Students produce privacy user stories and acceptance criteria.

  • Lesson 3 • Data Minimization Techniques

    Covers technical and organizational methods to collect and retain only necessary data. Students redesign data collection forms and retention schedules.

  • Lesson 4 • Default Settings and Access Controls

    Defines what privacy-by-default means for system configuration and user-facing settings. Students audit default configurations against the data-minimization principle.

  • Lesson 5 • Privacy-Enhancing Technologies

    Surveys tools that reduce privacy risk while preserving data utility. Students select appropriate technologies for specific processing scenarios.

Chapter 6See details

Data Protection Impact Assessments

  • Lesson 1 • Consulting the Supervisory Authority

    Explains when residual high risk requires prior consultation with the regulator. Students prepare a consultation submission and understand the regulator's response process.

  • Lesson 2 • Integrating DPIAs into Project Governance

    Embeds the DPIA process into project approval gates and procurement workflows. Students design a DPIA governance model for their organization.

  • Lesson 3 • When a DPIA Is Required

    Identifies the processing activities that trigger a mandatory assessment and those that warrant one voluntarily. Students apply screening criteria to real scenarios.

  • Lesson 4 • DPIA Methodology and Structure

    Walks through the required steps of a compliant assessment from scoping to sign-off. Students follow a standardized template aligned with regulatory guidance.

Chapter 7See details

Data Breach Management and Notification

  • Lesson 1 • Post-Breach Review and Remediation

    Establishes a structured lessons-learned process to prevent recurrence and strengthen controls. Students produce a remediation action plan from a breach case study.

  • Lesson 2 • Defining and Classifying Data Breaches

    Distinguishes confidentiality, integrity, and availability breaches and their risk implications. Students classify breach scenarios and determine notification obligations.

  • Lesson 3 • Regulatory Notification Requirements

    Details the 72-hour notification deadline, required content, and phased reporting rules. Students draft a compliant authority notification for a simulated breach.

  • Lesson 4 • Notifying Affected Data Subjects

    Explains when and how to communicate a breach to individuals and what information must be included. Students draft a subject notification and evaluate communication channels.

  • Lesson 5 • Incident Detection and Containment

    Covers technical and organizational measures for early breach detection and rapid containment. Students map detection controls to their organization's infrastructure.

Chapter 8See details

International Data Transfers and Vendor Management

  • Lesson 1 • Controller-Processor Agreements

    Details the mandatory contractual terms required when engaging a data processor. Students draft and review data processing agreements against regulatory requirements.

  • Lesson 2 • Restrictions on Cross-Border Data Transfers

    Explains why transfers outside adequate jurisdictions require additional safeguards. Students map their organization's data flows to identify restricted transfers.

  • Lesson 3 • Transfer Mechanisms and Safeguards

    Surveys the approved mechanisms for lawful international transfers and their practical requirements. Students select and implement the appropriate mechanism for each transfer scenario.

  • Lesson 4 • Vendor Due Diligence and Onboarding

    Builds a risk-based process for assessing vendor privacy and security practices before engagement. Students create a vendor assessment questionnaire and scoring model.

  • Lesson 5 • Ongoing Vendor Monitoring and Offboarding

    Establishes continuous oversight of processors and a secure offboarding process when relationships end. Students design a vendor review schedule and data return protocol.

Certification

Your valid completion certificate

This course is for you:

  • Compliance officers: needing structured GDPR knowledge to strengthen existing programs.

  • HR managers: handling sensitive employee data across recruitment and offboarding processes.

  • Software developers: embedding privacy requirements into product and system design workflows.

  • Legal professionals: advising clients on data protection obligations and regulatory exposure.

  • Marketing managers: running campaigns that rely on customer data and consent mechanisms.

  • Career changers: transitioning into privacy roles from adjacent legal or technology fields.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course