Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Fundamentals of Personal Data Processing
- Sources of national and international law.
- Scope of application for personal data protection laws.
- Authority powers regarding data protection.
- Judicial remedies for the right to personal data protection.
- GDPR overview: key information, definitions, and selected topics.
- Sector-specific GDPR applications.
- Definition and classification of personal data.
- Process of personal data processing.
- Legal bases for processing personal data.
- Responsibilities of the Data Controller.
- Rights of data subjects.
- Administrative fines and penalties.
- The Personal Data Protection Act of May 10, 2018 – regulatory scope.
- Procedures for appointing a Data Protection Officer.
- Legal proceedings for violations of personal data protection laws.
- Monitoring compliance with personal data protection regulations.
- Civil, criminal, and administrative liability.
- Conditions for lawful processing of personal data (standard and sensitive categories).
- Legal requirements for delegating personal data processing to third parties.
- Data Protection Impact Assessment (DPIA).
- Principles of privacy by design and privacy by default.
- Legal bases for transferring personal data to third countries.
- Personal data protection within employment relationships.
Appointment of a Data Protection Officer
- Mandatory requirements for DPO appointment.
- Voluntary appointment of a data protection representative.
Eligibility for the Data Protection Officer Role
- Qualifications required to serve as a DPO.
- Forms of employment for the DPO.
Status and Authority of the Data Protection Officer
- Direct reporting lines to senior management.
- Ensuring adequate resources and support for the DPO.
- DPO involvement in all matters related to personal data protection.
- Prohibition on giving instructions regarding how the DPO performs their duties.
- Avoiding conflicts of interest within the organization – defining DPO tasks.
- Prohibition against dismissing or penalizing the DPO for performing their duties.
- Duty to maintain confidentiality of performed tasks.
Information Security Management
- Discussion of organizational security management systems, referencing Polish standards.
- Identifying privacy risks and their legal implications.
- Principles of risk assessment and evaluating the effectiveness of safety solutions.
- Understanding and applying a risk-based approach through practical completion of Risk Analysis templates.
- Managing the lifecycle of personal data.
Executing Data Protection Officer (DPO) Duties
- Legal basis for DPO appointment.
- Criteria and procedures for appointing a DPO.
- DPO status and necessary qualifications.
- DPO responsibilities and rules for planning task execution.
- Conducting compliance reports for data processing in traditional and IT systems.
- Documenting DPO activities.
- Preparing audit reports.
- Guidelines for supervising personal data processing documentation.
- Powers of the Office for Personal Data Protection (UODO) concerning DPOs.
Practical Guide to Inspections by the Office for Personal Data Protection
- Requirements imposed on audited entities.
- Preparation strategies for inspections.
- Case studies.
Hands-on Exercises
- Drafting an exemplary Information Security Policy.
- Developing management directives.
- Creating a Record of Processing Activities (RoPA).
- Preparing concise personal data protection documentation.
- Case studies.
- Identifying common errors in documentation preparation.
Supplementary Materials for Participants:
Useful Forms and Templates:
- Consent for image use and dissemination.
- Event newsletter subscription form.
- Consent to receive offers.
- Templates for sending offer emails.
- Templates for general correspondence.
- Example of a personal data protection policy.
- Template for preparing information notices in accordance with GDPR, including instructions.
- Risk analysis template.
- Record of processing activities – template.
- Register of processing categories – template.
- GDPR Breach Log – Template.
- GDPR Compliance Checklist Template.
- Guidelines for handling personal data protection breaches.
- Data Protection Breach Report Template.
- Register of security incidents and corrective/preventive actions.
- Corrections register.
- Restorations register.
- Model correction form.
- Restoration pattern/form.
- Model objection form.
- Model contract for excluding further processing of personal data.
- Sample consents for competitions, marketing, and publications.
- Information obligation form for ferry crossings.
- Information obligation form for meeting monitoring.
- Information obligation form for recruitment processes.
- Information obligation form for the National Revenue Administration.
- LES information obligation form.
- Public Procurement Law (UCoC) information obligation.
- Labour Code information obligation.
- Tax-related information obligation.
- Employee personal data processing authorization – template with example.
- Data subject breach notification – template.
- Controller's Personal Data Processing Agreement – template.
- Processor's Personal Data Processing Agreement.
- And many more resources.
Requirements
Target Audience
- Individuals currently beginning their role as Data Protection Officers.
- Professionals scheduled to be appointed to this position in the near future.
21 Hours
Testimonials (1)
The variety of the information shared and the clarity to explain terms in plain English.