Skip to main content
GDPR & privacy

GDPR - Certified Data Protection Officer

GDPR - Certified Data Protection Officer. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBExpert5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants responsible for planning, implementing, or maintaining an organisational GDPR compliance programme
  • Appointed or aspiring Data Protection Officers seeking to formalise and deepen their operational expertise
  • Information security, incident management, and business continuity team members with privacy-related responsibilities
  • Technical experts preparing to transition into a dedicated data protection officer role
  • Compliance officers and legal advisors involved in protecting personal data and managing regulatory risk
  • Expert consultants advising organisations on the security and lawful processing of personal data

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Complete beginners with no prior exposure to data protection concepts, as the course moves quickly past foundational definitions
  • Professionals seeking a general introduction to cybersecurity who have no specific interest in privacy regulation or GDPR compliance
  • Individuals looking for broad IT governance training rather than focused personal-data protection content
  • Attendees expecting hands-on technical security engineering instruction rather than regulatory and operational DPO practice

What you'll be able to do

  • 1Interpret the core concepts, principles, and requirements of the GDPR in an organisational context
  • 2Map relationships between the GDPR and related frameworks such as ISO/IEC 27701, ISO/IEC 27001, and NIST Frameworks
  • 3Explain the formal designation process and operational responsibilities of a Data Protection Officer
  • 4Execute the day-to-day duties of a DPO, including advising business units and handling data subject requests
  • 5Inform and advise stakeholders on GDPR obligations and monitor ongoing organisational compliance
  • 6Conduct a GDPR compliance programme analysis and identify gaps requiring remediation
  • 7Coordinate effectively with supervisory authorities during audits or incident investigations
  • 8Apply practical GDPR toolkit components to support continual improvement of a data protection programme

Day by day

Day 1Introduction to GDPR concepts and principles
  • Core GDPR principles and legal bases

    Participants explore the foundational principles of the GDPR, including lawfulness, purpose limitation, data minimisation, and accountability, establishing the regulatory baseline for the rest of the course.

  • Scope, territorial reach, and key definitions

    This module examines who and what falls within the GDPR's scope, covering data controller and processor distinctions, categories of personal data, and the regulation's extraterritorial applicability.

  • Relationship with other regulatory frameworks and standards

    Participants map the GDPR against ISO/IEC 27701, ISO/IEC 27001, and NIST Frameworks to understand how privacy and security standards complement and reinforce each other.

By end of day

  • Articulate the six lawful bases for processing and identify which applies in common organisational scenarios
  • Distinguish controller from processor obligations and explain how each accountability principle operates in practice
  • Identify where ISO/IEC 27701 and ISO/IEC 27001 controls support GDPR compliance requirements
Day 2Designation of the DPO and analysis of the GDPR compliance programme
  • When and how to designate a DPO

    This module covers the mandatory and voluntary designation criteria under Articles 37 to 39, including the DPO's required qualities, position within the organisation, and publication requirements.

  • Structuring a GDPR compliance programme

    Participants learn how to scope, design, and document a compliance programme, identifying the policies, procedures, and records of processing activities needed to demonstrate accountability.

  • Roles and responsibilities of accountable parties

    This module examines how accountability is distributed among controllers, joint controllers, processors, and sub-processors, clarifying contractual and operational obligations at each level.

By end of day

  • Determine whether an organisation is legally required to designate a DPO and document the rationale
  • Draft the initial scope and key components of a GDPR compliance programme for a realistic organisational scenario
  • Assign accountability roles accurately across a multi-party data processing chain
Day 3DPO operations
  • Daily advisory and monitoring tasks

    Participants examine the DPO's ongoing obligations to inform and advise the organisation, monitor compliance activities, and maintain appropriate records without assuming managerial liability.

  • Data subject rights management

    This module covers procedures for handling access, rectification, erasure, portability, and objection requests within statutory timeframes, including escalation paths for complex cases.

  • Privacy impact assessments and high-risk processing

    Participants practice conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities and learn when prior consultation with a supervisory authority is required.

  • Cooperation with supervisory authorities

    This module outlines the DPO's role as the contact point for supervisory authorities, covering communication protocols, audit cooperation, and handling regulatory inquiries.

By end of day

  • Respond to a data subject rights request using a structured process that meets GDPR timing requirements
  • Determine whether a processing activity triggers a mandatory DPIA and initiate the assessment workflow
  • Prepare appropriate documentation before a supervisory authority inquiry or audit visit
Day 4Monitoring and continual improvement of GDPR compliance
  • Technical and organisational measures for data protection

    Participants review the categories of technical controls, such as encryption and pseudonymisation, and organisational measures, such as staff training and access policies, that satisfy Article 32 obligations.

  • Personal data breach detection and notification

    This module addresses how to identify a reportable breach, apply the 72-hour notification rule to supervisory authorities, and communicate with affected data subjects proportionately.

  • Auditing and reviewing the compliance programme

    Participants learn how to plan and execute internal compliance reviews, interpret audit findings, and translate results into corrective actions that support continual improvement.

By end of day

  • Select appropriate technical and organisational measures proportionate to the risk profile of a processing activity
  • Apply the breach notification decision tree to determine reportability within the 72-hour window
  • Use audit findings to prioritise and document corrective actions in a GDPR compliance register
Day 5GDPR toolkit practice, analysis, and exam preparation
  • Applying the GDPR toolkit in practice

    Participants work through practical toolkit components, including templates for records of processing activities, DPIA forms, and consent mechanisms, applying them to realistic organisational scenarios.

  • Assisted compliance programme review exercise

    This module uses a case-study format to help participants identify compliance gaps, propose remediation steps, and present findings in a manner suitable for senior management.

  • Exam domain review and knowledge consolidation

    Participants revisit the three assessed competency domains covering data protection concepts, accountable-party responsibilities, and technical and organisational measures to consolidate course learning before the exam.

By end of day

  • Complete a records-of-processing-activities template accurately for a multi-department organisational scenario
  • Present a gap analysis and prioritised remediation plan drawn from a full compliance programme review
  • Identify which competency domain each exam question type targets and apply appropriate knowledge accordingly

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Data protection concepts, General Data Protection Regulation (GDPR), and compliance measures
  • Domain 2: Roles and responsibilities of accountable parties for the GDPR compliance
  • Domain 3: Technical and organizational measures for data protection

Certification Rules and Policies.

The requirements for PECB Data Protection Certifications are:

To be considered valid, these activities should follow best data protection practices and include the following:

  1. Assisting in applying the GDPR requirements
  2. Monitoring a GDPR compliance program
  3. Providing advice on the data protection impact assessment
  4. Monitoring a data protection project with regard to the processing of personal data in alignment with the GDPR
  • Certification and examination fees are included in the price of the training course.
  • Participants will be provided with training course materials containing over 400 pages of information, practical examples, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12 month period from the initial date of the exam.

Educational approach

  • This training course is based on both theory and best practices used in exercising the role of the DPO.
  • Lecture sessions are illustrated with practical exercises based on a case study which include role-playing and discussions.
  • The participants are encouraged to intercommunicate and engage in discussions and exercises.
  • Practice exercises and quizzes are similar to the certification exam.

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

What prior knowledge should I have before attending this course?+

PECB recommends that participants arrive with a foundational understanding of GDPR concepts and comprehensive knowledge of data protection requirements. Attendees who have worked in compliance, information security, legal, or privacy advisory roles will typically find the pace comfortable.

The course does not begin with a GDPR primer, so candidates who are entirely new to data protection regulation are advised to undertake preparatory self-study before enrolling. Familiarity with a related standard such as ISO/IEC 27001 or ISO/IEC 27701 is useful but not formally required.

Which competency domains does the PECB exam for this certification cover?+

According to PECB, the exam assesses three domains: Domain 1 covers data protection concepts, the GDPR, and compliance measures; Domain 2 addresses the roles and responsibilities of accountable parties under the GDPR; and Domain 3 focuses on technical and organisational measures for data protection.

Day five of this training course includes a structured review of all three domains to help participants consolidate their knowledge before sitting the exam independently.

What professional activities are recognised toward a PECB Data Protection credential after passing the exam?+

PECB indicates that relevant data protection activities should follow best practices and include work such as assisting in applying GDPR requirements and monitoring a GDPR compliance programme. The specific volume and type of experience required varies by credential level.

Candidates should review the current PECB certification requirements directly on the PECB website, as Cyber Academy does not administer the credential application process and requirements may be updated by PECB.

How does this course address the GDPR's relationship with ISO/IEC 27701 and ISO/IEC 27001?+

Day one of the programme explicitly maps GDPR obligations against ISO/IEC 27701, ISO/IEC 27001, and NIST Frameworks, helping participants understand how controls from these standards can serve as evidence of compliance with GDPR's accountability and security requirements.

This cross-framework perspective is particularly valuable for information security professionals who already operate within an ISO-certified environment and need to integrate privacy management into an existing security management system.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.