Skip to content
Security / Governance, Risk & Compliance

Personal Data Protection in Practice - RODO

The training provides a comprehensive knowledge of personal data protection and the practical aspects of implementing RODO in an organization. The program combines elements of theoretical lectures with intensive practical workshops, during which participants will gain the skills necessary to effectively manage personal data processing processes. Classes are conducted with the use of the case study method and interactive group exercises, which allows for effective assimilation of knowledge and its application in everyday work.

Issues

  • Legal grounds for processing personal data

  • Consent for data processing: acquisition and management

  • Data retention and information lifecycle management

  • Register of data processing activities

  • Data Protection Impact Assessment (DPIA)

  • Risk analysis in personal data protection

  • Rights of data subjects

  • Responsibilities of the data controller and processors

  • Privacy by design and privacy by default

  • Reporting of data protection violations

  • The role and tasks of the Data Protection Officer

  • Cooperation with the supervisory authority (PUODO)

This training is part of the path:

Benefits

  • Practical knowledge of interpreting and applying the provisions of RODO in everyday work
  • Ability to identify and categorize personal data in the organization
  • Methods for conducting data processing risk analysis
  • Knowledge of creating and managing the documentation required by RODO
  • Ability to respond to requests from data subjects
  • Procedures for reporting and managing data breach incidents
  • Principles of designing processes in accordance with the concept of privacy by design
  • Practical tools to implement and maintain RODO compliance

Who is this training for?

Data Protection Officers (DPOs).
People responsible for information security in the organization
Employees of legal and compliance departments
IT security specialists
Managers and decision makers in organizations that process personal data
Information systems administrators
HR and marketing employees
Individuals preparing for the role of IOD

Prerequisites

  • Basic knowledge of legal issues related to business operations
  • General knowledge about data protection and privacy
  • Understand the basic concepts of information security
  • Experience working with personal data in an organization
  • Knowledge of your organization's business processes

Training program

01

Training Objective

  • Training Objective: To familiarize participants with the key principles of data protection
  • Practical aspects of implementing RODO in an organization
  • Presentation of the training program and methodology
  • Participants' expectations and individual training needs
02

RODO basics

  • Genesis and objectives of the regulation: history, needs for implementation, and main goals of RODO
  • PUODO recommendations and interpretations and their practical significance
  • Definitions and key terms: personal data, data subject, controller and processor
  • Consent to data processing, pseudonymization and anonymization of information
  • Principles of personal data processing
  • Legality, reliability and transparency: a discussion of the legal basis for data processing
  • Target reduction and data minimization: practical implementation
  • Correctness and limitation of storage: data lifecycle management
  • Accountability principle: how to document compliance with RODO
03

Rights of data subjects

  • Data access and rectification: procedures and deadlines for implementation
  • Deletion of data (right to be forgotten): technical and organizational challenges
  • Data portability: format and how to exercise the right
  • Right to restrict processing and object: responding to requests
  • Responsibilities of the controller and processor
  • Records management: records of processing activities
  • Internal policies and procedures for data protection
  • Processing entrustment agreements: key elements and responsibilities of the parties
  • Data protection impact assessment (DPIA): methodology and examples
  • Risk analysis
  • Threat identification: methods for detecting potential threats to data
  • Risk assessment: techniques for evaluating the likelihood and impact of hazards
  • Planning countermeasures: strategies to minimize risks
  • Practical examples: workshops on conducting risk analysis
04

Security of personal data

  • Technical measures to secure data: encryption, pseudonymization, access control
  • Organizational measures: training, security policies, privilege management
  • Incident management: breach response procedures
  • Notification obligations: communication with PUODO and data subjects
  • Practical module - implementation of RODO
  • Mapping the organization's data processing processes
  • Create and update data protection documentation
  • Conduct risk analysis and DPIA
  • Implementation of procedures to realize the rights of data subjects
05

Workshops and case studies

  • Analysis of data breaches and lessons learned
  • Examples of proper implementation of RODO in various industries
  • Group exercise: simulation of a security incident
  • Develop strategies for responding to reports from data subjects
06

Question and answer session

  • Discussion and exchange of participants' experiences
  • Clarification of individual concerns
  • Analysis of specific cases reported by participants
  • Summary of key findings and practical tips

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the prerequisites for this training?

For Personal Data Protection in Practice - RODO we recommend: Basic knowledge of legal issues related to business operations; General knowledge about data protection and privacy; Understand the basic concepts of information security.

What is the format and duration of this training?

The training lasts 1 day and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.

Who is this training designed for?

This training is designed for: Data Protection Officers (DPOs).; People responsible for information security in the organization; Employees of legal and compliance departments.

Patrycja Petkowska
Patrycja Petkowska Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90