
The new General Data Protection Regulation (GDPR) will substitute the European Directive 95/46/CE relative to data protection the 25th May 2018. The GDPR will be applicable in each member state and will proportionate a better homogenization of personal data protection in the EU. Controllers and processors may have the obligation to designate a Data Protection Officer (DPO) according to article 37th of the GDPR. Our proposal of formation is developed to prepare the candidates for this task taking into account the technical and juridical perspective putting a big emphasis the day by day application and sharing experience in several areas such as cybersecurity, data protection, ISMS,... The certification program DPO was developed to, based on real life examples and specific exercises, deliver to the student the knowledge and abilities to undertake the implementation of the General Data Protection Regulation in the organization
Day 1: Data protection and the GDPR
Introduction to international framework
Data protection in Europe
GDPR Scope, definitions and principles
Legitimation of processing and rights of the data subjects
Consent
Documentation and reerences to the GDPR (documentation, ressources, etc.)
Day 2: Actors of GDPR
Measures related to compliance with GDPR (policies, procedures, etc.)
Controller and processor
Privacy by design and by default
Personal data breach notifications
Data Protection Officer (DPO)
Data protection authorities
International transfer of personal data
Opinions issued by the Working party 29 (WP29)
Certification exam « GDPR Foundation » (1h – 50 questions QCM)
Day 3: Risk management and accountability
Personal data protection risk management
Measures and residual risk
Risk management methodology applied to case scenario
Compliance program
Traceability of compliance
Relationship between GDPR compliance, information security and cybersecurity
Tools for a personal data risk management program
Day 4: Data protection impact assessment (DPIA)
Introduction to the DPIA: origin, concepts and characteristics
Differencies between risk and high risk for the data subject
Determining when it is necessary to conduct a DPIA
Function of the DPO regarding a DPIA
Personal data life cycle
Conducting a DPIA (Case scenario)
References, opinions and recommendations
Tools for carrying out and managing a DPIA
Day 5: Testing a data protection compliance program
Information system audit and integration of data protection measures
Personal data protection audit
Useage of data life cycle monitoring tools (case scenario)
New technologies and personal data protection
Certification exam « Data Protection Officer » (3h – 100 questions QCM)
Where does it take place?
Elgon
6
Rue d'Arlon Windhof Luxembourg
You could like it :

find out about all the networking events and trainings tailored for you!
find out about all the networking events and trainings tailored for you!