Understanding the GDPR

Take the first steps to becoming compliant with GDPR - the General Data Protection Regulation - by improving your knowledge of it, with this online course.

Duration

4 weeks

Weekly study

3 hours

100% online

How it works

Unlimited subscription

Learn more

Understand what the GDPR means for you as data subject, controller or processor

On 25 May 2018, the General Data Protection Regulation (GDPR), aiming to improve data protection for individuals across the EU, became directly applicable. Now, organisations need to be compliant with the new rules and should act immediately.

By developing good knowledge of the GDPR and understanding how it affects you, you will learn about the first steps for making your organisation compliant and can immediately start taking them. You will explore data subjects’ rights, data controllers’ and processors’ obligations, and enforcement and compliance notions in the context of the Regulation.

class central badge This course has been ranked as one of the best online courses of all time by online course aggregator class central.

  • Week 1

    Introduction to data protection and the GDPR

    • General introduction

      In this activity, the course and the GDPR will be introduced to you.

    • Privacy and data protection

      We will learn about the concepts of privacy and data protection, the associated human rights and compliance with them.

    • EU legal regime on data protection

      In this activity, we will focus on the old and new legal regimes of the EU on data protection and discuss the scope of the GDPR and its applicability.

    • Basic fundamentals of the GDPR

      Together, we will examine different concepts and definitions laid down in the GDPR that are essential to understanding the new regulation and assess a number of important data protection roles.

    • Data protection principles, consent and minors

      This activity deals with six essential data protection principles, the issue of consent and minors in the context of the GDPR.

    • Conclusion

      In this activity, we will provide a conclusion of Week 1.

  • Week 2

    Rights of data subjects

    • Introduction to data subjects' rights

      In this activity, we will introduce Week 2 to you, discuss the Google case and the need for data subjects' rights.

    • Transparency and modalities

      The focus of this activity is on the general requirements for the processing of personal data introduced in the GDPR: the so-called transparency and modalities requirements.

    • Rights of access, rectification, objection and restriction of processing

      We will examine four rights that data subjects have under the GDPR. Those are the rights of access, rectification, object and restriction of processing.

    • Rights to erasure and data portability

      In this activity, we would like to address the rights to erasure and to data portability and explain the judgment of the CJEU in the Google Spain case.

    • Rights with regard to complaints, judicial remedies, automated individual decision-making, representation and compensation

      In this activity, we will deal to a spectrum of remaining data subjects rights concerning complaints, judicial remedies, automated individual decision-making, representation and compensation.

    • Restrictions of rights

      We will discuss possible ways to restrict rights of data subjects and talk about the most often used types of restriction.

    • Concluding data subjects' rights

      In this final activity, our goal is to give you a quiz on data subjects' rights testing your acquired knowledge and to conclude Week 2.

  • Week 3

    Obligations of controllers and processors

    • Who are controllers and processors?

      In this activity you will learn how the GDPR defines data controllers, joint controllers and processors before diving into their obligations and responsibilities for legal compliance.

    • Controller's obligations and responsibilities

      In this activity, you will learn what a data controller's obligations and responsibilities are and how to comply with these legal requirements.

    • Information, notification and record keeping

      Controllers need to keep records and inform supervisory authorities and data subjects of their processing activities and notify them in case of a data breach. In this activity you will learn more about this topic.

    • DPIA and DPO

      Under certain circumstances the GDPR provides that Data Protection Impact Assessments need to be carried out and Data Protection Officers need to be appointed. This activity discusses these topics.

    • Joint controllers

      When can a joint controller act in data processing under the GDPR and what are the legal obligations? This activity discusses more on this topic.

    • Processor's obligations and responsibilities

      In the following steps, you will learn the GDPR obligations of data processors and how they might be similar to and different from the obligations of data controllers, taking into account their different data processing roles.

    • Summary and concluding remarks

      Week 3 summary and concluding remarks.

  • Week 4

    GDPR enforcement and compliance

    • Responsibilities, liabilities and penalties

      In the following steps you will learn a number of mechanisms that the GDPR provides to ensure the fair and lawful processing of personal data as well as the consequences for data controllers and processors in case of infringement.

    • Data protection supervisory authorities

      In the following steps, you will learn about the legal status, tasks and powers of national data protection supervisory authorities as well as on the European Data Protection Board and their role in enforcing the GDPR.

    • Codes of conducts, certification mechanisms and binding corporate rules

      In the following steps a number of tools for facilitating the operation of data controllers and processors while bringing it in line with the GDPR are presented.

    • Data transfers and processing outside the EU

      In the following steps you will learn about the GDPR requirements for lawful data transfers and processing outside the territory of the EU.

    • Liabilities, responsibilities and penalties

      In the following steps you will learn about the liabilities, responsibilities and penalties of data controllers and processors in case they do not comply with the GDPR provisions.

    • Conclusion

      Is this the end of our course? Of course, not. It is the end of the beginning at most. Now, we should recap what we have discussed and leave it to you to apply this knowledge in practice.

More courses you might like

Learners who joined this course have also enjoyed these courses.

©2025  onlincourse.com. All rights reserved