Tranchulas

European Data Protection and GDPR Practitioner Training Course

An intensive three-day European data protection programme for people who make privacy decisions in the real world — advising product teams, negotiating supplier contracts, answering rights requests, reviewing incidents and challenging assumptions in project meetings.

About the Course

The GDPR did not change in 2018 and stop. The instruments that now decide a European privacy answer — the EU AI Act, NIS2, the EU–US Data Privacy Framework, renewed UK adequacy and a decade of CJEU judgments — mostly arrived afterwards, and several more land inside the next two years.

This intensive three-day programme is built for the moment a decision has to be made and defended: when a product team wants an answer today, a supplier will not disclose where its engineers sit, or a regulator asks why an organisation considered something acceptable. Every module keeps legal requirement, regulatory interpretation and good practice distinct, because collapsing those three is the most common way a confident answer turns out to be indefensible.

  • Globe
    Applied Judgment, Not Recall
    • Work through twelve modules of real advisory fact patterns
    • Practise on scenarios that deliberately withhold material facts
    • Learn to name what must be established, documented or escalated before advising
    • Defend a position against challenge the way a regulator would test it
  • Brain
    Intensive 3-Day Format
    • Twelve applied modules across three focused days
    • Nine landmark CJEU and ECtHR judgments taught as working tools
    • A 40-question applied assessment with structured debrief
  • Target2
    Current to the 2027 Horizon
    • EU AI Act application dates and the AI Omnibus deferrals
    • The Digital Omnibus proposals to amend the GDPR itself
    • NIS2, adequacy and cross-border enforcement reform
    • Every time-sensitive point carries a recheck trigger and a named source

Twelve applied modules across three focused days, each ending in a decision point or scenario lab where the material facts are deliberately incomplete. The same five case organisations recur throughout, so a role decision taken on day one constrains the transfer analysis on day two and the incident response on day three.

Proven Legacy
Day 1: Legal Foundations, Scope, Roles and Lawful Processing

Establish which legal regime governs before analysing anything else, then classify the data and the roles correctly and choose a lawful basis you can evidence. Day one sets the discipline the rest of the course depends on: separate the Council of Europe from the European Union, the ECtHR from the CJEU, and a contract label from a factual role.

Applied Focus: Work the Breyer, Fashion ID and Meta Platforms judgments as working tools. Determine whether a coded customer dataset can be released as anonymous, allocate roles across a co-branded campaign and a hosted SaaS platform, and build a defensible lawful-basis record for a fraud-detection model.

Key Learning Areas:

  • Building a source hierarchy: primary law, court authority, regulator guidance
  • Material and territorial scope, establishment, targeting and monitoring
  • Identifiability, pseudonymisation and genuine anonymisation
  • Controller, joint-controller and processor roles decided by activity
  • Article 5 as a design test and the six Article 6 lawful bases
  • Structured legitimate-interests assessments and the Article 9 two-stage analysis
Gears
Day 2: Rights, International Transfers, Workforce and Marketing

Make individual rights operational, move data across borders defensibly, and hold the line in the two places where practice is most local and most contested: the workplace and the marketing stack. Day two is where a weak data inventory becomes visible to the outside world.

Applied Focus: SCHUFA, Schrems II, Bărbulescu v Romania and Planet49. Operate a rights request from receipt to documented response, build a transfer file for a third-country support model, test a workplace monitoring proposal for proportionality, and audit a cookie banner and a purchased marketing list.

Key Learning Areas:

  • Transparency, access, erasure, restriction, portability and objection in practice
  • Profiling distinguished from Article 22 automated decisions
  • Mapping transfers including remote and administrator access
  • Adequacy, SCC module selection, transfer impact assessment and Article 49 limits
  • Monitoring, BYOD, CCTV, location tracking and biometrics under national labour law
  • ePrivacy, terminal-equipment rules and deceptive consent design
Integration
Day 3: Technology, Security, Governance and Enforcement

Take the analysis into cloud and AI deployments, security incidents, the governance evidence a regulator will actually accept, and the regulator’s inbox itself. Day three closes with the applied assessment and a structured debrief.

Applied Focus: Natsionalna agentsia za prihodite and Österreichische Post. Run a pre-procurement review of a generative-AI vendor, take a ransomware incident to a documented notification decision, rebuild a records-of-processing entry, and prepare a first response plan to a cross-border complaint.

Key Learning Areas:

  • Separating hosting, telemetry, prompts and model improvement as distinct purposes
  • Article 22 in AI deployments and meaningful human involvement
  • The GDPR and EU AI Act boundary, and where NIS2 reporting differs
  • Article 32 measured against risk; Article 33 and 34 breach thresholds
  • Records, retention governance, privacy by default and usable DPIAs
  • Supervisory powers, the one-stop shop, Article 82 damages and Article 83 criteria

Professional Capabilities

Participants leave able to reach a defensible position on the privacy questions their organisation actually faces, and to show the reasoning behind it — to a colleague, a customer or a supervisory authority.

Assesment

Scope and Role Determination

Establish whether the GDPR reaches a processing activity at all, classify the data honestly, and allocate controller, joint-controller and processor roles from what each party actually decides rather than from the contract label.

Security

Lawful Basis and Rights Operations

Select and document a lawful basis that survives challenge, run structured legitimate-interests and Article 9 analyses, and operate individual rights requests from receipt to documented response within statutory deadlines.

CloudOps Security Management

Transfers, Cloud and AI Deployment

Map transfers including remote and administrator access, choose Chapter V mechanisms with effective supplementary measures, and analyse cloud and AI deployments across roles, purposes and the EU AI Act boundary.

Compliance

Incident Response and Accountability

Classify personal-data breaches against the Article 33 and 34 thresholds, build records, retention governance and usable DPIAs, and prepare an evidence-based response to a supervisory authority inquiry.

Upcoming Training Dates