GDPR Compliance
Go deep on GDPR: what the EU regulation requires, what counts as personal data and whether you're a controller or processor, lawful basis and data-subject rights, your core obligations (RoPA, DPIAs, DPAs, DPO), breach notification and accountability, and international transfers. The data-privacy deep-dive spoke — take it after the Compliance Frameworks hub. Educational, not legal advice.
"We know our lawful bases, we can honor a deletion request, our RoPA is current, and we have a 72-hour breach plan — GDPR as a running program"
6 Interactive Sessions
Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.
- 1
What GDPR actually is — and who it reaches
GDPR is an EU law protecting the personal data of people in the EU — and its reach follows those people across borders, so a US company with EU customers is in scope.
- 2
Personal data, roles & scope — know what you hold and who you are
GDPR follows the personal data: know what counts as personal data, whether you're a controller or a processor, and where that data flows.
- 3
Lawful basis & data-subject rights
GDPR has two halves: you must have a valid lawful basis BEFORE you process personal data, and individuals have concrete rights over the data you hold — including the right to have it erased.
- 4
Your core obligations — accountability made operational
GDPR accountability isn't a privacy policy on your website — it's a set of operational obligations: know your data (RoPA), build privacy in, assess high-risk work (DPIA), contract your processors (DPAs), and be transparent.
- 5
Breach notification & accountability — the clock and the proof
When personal data is breached you generally report to the supervisory authority without undue delay (where feasible, within ~72 hours) if it risks people — and accountability means you must be able to DEMONSTRATE compliance, not just claim it.
- 6
Staying compliant
GDPR is a continuous program, not a launch-day project: you keep the RoPA, lawful bases, rights, DPIAs, transfers and training current — and if you move EU data across borders, you need a valid transfer mechanism.
Production patterns you'll master
Synthetic data included
- Personal-data examples
- The six lawful bases
- Data-subject rights
- Core obligations (RoPA/DPIA/DPO/DPA)
What you walk away with
Shareable portfolio
A public URL showing your module timeline, patterns mastered, and completion status.
All the code
Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.
Module walkthrough
Each module documented with deliverables and the production pattern you implemented.
Ready to build your gdpr compliance?
First course free. $20 per course after that.