Let’s make it work for you
Certified Data Protection Practitioner (GDPR)
From £2,080 + VAT
Interested in this course? Check out when this course is running and get in touch
Overview
This comprehensive practitioner course with independent APMG exam, will provide a practical guide to planning, implementing, and maintaining compliance with Data Protection & GDPR (EU & UK) Regulations. The course contains Data (Use and Access) Act impacts on Data Protection throughout.
Data protection law requires, the appointment of a Data Protection Officer (DPO) for some controllers and processors, including those in the public sector. The obligations for this challenging role will require insight into privacy threats, risks, data breach management, secure design and secure by default principles, artificial intelligence (AI) and privacy compliance and the legal spectrum of the DPA18 & the GDPRs.
This course is suitable for data protection officers, data protection practitioners, HR Professionals, compliance officers, auditors, IT & security Professionals.
Continuous Professional Development (CPD)
CPD points can be claimed for NCSC assured courses at the rate of 1 point per hour of training for NCSC assured courses (up to a maximum of 15 points).
Prerequisites
We advise learners to have some prior practical Data Protection experience, although not essential. Attending the QA Data Protection Foundation (QACDPF) course is recommended but not mandatory.
Target audience
This Data Protection Foundation & Practitioner course is primarily aimed at DPOs and professionals working with IT, Risk, Security, Governance and Compliance roles across public and private sectors. It is also aimed at Human Resource and Marketing Professionals, Product Owners, Business Analysts and Project Managers.
Learning Outcomes
Learn to address new privacy situations by applying acquired knowledge, facts, techniques, and rules learnt from this course.
- Apply the implementation pathway for Data Protection & GDPR compliance
- Data Protection Principles & Individual Rights
- Data Protection Impact Assessments
- Incident Response
- Policy Frameworks
- Privacy by Design / Default
- Information Risk Management
- Understand the role of the data Protection Officer (DPO)
- Understand the impact of the Data (Use and Access) Act on Data Protection
- Develop a plan to address the challenges of developing a privacy programme across your organisation
- Understand the role of Artificial Intelligence (AI) on privacy
- Prepare for managing and reacting to a data breach both from a regulator and commercial perspective
- Identify and understand the rights of data subjects, consent, data in the cloud and third parties
- Model the enforcement aspects of the DPA18 & GDPRs to your organisation
Business outcomes
- Demonstrate understanding of the data protection principles and individual data subject rights and when and how they apply at an operational level.
- Understand why privacy is important, and how it relates to data protection in your business
- Be able to understand the role of the Data Protection Officer, if you need one and how they help your business achieve compliance
- Learn to solve Data Protection (GDPR) problems and advise on privacy risks by applying acquired knowledge, facts, techniques, and rules learnt
- Respond in a more responsible, ethical, and well-informed manner, to GDPR compliance issues and scenarios
- Consider the privacy, ethical and regulatory impact of Artificial Intelligence (AI) and or shadow AI being adopted in your organisation or supply chain
- Adapt your communication style to being one of a knowledgeable, capable Privacy Professional and or Practitioner
- Build effective working relationships by being able to articulate and determine GDPR compliance issues, via the logical interpretation and application of the GDPR Articles and Recitals, to real world and hypothetical work/life scenarios
- Demonstrate good knowledge of the (EU & UK) GDPRs and related legislation
Course Outline
Module 1: Data Protection Management Maturity
By the end of this module, learners will:
- Be able to establish their current level of compliance.
- Be able to conduct a self-assessment and create an improvement plan.
- Understand what data mapping is and why it is used.
- Be able to carry out a data mapping exercise.
Exercise: Accountability Framework and Implementation Plan Document
Module 2: Useful steps to compliance
By the end of this module, learners will be able to:
- Identify useful steps to take to achieve / maintain GDPR compliance.
Module 3: Data Protection by Design, by Default and DPIAs
By the end of this module, learners will:
- Understand what is meant by privacy by design.
- Know what a DPIA is.
- Understand how DPIAs are linked to the risk management approach.
- Understand how data mapping and creating information flows facilitate DPIAs.
- Be familiar with the ICO DPIA template and what the expected outputs of that framework are.
- Understand how DPIAs are used to check for and demonstrate compliance with the principles.
- Understand how DPIAs are used as part of the prior consultation process.
Exercise: DPIA
Module 4: Risk Management, Assurance and Appropriate Security
By the end of this module, learners will:
- Be able to determine what appropriate security is, using a risk-based approach.
- Understand what information assurance is and why an information assurance plan is required.
- Be able to create an information assurance plan.
- Understand what is meant by baseline control sets.
- Be able to implement a baseline control set for personal data.
Exercise: Baseline Control Sets and Risk Assessment for the process
Module 5: Obligations on Controllers and Processors
By the end of this module, learners will:
- Understand the obligations GDPR puts on controllers and processors.
- Understand the impact of the Data (Use and Access) Act 2025.
- Be able to identify ways their organisations can maintain compliance with these obligations.
Exercise: Breach Reporting
Exercise: Subject Access Requests
Module 6: Direct Marketing and Online Profiling
By the end of this module, learners will:
- Understand how the e-privacy review may potentially impact their organisation.
- Understand how the GDPR consent impacts on direct marketing operations.
- Understand the impact of the Data (Use and Access) Act 2025.
- Understand why consent clarification emails may not be legal.
- Understand why GDPR impacts how an organisations website works.
- Understand how GDPR consent applies for cookies and profiling.
Module 7: Transfers to Third Countries
By the end of this module, learners will:
- Understand how transferring data to processors or international organisations is impacted by GDPR.
- Understand what arrangements apply where no safeguards or adequacy agreements exist.
- Understand the impact of the Data (Use and Access) Act 2025.
- Understand international transfers.
Module 8: Privacy & Monitoring
By the end of this module, learners will:
- Be aware of privacy and monitoring aspects relating to GDPR.
- Be able to identify areas where DPIAs are necessary and critical to compliance.
- Be aware of relevant ICO guidance.
Module 9: Information Commission & Staying Compliant
By the end of this module, learners will:
- Understand the impact of the Data (Use and Access) Act 2025.
- Understand the new role of the Information Commission.
- Be aware of different approaches they can take to become and remain compliant.
- Be aware of useful privacy resources.
Exercise: Case Studies
Module 10: AI, Data Protection & Other Laws
By the end of this module, learners will:
- Understand how Data Protection & AI are related.
- Recognise the overlap between Data Protection & AI Governance.
- Explore key areas to consider AI under Data Protection.
- Recognise legislation related to AI & Data Protection.
Module 11: Introduction to AI Governance
By the end of this module, learners will:
- Be aware of AI Governance principles and strategies.
- Understand aims and objectives of EU AI Act.
- Introduction to the EU General Practice AI Code of Practice.
Module 12: Introduction to Privacy impact of Generative AI & AI Agents
By the end of this module, learners will:
- Understand the differences between Generative AI and AI Agents.
- Understand some of the risks and benefits of AI Agents and the privacy impact.
Module 13: Implementing AI Systems and Privacy
By the end of this module, learners will:
- Explore strategies and steps to addressing privacy risk when implementing AI.
Exams and assessments
Learners will be prepared for the independent APMG Data Protection Practitioner exam. The exam is administered separately and is not included as part of the teaching delivery. Exercises, reviews, and scenario-based work support exam readiness throughout the programme.
Hands-on learning
The course includes practical exercises, case studies, and real-world scenario analysis. Learners develop hands-on capability in DPIAs, breach reporting, information assurance planning, international transfers, and applying GDPR requirements.
NCSC Assured Training

Continuous Professional Development (CPD)
CPD points can be claimed for NCSC assured training courses at the rate of 1 point per hour of training for NCSC assured training courses (up to a maximum of 15 points).
Special Notices
This is course is part of the 5 day Certified Data Protection Foundation and Practitioner.
Related courses
Cyber Security learning paths
Want to boost your career in cyber security? Click on the roles below to see QA's learning pathways, specially designed to give you the skills to succeed.
Privacy Professional learning path
Want to boost your career as a Privacy Professional? View QA's learning pathway below, specially designed to give you the skills to succeed.
Frequently asked questions
How can I create an account on myQA.com?
There are a number of ways to create an account. If you are a self-funder, simply select the "Create account" option on the login page.
If you have been booked onto a course by your company, you will receive a confirmation email. From this email, select "Sign into myQA" and you will be taken to the "Create account" page. Complete all of the details and select "Create account".
If you have the booking number you can also go here and select the "I have a booking number" option. Enter the booking reference and your surname. If the details match, you will be taken to the "Create account" page from where you can enter your details and confirm your account.
Find more answers to frequently asked questions in our FAQs: Bookings & Cancellations page.
How do QA’s virtual classroom courses work?
Our virtual classroom courses allow you to access award-winning classroom training, without leaving your home or office. Our learning professionals are specially trained on how to interact with remote attendees and our remote labs ensure all participants can take part in hands-on exercises wherever they are.
We use the WebEx video conferencing platform by Cisco. Before you book, check that you meet the WebEx system requirements and run a test meeting to ensure the software is compatible with your firewall settings. If it doesn’t work, try adjusting your settings or contact your IT department about permitting the website.
How do QA’s online courses work?
QA online courses, also commonly known as distance learning courses or elearning courses, take the form of interactive software designed for individual learning, but you will also have access to full support from our subject-matter experts for the duration of your course.
Once you have purchased the Online course and have completed your registration, you will receive the necessary details to enable you to immediately access it through our e-learning platform and you can start to learn straight away, from any compatible device. Access to the online learning platform is valid for one year from the booking date.
All courses are built around case studies and presented in an engaging format, which includes storytelling elements, video, audio and humour. Every case study is supported by sample documents and a collection of Knowledge Nuggets that provide more in-depth detail on the wider processes.
When will I receive my joining instructions?
Joining instructions for QA courses are sent two weeks prior to the course start date, or immediately if the booking is confirmed within this timeframe. For course bookings made via QA but delivered by a third-party supplier, joining instructions are sent to attendees prior to the training course, but timescales vary depending on each supplier’s terms. Read more FAQs.
When will I receive my certificate?
Certificates of Achievement are issued at the end the course, either as a hard copy or via email. Read more here.
Let's talk
A member of the team will contact you within 4 working hours after submitting the form.