Chapter Title Min Max Competencies
Origins and
Develeopment of Understand the origins and historival
1 1 3
European Data context of European data protection laws
Protection Law
European Union Understand the roles and functions of
2 1 2
institutions significant EU institutions
Understand the legislative framework
3 Legislative Framework 5 8 underpinning the principles of European
data protection
Understand basic GDPR data protection
4 Data Protection Concepts 3 5
concepts
Territorial and material Understand issues related to the
5 2 4
scope of the GDPR territorial and material scope of the GDPR
Data Processing Understand the principles of European
6 2 4
Principles data processing
Know what constitutes a lawful
7 Lawful Processing Criteria 3 5
processing basis
Information Provision Understand information provisions
8 4 6
Obligations obligations
9 Data Subject Rights 8 12 Understand data subjects' rights
Understand the requirements involved in
10 Security of Personal Data 7 11
maintaining the security of personal data
Accountability Understand the various accountability
11 4 8
Requirements requireents under the GDPR
Understand the principles of, and the
International Data
12 4 6 risks involved in, international data
Transfers
transfers
Understand the European data protection
Supervision and
supervision and enforcement structure;
13 Enforcement; Sanctions 4 6
Understand the consequences for GDPR
and penalties
violations
Understand how to comply with
European data protection laws and
Employment
14 3 5 regulations in the workplace, specifically
Relationships
as they relate to employment
relationships
Understand how to comply with
European data protection laws and
15 Surveillance Activities 1 3
regulations related to surveillance
activities
Understand how to comply with
16 Direct Marketing 2 4 European data protection laws and
regulations related to direct marketing
Understand how to comply with
Internet Technology and European data protection laws and
17 2 4
Communications regulations related to internet technology
and communications
18 Outsourcing
Indicators
- Know the historical rationale for data protection.
- Konw relevant human rights laws and early data protection laws and regulations such as the
OECD Guidelines, The Treaty of Lisbon, and Concention 108, and understand the ways in which
some of these laws have been updated (e.g. Convention 108+).
- Understand how the need for a harmonized European approach to data protection
developed, and know the challenges involved in implementing this approach (e.g. Brexit).
- Know the roles and functions of the European Union institutions such as the Council of
Europe, the European Court of Human Rights, European Parliament, the European Commission,
the European Council and the Court of Justice of the European Union.
- Understand early pieces of data protection legislation, such as the Council of Europe
Convention for the Protection of Individuals with Regard to the Automatic Processing of
Personal Data of 1981 (the CoE Convention), the EU Data Protection Directive (95/46/EC), the
EU Directive on Privacy and Electronic Communications (2002/58/EC) (ePrivacy Directive) — as
amended, and the EU Directive on Electronic Commerce (2000/31/EC).
- Understand the main principles and goals of significant data protection legislation, such as the
General Data Protection Regulation (GDPR) (EU) 2016/679 and related legislation, the NIS/NIS
2 Directives, and the EU Artificial Intelligence Act.
- Know the concepts of personal data, sensitive personal data, and special categories of
personal data.
- Understand the concepts of pseudonymous and anonymous data and the differences
between them.
- Know the key principles of lawful processing.
- Know the concepts of controller and processor, and understand European Data Protection
Board guidelines and opinions on the subject.
- Understand the concept of data subject.
Understand what constitutes establishment and non-establishment in the EU, including
European Data Protection Board guidelines and opinions on the subject.
Understand the GDPR’s scope of processing, as well as the exemptions it allows.
Understand the data processing concepts of fairness and lawfulness, purpose limitation,
proportionality, accuracy, storage limitation (retention), and integrity and confidentiality.
Understand lawful processing bases (consent, contractual necessity, legal obligation/vital
interests/ public interest and legitimate interest), including European Data Protection Board
guidelines and opinions on the subject.
Understand processing of special categories of personal data.
Understand the transparency principle.
Know the key components of privacy notices.
Understand the purpose of layered privacy notices.
- Understand the right of access, including EDPB guidelines and opinions on the subject.
- Understand the right of rectification.
- Understand the right of erasure/the right to be forgotten (RTBF), including EDPB guidelines
and opinions on the subject.
- Understand the rights of restriction and objection.
- Understand the concept of consent, including the right of withdrawal.
- Understand the rights related to automated decision-making, including profiling.
- Understand the right of data portability.
- Know the restrictions on data subjects’ rights and understand the principles regarding them
set forth by EDPB guidelines.
- Understand what appropriate technical and organizational measures are (e.g., protection
mechanisms such as encryption and access controls) and how they should be defined.
- Know what is required for breach notification (e.g., risk reporting requirements), and
understand EDPB guidelines and opinions on the subject.
- Understand the principles of effective and responsible vendor management.
- Know the key principles and requirements of sharing personal data with third parties.
Understand the accountability requirements of controllers, joint controllers and processors,
including those related to data protection by design and by default.
Understand the importance of documentation and cooperation with regulators.
Understand the role of data protection impact assessments (DPIAs) and know the established
criteria for conducting them.
Understand the requirement for mandatory data protection officers
Understand the role that auditing plays in privacy programs.
Understand the rationale for prohibiting transfers, including EDPB guidelines and opinions on
the subject.
Know the concept of adequate jurisdiction. Understand the historical importance of Safe
Harbor and Privacy Shield (including the implications of the Schrems decisions regarding them)
and know the basics of the EU-US Data Privacy Framework.
Understand the content, purpose and use of Standard Contractual Clauses and Binding
Corporate Rules (BCRs).
Understand the role of codes of conduct and certifications, including EDPB guidelines and
opinions on the subject.
Understand the rationale for, and role of, derogations, including EDPB guidelines and opinions
on the subject.
Understand the goal of transfer impact assessments (TIAs), including EDPB guidelines and
opinions on the subject.
Understand the roles and powers of the European Data Protection Board (EDPB) and the
European Data Protection Supervisor (EDPS). Understand the roles and powers of other
supervisory authorities. Understand the concept of lead supervisory authority, including EDPB
guidelines and opinions on the subject.
Know the procedures related to GDPR violations, and the fines that may be imposed as a result
of infringements.
Understand the conditions under which class actions involving GDPR violations may be filed.
Understand the types and amounts of compensation due to data subjects stemming from
GDPR violations
Know the legal basis for processing employee data, the issues related to the storage of
personnel records and the risks involved in handling employee data. Understand the role of,
and the risks involved in, workplace monitoring and data loss prevention. Understand the pros
and cons of bring your own device (BYOD) programs. Understand the role of EU Works Councils
and whistleblowing systems.
Understand the compliance issues related to surveillance conducted by public authorities.
Understand the laws regarding the interception of communications. Understand the
compliance issues related to technologies such as closed-circuit television (CCTV), geolocation
and biometrics/facial recognition, and know European Data Protection Board guidelines and
opinions on the subject.
Understand the compliance issues and requirements related to the processing of personal data
for marketing activities. Understand the compliance issues related to online behavioral
targeting, including EDPB guidelines and opinions on the subject.
Understand the compliance issues related to cloud computing. Understand the compliance
issues related to the use of web cookies. Understand the compliance issues related to social
media platforms (e.g., the use of dark patterns), and know EDPB guidelines and opinions on the
subject. Understand the compliance issues related to search engine marketing (SEM).
Understand the compliance issues and ethical issues related to artificial intelligence (AI),
including machine learning.
Status Karten Qualität
Übersprungen n/a
Übersprungen n/a
Noch nicht begonnen Muss dringend überarbeitet werden!
Abgeschlossen Angepasst
Abgeschlossen Angepasst
Abgeschlossen Angepasst
Abgeschlossen Angepasst
Abgeschlossen Angepasst
Abgeschlossen Angepasst
Abgeschlossen Angepasst
Noch nicht begonnen Angepasst
Noch nicht begonnen Angepasst
Noch nicht begonnen Angepasst
Noch nicht begonnen Angepasst
Übersprungen n/a
Noch nicht begonnen Angepasst
Noch nicht begonnen Angepasst
Übersprungen n/a