Level 1: Introduction to Data Protection
25th September 2023 Ideal for junior staff or for annual refresher trainingWho is This Course For?
This course is ideal for employees, volunteers and trustees in junior roles who don’t actively deal with confidential or sensitive personal information.
Staff who have more data protection responsibilities, and those who show a keen interest, should consider enrolling in our Level Two course. This will help your organisation increase its awareness of data risks.
For people with a more hands-on role with data and personal information, we suggest our Level 2 or Level 3 courses.
Why This Course is Important
The collation, storage and processing of people’s personal and sensitive information is heavily regulated.
The responsibilities you have over the personal data you collect and use can be extremely complex with a need to consider the data you control on a wide range of individuals. These include trustees, paid staff, donors, service users, volunteers, partner agencies and government officials.
Data breaches can result (and have resulted) in huge fines and levies being enforced on companies and organisations.
It isn’t only fines your organisation needs to worry about. The loss of brand trust, customer loyalty and potential fall in share prices can have an even bigger financial impact than the fines themselves.
This engaging course empowers learners with basic data protection knowledge, thereby protecting data subjects, the organisation and yourself.
Additional bespoke modules tailored to your specific organisation can be created.
Course Overview
This certified course will give individuals a strong understanding of data protection.
Most people within an organisation come across data of some kind. This online e-learning course will give everyone within your organisation the basic understanding of data protection and fulfil your legal obligations under the UK GDPR.
The course is delivered online through pre-recorded animated video and should take 2 – 2.5 hours to complete.
What You’ll Learn
- The basics of data protection and the need for protection
- The key definitions used when talking about data protection
- The differences between personal and special category (sensitive) data
- The laws around collecting, controlling, and processing personal and sensitive data
- The obligations you have as a data controller
- What rights people have over the data you keep on them
- Your responsibility to keep data safe and secure and how you can do it
- How to avoid data breaches and what to do if you have one
- Role of data protection regulators or supervisory authorities
- Levels of sanctions, fines, and enforcement action in the event of a data breach
- Real life examples of organisations being sanctioned
Benefits:
- Strengthen brand and client trust
Build trust with current and future clients, assuring that their data is safe and used properly. - Protect your organisation
Keep your organisation safe from fines and sanctions and loss of client trust. - Empower your team with knowledge
Improve their confidence when dealing with personal information. - Enhance professional development
Data protection is now a legal necessity in most job roles, it’s an important skill to acquire. - Complies with GDPR training obligations
Designed to enable organisations to comply with their GDPR training obligations
Course Content
Part 1: Introduction
- Why the Need for Data Protection – Learn how advancements in technologies and the way organisations harvest and store data have created the need for greater protection over personal data.
- What Data is Processed by Your Organisation? – Consider what types and how much personal information your business or organisation collects and stores.
- What PII Did You Identify? – Learn all the types of information you organisation and potential suppliers might capture, store and control.
- Revision Quiz – 4 questions
Part 2: Definitions & Actors
- Data Protection Actors – Learn about the different definitions used in data protection law and legislation, who the ‘actors’ are and what they do.
- Revision Quiz – Interactive activity
Part 3: Data Protection Overview
- Introduction
- What is Personal Information? – Learn how legislation defines the terms ‘personal data’ or ‘personal information’.
- Does GDPR Apply to All of These People) – Take a little quiz to see if you can identify who is classed as an individual. Learn why the names of these individuals are, or aren’t classed as personal data, and how this might change.
- The Definition of an Organisation – Understand who or what an organization is in the context of data protection.
- The spirit of the legislation – Learn why data protection legislation was created and what it says about how organisations must treat and protect the data they collect.
- Revision Quiz – 3 Questions
Part 4: Controller Obligations
- Transparency – Lean about your obligations as a data controller to be transparent about the data you collect, how you’ll store it, and how you’ll use it.
- Data Accuracy – Understand the importance of keeping accurate data and things that can go wrong if personal data is inaccurate.
- Controller vs. DPO Obligations – Discover the difference between the data controller and the data protection officer, who is responsible for what.
- Data Retention – Learn how long you should keep personal data for and when you should delete it.
- Excessive Data Collection – Different businesses or organisations need to collect different amounts of data. Learn how much data is too much.
- Data Adequacy – Understand the types of data and how much data is needed, necessary, or relevant to offer services to individuals.
- Subject Access Requests – Learn what Subject Access Requests are, and what you should do if an individual requests access to the data you store on them.
- Subject Access Request Channels – Learn all the ways that individuals can submit a Subject Access Request.
- Subject Access Request Procedure – Understand the procedure you must follow when someone submits a Subject Access Request, and the time limits you must adhere to.
- International Transfers – Learn when the European Commission forbids the international transfer of personal data and what you must do to stay compliant.
- Revision Quiz – 8 questions
Part 5: The Rights of Data Subjects
- The Rights to be Informed – Learn about the 9 rights you have as a data subject when an organisation has your personal data. This includes the right to claim compensation.
- Revision Quiz – 6 questions
Part 6: Security
- CRMs – A brief overview about who is responsible for personal data stored in customer relationship management systems.
- CRM Considerations – Things to consider when choosing or using a CRM system, like access control, audit trails and records of consent.
- Data transfers – Understand how personal data reaches your organisation, the type of data it contains, where it is stored and who might see it, and what might happen if that data gets intercepted or stolen.
- Password Security – Learn how important password security is, simple tips when choosing a password that potential hackers can’t crack and how to keep your passwords safe.
- Emails and the Web – Learn how to keep personal data safe from malicious files when using emails and the web and how you might get caught out.
- What is Malware – Discover what Malware is and how hackers use it to infect your systems, including examples of high profile attacks.
- Other Measures You Can Take – Other things you can do to protect your business from data breaches.
- Email Best Practices – Learn how to keep emails safe and things you can do to minimize the risks of sending personal and sensitive information to the wrong recipients.
- Revision Quiz – 5 questions
Part 7: Sanctions & Penalties
- Introduction to UK & EU Sanctions – The responsibilities that data controllers have to protect personal data of EU citizens, no matter which country they’re based in, and how different jurisdictions have one or more regulators.
- EU Maximum Fine – Learn the maximum fine the EU can enforce on an organisation for both fundamental and technical breaches of data protection regulations.
- UK Maximum Fine – Learn the maximum fines the UK can place on organisations who breach data protection legislation.
- Liability – Discover who is liable for fines and/or compensation when data protection regulations are breached. These can also include criminal convictions against individuals.
- Real Life Examples – Learn about real life examples of data protection breaches that have happened and how different types of breaches result in different sanctions.
- Electronic Marketing – Learn about the fines you could face under the EU’s EPrivacy Directive when conducting unlawful electronic marketing activities and what you can do to remain compliant.
- Revision Quiz – 5 questions
Part 8: Course Assessment
- Guidance For Final Assessment – Advice on what to expect in the final assessment and some hints and tips to get the best results.
- Course Assessment – 20 questions.
- Course Certificate - download your certificate.