
Understand who am i and what i will offer you in this complete GDPR learning plan
Understand what is included in this course and how you will benefit around it
Complete list of course resources - 61 templates + presentations
My first promise to you to get CIPT, CIPM and CIPP/E certifications
Understand what content I am producing further
GDPR training course - compliance requirements
Learn about Major Risks to a Company's IT Framework
GDPR training course - Application Related Risks
GDPR training course - Network Related Risks
GDPR training course - Storage Related Risks
GDPR training course - stakeholder expectations
GDPR training course - privacy vs security
GDPR training course - IT vs Data Governance
GDPR Training Course - the role of the IT professional and other stakeholders in preserving privacy
Understand why privacy and security will never die
Learn the difference between privacy and security
Why privacy risks expand
Learn about cyberattacks and what makes them possible
Confidentiality, Integrity, Availability or CIA and their privacy implications
How can we build and operate systems in a more secure way
Why a privacy program is a must for every organization
Privacy Foundational elements - Organizational Privacy Notice
Privacy Foundational elements - Organizational Privacy Policy
Take a look and learn from this great Organizational Privacy Policy
Privacy Foundational elements - Organizational Security Policies
Incident Response - Security and Privacy Perspectives
System Development Lifecycle and Enterprise Architecture
Privacy Impact Assessments (PIA)
GDPR training course - privacy principles
Data Retention Concepts and Best Practices in GDPR context
Notice - part of the Collection Process
The Collection Process - Choice, Control & Consent
Other topics related to Collection
Use
Security Practices and Limitations on Use
Disclosure
Retention - Records, Limitations, Access
Retention - Security Considerations
Destruction
Identity and access management under GDPR (data privacy concepts)
Limitation of access management and least privilege under GDPR (data privacy concepts)
user based access control and role based access control under GDPR (data privacy concepts)
context of authority under GDPR (data privacy concepts)
cross site authentication and authorization under GDPR (data privacy concepts)
credit card information & processing under GDPR (data privacy concepts)
PCI DSS and PA-DSS
Remote access and bring your own device policy under GDPR (data privacy concepts)
remote access and bring your own device policy under GDPR (data privacy concepts)
data encryption design considerations under GDPR (data privacy concepts)
application, record and field encrytpion under GDPR (data privacy concepts)
file & disk encryption under GDPR (data privacy concepts)
encryption under GDPR (data privacy concepts)
other privacy enhancing technologies under GDPR (data privacy concepts)
software notifications and agreements under GDPR (data privacy concepts)
GDPR short overview
GDPR training course - Format and definitions of GDPR regulation
GDPR training course - GDPR Principles
GDPR training course - what lawfulness means
GDPR training course - gap assessment
Describe the EU institutions - part of CIPP/E exam
GDPR training course - how to plan your project
GDPR training course - GDPR roles
Understand Data Protection Concepts
What are users data subject rights
Processors under GDPR
GDPR training course - personal data form
GDPR training course - privacy data protection policy
GDPR training course - data subject request procedure
GDPR training course - DPIA
GDPR training course - how to treat data breaches
GDPR training course - international transfers
You will understand the relationship between ISO27K and GDPR
Privacy by design under GDPR (data privacy concepts)
Processors, Controllers, Sub Processors - deep dive with examples
Understand the Territorial and Material Scope of GDPR with examples
Understand what sanctions covers the GDPR
Understand what GDPR calls, Legal Basis for Processing
Understand the Consent
Understand the Legal Basis for Processing Sensitive Data.
Understand the difference between security & Breach
Legitimate interests deep dive - examples
Data Processing Obligations
The right to data portability Deep Dive
GDPR vs ePrivacy Directive
Brexit and GDPR - what has changed
General Principles for International Transfers
Schrems II - General Statements
Compliance with Schrems II
EU US Data Privacy Framework part 1
EU US Data Privacy Framework part 2
Understand organizational privacy strategy for social media
Understand the consumer expectations for personal data under social media
understand threats around children online privacy
Understand social media and personal information collected around it
Understand personal data under social media - ownership and sharing
Understand e-commerce personalization
Understand Online Advertising
Understand key considerations when posting ads
Understand cookies, beacons and other tracking technologies
Understand cookies exceptions and what you need to do to comply
Understand web privacy and security risks
Wireless technology - RFID under GDPR (data privacy concepts)
Wireless technology - NFC, Bluetooth & WiFi under GDPR (data privacy concepts)
Location Based Services (LBS) - generalities under GDPR (data privacy concepts)
Location Based Services (LBS) - GPS under GDPR (data privacy concepts)
GIS under GDPR (Data Privacy concepts)
Surveillance of individuals under GDPR (data privacy concepts)
Data surveillance and biometrics under GDPR (data privacy concepts)
Lessons from Chief Security Officer (CISO) of SAP
also an ex IBM-er, MICROSOFT-er, Accenture, Cognizant, Genpact and Cisco
This course is about how to make privacy operational and how to start your journey to get 3 privacy certifications in less than 30 days: CIPT, CIPM, CIPP/E by IAPP”
Please take a look at the Learning Plan and together with my other courses, especially:
- How to Succeed in a DPO role
- GDPR Privacy Data Protection Case Studies Explained
- Ultimate Privacy by Design Data Protection Course
2025 Updated - 13+ hours of GDPR content and 61 templates
No prior GDPR knowledge is needed.
CIPT, CIPM and CIPP/E certification preparation in a complete learning plan
This is the 1st course in a 6 course series that will drive you to Data Privacy expert and will allow you to go for all IAPP certifications: CIPT, CIPM and CIPP/E.
MY FIRST PROMISE TO YOU is the following: You will be prepared to pass 3 IAPP certifications in less than 30 days if you follow the below learning plan:
Course 1: Build EU GDPR data protection compliance from scratch
Course 2: How to succeed in a Data Privacy Officer Role (GDPR DPO, CIPM)
Course 3: GDPR Privacy Data Protection Case Studies Explained (CIPP/E, CIPM, CIPT)
Course 4: Ultimate Privacy by Design Data Protection Course
Course 5: Build Security Incident Response for GDPR Data Protection (incl. parts from CIPT and CIPM also)
Course 6: (part of CIPP/US): California Consumer Privacy Act (CCPA) - Complete course
Course 7: Build a Cybersecurity Career and Earn more than 150K per year
My name is Roland Costea and I am currently the Chief Security Officer (CISO) of SAP.
After spending my last 10 years working for SAP, Microsoft, IBM, Genpact and Cognizant as a Chief Security Officer or Privacy & Security Director being able to create hundreds of integrated security & privacy programmes for top organizations in the world, I have decided to put all my experience together in a comprehensive privacy LEARNING PLAN, to show how to actually make Data Privacy operational and most importantly how to think out of the box.
I have been involved in engineering privacy for a lot of industries including Automotive (Mercedes-Benz, Geely, Volvo) and also provided DPO as a service for several other top companies in Europe and US. I have worked and developed the privacy strategy for Microsoft & IBM for the whole Central & Eastern Europe and also drived Cognizant Security & Privacy business in DACH.
Certifications I hold: CIPT, CIPM, CISSP, CRISC, CISM, CCSK, CCSP, LPT, CEH, ECSA, TOGAF
Course Curricula:
Section 1: Introduction
Section 2: Understanding the need for privacy in the IT environment
Section 3: Core Privacy Concepts
Section 4: Privacy Considerations & Techniques
Section 5: Privacy in Systems and Applications
Section 6: GDPR Implementation - short intro guide!
Section 7: Online Privacy Issues
Section 8: Technologies with Privacy Considerations
Section 9: Direct Marketing Challenges
Section 10: Lawful Processing of HR Data, Contracts & Recruiting
Section 11: GDPR for Cloud Service Providers (CSPs)
Section 12: GDPR and Payment Services Directive (PSD2)
Section 13: How Technology can help in achieving GDPR compliance
Section 14: Conclusion