Skip to main content
GDPR & privacy

GDPR Foundation

GDPR Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Professionals involved in personal data protection or information security who need a structured grounding in GDPR
  • Individuals seeking to understand the main privacy principles before moving into a specialist role
  • Those considering a career path in data protection or compliance
  • IT, legal, HR, or business professionals whose work involves handling personal data
  • Junior compliance or privacy officers looking to formalise their foundational knowledge
  • Students or career changers exploring the data protection field

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced data protection officers or privacy lawyers who already work with GDPR daily and need advanced or practitioner-level content rather than foundational coverage
  • Technical security specialists seeking in-depth controls implementation or penetration testing skills, as this course focuses on regulatory concepts rather than technical security measures
  • Participants who require immediate hands-on implementation guidance for complex cross-border data transfer scenarios, since the course addresses foundational principles rather than advanced compliance architecture
  • Those looking for a course focused exclusively on non-EU privacy frameworks such as CCPA or PIPEDA, as the content is scoped specifically to the GDPR

What you'll be able to do

  • 1Explain the core requirements of the General Data Protection Regulation and how they apply to an organisation's data practices
  • 2Describe the fundamental principles of privacy and personal data protection established under the GDPR
  • 3Identify the obligations, roles, and responsibilities assigned to a Data Protection Officer
  • 4Distinguish between the roles of data controllers and data processors and their respective accountabilities
  • 5Outline the key concepts and techniques used to build a personal data compliance framework
  • 6Recognise the lawful bases for processing personal data and the conditions under which each applies
  • 7Describe individual rights under the GDPR and the mechanisms organisations must provide to honour them
  • 8Summarise the competency domains assessed in the PECB GDPR Foundation examination

Day by day

Day 1Introduction to GDPR and Data Protection Principles
  • Overview of the GDPR and Its Context

    This module introduces the origin, scope, and territorial reach of the General Data Protection Regulation and explains why it was enacted to replace earlier EU data protection law.

  • Core Privacy Principles

    Participants examine the seven foundational principles of personal data processing, including lawfulness, fairness, transparency, purpose limitation, and data minimisation.

  • Key Definitions and Concepts

    This module clarifies essential GDPR terminology such as personal data, special categories of data, data subject, controller, and processor.

  • Lawful Bases for Processing Personal Data

    The module covers the six legal grounds under which personal data may be processed and the conditions that must be met for each.

  • Rights of Data Subjects

    Participants learn about the rights granted to individuals under the GDPR, including access, rectification, erasure, restriction, portability, and objection.

By end of day

  • Ability to explain the purpose and scope of the GDPR to colleagues unfamiliar with data protection regulation
  • Confidence in identifying whether a data processing activity has a valid lawful basis
  • Clear understanding of the rights data subjects can exercise and the timelines organisations must respect
Day 2GDPR Requirements, Roles, and Compliance Framework Concepts
  • Obligations of Controllers and Processors

    This module details the accountability and governance obligations placed on data controllers and processors, including records of processing activities and data protection by design.

  • The Data Protection Officer Role

    Participants explore when appointment of a DPO is mandatory, what qualifications and independence the role requires, and what tasks the DPO must perform.

  • Data Breach Notification Requirements

    The module outlines the GDPR obligations to detect, assess, and notify supervisory authorities and affected individuals of personal data breaches within prescribed timeframes.

  • Compliance Framework and Implementation Concepts

    Participants are introduced to the approaches, methods, and techniques used to build and maintain a personal data compliance programme aligned with GDPR requirements.

  • Examination Preparation and Competency Domain Review

    This closing module maps the day's content to the two PECB examination competency domains and guides participants through the format and expectations of the GDPR Foundation exam.

By end of day

  • Practical understanding of what a DPO does and how the role supports organisational accountability under the GDPR
  • Ability to outline the steps an organisation should follow when a personal data breach occurs
  • Readiness to approach the PECB GDPR Foundation examination with awareness of the competency domains it covers

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

The exam fully meets the requirements of the PECB Examination and Certificate Programme. It covers the following competency domains:

  • Domain 1: Fundamental principles and concepts of the General Data Protection Regulation (GDRP)
  • Domain 2: General Data Protection Regulation (GDPR)

The “PECB Certified GDPR Foundation” exam is available in several languages.

After successfully completing the exam, you can apply for the credential shown on the table below.

The certificate requirements for the GDPR Foundation are:

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Why should you attend?

After completing this course, you can sit for the exam and apply for a “PECB Certificate Holder in GDPR Foundation” certificate. A PECB Foundation Certificate shows that you have understood the fundamental methodologies, requirements, framework and management approach.

Educational approach

  • Lecture sessions are illustrated with practical questions and examples
  • Practical exercises include examples and discussions
  • Practice tests are similar to the Certificate Exam

Prerequisites

None

Buyers always ask

What is the difference between completing this training and obtaining a GDPR Foundation certificate?+

Completing the two-day training course earns participants an attestation of course completion worth 14 CPD credits, issued by PECB. This confirms attendance and engagement with the curriculum but is not the same as a professional certification.

To obtain the PECB Certified GDPR Foundation credential, participants must separately pass the GDPR Foundation examination, which assesses competency across two defined domains. Cyber Academy provides the training; the examination and certification process are administered by PECB under its own examination rules and policies.

Do I need any prior knowledge of data protection law before attending?+

No prior knowledge of data protection law or the GDPR is required. The course is designed as a starting point for individuals who are new to the subject or who want to formalise knowledge they have acquired informally.

A general familiarity with how organisations handle information, whether from an IT, HR, legal, or business background, will help contextualise the material, but it is not a formal requirement.

What competency domains does the PECB GDPR Foundation examination cover?+

According to PECB, the examination covers two domains: Domain 1, which addresses the fundamental principles and concepts of the GDPR, and Domain 2, which covers the GDPR requirements in detail.

The training programme maps directly to these domains across the two days, so participants who engage fully with the course content will be prepared to demonstrate competency in both areas during the examination.

In which languages is the PECB GDPR Foundation examination available?+

PECB offers the examination in several languages. For the current list of available languages, as well as details about the exam format and applicable rules, participants should consult the official PECB List of Exams and the Examination Rules and Policies on the PECB website.

Cyber Academy delivers the training in the language agreed at booking; language availability for the examination is determined entirely by PECB.

What do participants receive upon finishing the training course?+

Participants who attend the course receive a training manual containing more than 200 pages of information and practical examples, and an attestation of course completion carrying 14 CPD credits.

These materials and the CPD attestation are provided as part of the training. The examination and any associated certification fees are not part of the Cyber Academy training offer and are subject to PECB's own pricing and registration process.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.