Instructor
-
MGSI
is a consulting firm established in Canada and Luxembourg that delivers data protection and information security services. MGSI supports organisations in complying with the General Data Protection Regulation (GDPR). MGSI brings its legal, organisational and technological expertise through tailor-made audit, support and consultancy missions. MGSI is an authorised training provider in France and Luxembourg and offers a range of thematic training courses.
Sessions
-
June 5, 2025 - June 6, 2025
9:00 am - 5:30 pm -
July 17, 2025 - July 18, 2025
9:00 am - 5:30 pm -
October 16, 2025 - October 17, 2025
9:00 am - 5:30 pm
Venue: Paris and online
Language: English
Duration: 2 days – 14 hours
12-month IAPP membership + exam included.
For registration in both courses: CIPP/E + CIPM, the price is 3,490€ excluding tax.
Training Overview
Regulation n° 2016/679, known as the General Data Protection Regulation (GDPR), is a European Union regulation that serves as the reference text for personal data protection. It introduces new rights for individuals and new obligations for all companies, which must comply with it. This entry-level training is suitable for both professionals aiming to get certified and those who wish to deepen their theoretical knowledge of personal data protection in a European context.
About IAPP: Established in 2000, IAPP is a non-profit, non-political association whose mission is to support and enhance the knowledge of personal data protection professionals worldwide. Headquartered in Portsmouth, New Hampshire, with an office in Brussels for Europe, IAPP currently has over 52,000 members across 110 countries. It offers its members training on personal data protection, certifications, publications, research, monitoring, events, and networking opportunities.
TRAINING OBJECTIVES
At the end of this training, the participant will have the skills to:
- Prepare for the CIPP/E IAPP certification exam
- Understand regulatory changes imposed by the GDPR
- Identify the impacts on organizational aspects within the company
- Prepare an action plan for compliance
TARGET AUDIENCE
DPOs, DPO liaisons for international companies, GDPR consultants.
PREREQUISITES
No prerequisites are required.
DETAILED PROGRAM
Introduction
- Module 1: “Laws” on data protection
- National initiatives on data protection
- Technological developments
- The need for regulation by European law
- European organization and governance of data protection, and data governance at both the European and national levels
- European regulatory tools (normative tools, appropriate concepts from international treaties: protection of personal data and fundamental freedoms…)
- Module 2: Key definitions and concepts of GDPR
- Definition of new and old key concepts in European data protection
- Data categories, special data
- Concepts of data controller, processor, and joint controller
- Processing, automated processing
- Data subjects
- Principles of personal data protection
- Material and territorial scope of GDPR
- The representative of the data controller
- Module 3: Data Controllers and Processors
- Obligations of data controllers, processors
- Privacy by Design and by Default
- Contractual relationships
- Accountability
- Proof management
- Certifications, accreditations, labels
- Module 4: Personal Data Processing
- Principles related to data processing
- Legal basis for processing
- Purpose and its limitations
- Requirements related to consent
- Module 5: Rights of data subjects
- Existing rights and new rights introduced by the GDPR for the protection of data subjects
- New jurisdictional rights (recourse rights, class action)
- Characteristics of information provided to data subjects
- Module 6: Data transfers outside the EU
- Definition of transfers outside the EU
- The principle of prohibition
- Exemptions (adequate countries, appropriate measures, Article 49)
- Module 7: Ensuring compliance
- The DPO, its appointment
- Its role and duties
- Role and powers of supervisory authorities, composition and mission of the EDPS
- Recourse against data controllers and processors, their responsibilities, and penalties (administrative fines)
- Module 8: Security measures to protect data
- Obligations of data controllers and processors regarding security
- Characteristics of security elements
- Requirements and best practices
- Managing breaches
- Module 9: Achieving compliance
- Actions to take for the company to become compliant, considering national particularities
- Proof of compliance with the regulation
- Governance
- Compliance tools
Conclusion
ASSESSMENT METHODS
Knowledge and skills validated through a quiz at the end of each chapter.
OFFER
For registration to both courses: CIPP/E + CIPM, the price is 3 490€ excluding tax.