← All courses
$20

GDPR Compliance

Go deep on GDPR: what the EU regulation requires, what counts as personal data and whether you're a controller or processor, lawful basis and data-subject rights, your core obligations (RoPA, DPIAs, DPAs, DPO), breach notification and accountability, and international transfers. The data-privacy deep-dive spoke — take it after the Compliance Frameworks hub. Educational, not legal advice.

"We know our lawful bases, we can honor a deletion request, our RoPA is current, and we have a 72-hour breach plan — GDPR as a running program"

6 Interactive Sessions

Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.

  1. 1

    What GDPR actually is — and who it reaches

    GDPR is an EU law protecting the personal data of people in the EU — and its reach follows those people across borders, so a US company with EU customers is in scope.

  2. 2

    Personal data, roles & scope — know what you hold and who you are

    GDPR follows the personal data: know what counts as personal data, whether you're a controller or a processor, and where that data flows.

  3. 3

    Lawful basis & data-subject rights

    GDPR has two halves: you must have a valid lawful basis BEFORE you process personal data, and individuals have concrete rights over the data you hold — including the right to have it erased.

  4. 4

    Your core obligations — accountability made operational

    GDPR accountability isn't a privacy policy on your website — it's a set of operational obligations: know your data (RoPA), build privacy in, assess high-risk work (DPIA), contract your processors (DPAs), and be transparent.

  5. 5

    Breach notification & accountability — the clock and the proof

    When personal data is breached you generally report to the supervisory authority without undue delay (where feasible, within ~72 hours) if it risks people — and accountability means you must be able to DEMONSTRATE compliance, not just claim it.

  6. 6

    Staying compliant

    GDPR is a continuous program, not a launch-day project: you keep the RoPA, lawful bases, rights, DPIAs, transfers and training current — and if you move EU data across borders, you need a valid transfer mechanism.

Production patterns you'll master

Personal Data & RolesLawful BasisData-Subject RightsRoPA & DPIABreach NotificationInternational Transfers

Synthetic data included

  • Personal-data examples
  • The six lawful bases
  • Data-subject rights
  • Core obligations (RoPA/DPIA/DPO/DPA)

What you walk away with

Shareable portfolio

A public URL showing your module timeline, patterns mastered, and completion status.

All the code

Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.

Module walkthrough

Each module documented with deliverables and the production pattern you implemented.

Ready to build your gdpr compliance?

First course free. $20 per course after that.