Training Package
Introduction to GDPR
🎬 Contains VideosThis course gives you a clear, practical grasp of the General Data Protection Regulation (GDPR) and how to apply it in real workplaces. You’ll explore the core GDPR principles—lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability—and learn what they mean for day-to-day decisions. The course explains essential terms in plain language, including data subjects, data controllers, and processors, so you can confidently understand roles and responsibilities. You’ll master individuals’ rights such as access, rectification, erasure, portability, and objection, and practise handling subject access requests and breach responses. Step by step, you’ll build compliance know-how by mapping data flows, setting lawful bases, drafting privacy notices, conducting risk assessments, and working with suppliers. You’ll also cover penalties and enforcement, including how regulators operate, and consider future trends such as AI, international transfers, and evolving UK rules to help you design resilient, privacy-by-design programmes.
£2.00 per learner
Learning outcomes
By completing this package, learners can:
- List the seven GDPR principles and define each in one sentence with correct Article references.
- Describe the rights of data subjects and state the standard response timeline (one month, with a possible two-month extension) and lawful grounds for refusal.
- Classify real-world scenarios as controller, joint controller, or processor relationships and explain the justification using accountability and contract criteria.
- Apply GDPR to draft a 150–200-word privacy notice that includes controller identity, purposes, lawful basis, retention period, data subject rights, and international transfer safeguards.
- Analyse an organisational data map to identify personal versus special-category data, children’s data, and cross-border transfers, and determine whether a DPIA is required under Article 35, documenting at least three risk mitigations.
- Evaluate an organisation’s GDPR compliance posture using a structured checklist, prioritise remediation based on risk and potential penalties under Article 83, and justify the prioritisation.
- Assess maximum administrative fines for a provided turnover figure by applying the 2%/€10m and 4%/€20m thresholds.
- Design a 90-day GDPR implementation plan for a mid-sized organisation including governance roles (e.g., DPO), key policies, ROPA creation, processor due diligence, legitimate interests assessments, consent management, data subject request workflows, breach notification procedures, training, and audit metrics.
What’s included
A deployable SCORM package with practical learning content, ready for your LMS.
How it works
Add access, upload the package to your LMS, and pay per learner who uses it.
Who it’s for
Organisations deploying flexible workplace learning through an LMS.
