My Privacy — Professional GDPR Training
The complete path to build a privacy system that is effective, accountable and demonstrable over time.
Privacy principles applied to daily work: procedures, roles, documents and security measures.
Legal framework
What the GDPR is
The GDPR is EU Regulation 2016/679, the European law governing the processing of personal data of natural persons.
It recognises data protection as a fundamental right, guarantees uniform protection across the European Union and works alongside national laws (in Italy, Legislative Decree 196/2003 as amended by 101/2018).
Privacy is not a one-off task, it is a continuous process.
Personal data protection is safeguarded by the EU Charter of Fundamental Rights.
The same directly applicable rules across every member state.
The Italian Privacy Code complements the Regulation on specific points.
The privacy system must be maintained, checked and updated every year.
The foundations
The 7 GDPR principles
Every processing activity must comply with all principles at the same time.
Process data only on a valid legal basis and inform the data subject clearly.
Collect data for specified, explicit and legitimate purposes only.
Process only data that is adequate, relevant and limited to what is necessary.
Keep data up to date and correct or erase inaccurate data without delay.
Keep data only as long as necessary, following a defined retention plan.
Ensure appropriate security against unauthorised access, loss and destruction.
The controller must be able to demonstrate compliance with documents and evidence.
People first
Data subject rights
Every request must be handled through a defined, traceable procedure, normally within 30 days.
- Access to their data
- Rectification of inaccurate data
- Erasure (right to be forgotten)
- Restriction of processing
- Data portability
- Objection to processing
- No automated decisions without safeguards
Roles and responsibilities
Key GDPR roles
Who does what: appointments, duties and concrete business examples.
Determines purposes and means of processing and answers for overall compliance.
Duties: Record of processing, notices, appointments, security measures, rights handling.
Example: The company or professional deciding which data to collect and why.
Coordinates a business area under the controller's direction.
Duties: Apply procedures, supervise staff, report issues and incidents.
Example: The head of HR or administration.
Processes data on behalf of the controller under an Art. 28 contract.
Duties: Adequate guarantees, documented instructions, authorised sub-processors, confidentiality.
Example: Accountant, payroll provider, IT or cloud supplier.
Determines purposes and means together with another controller.
Duties: Joint controllership arrangement setting out roles, duties and contact point.
Example: Two companies running a shared platform or campaign.
Physically handles data within the instructions received.
Duties: Follow procedures, confidentiality, regular training, report anomalies.
Example: Front desk, technicians, administrative staff.
Monitors compliance, advises the controller, is the contact point for the authority.
Duties: Independence, expertise, no conflict of interest, reporting.
Example: Mandatory for public bodies, large-scale processing and special categories.
Manages infrastructure, access and technical security of information systems.
Duties: Specific appointment, access logs retained and reviewed, annual audit.
Example: The internal IT technician or supplier managing servers, network and backups.
Organisation
Privacy governance and compliance
The pillars that make the privacy system demonstrable and sustainable.
Full map of data, purposes, legal bases, recipients and retention periods.
Who decides, who processes, who checks: formalised, up-to-date roles.
Appointments of processors, staff and system administrators; Art. 28 contracts.
Clear texts and traceable consent collection where consent is the correct basis.
Assessment of risks to people's rights and DPIA where required.
Data breach, rights handling, retention and secure deletion.
Trained, up-to-date staff: an explicit accountability requirement.
The compliance cycle
- 1Map
- 2Formalise
- 3Protect
- 4Train
- 5Review
Technical and organisational measures
Data security
Measures appropriate to the risk, applied to both digital and paper.
Paper documents: golden rules
- Clean desk: no unattended documents
- Cabinets and drawers locked
- No unauthorised copies and no paper recycling
- Secure destruction with a shredder
Incident management
Data breach: what to do
72 hours
to notify the supervisory authority from becoming aware of the breach
Within 72 hours, unless the breach is unlikely to result in a risk to rights.
Without undue delay when the risk is high.
Breach register: facts, effects and remedial action taken.
Containment, recovery and actions to prevent recurrence.
Supervision
Supervisory bodies
Consequences
GDPR fines
up to €20M or 4% of turnover
of total worldwide annual turnover, whichever is higher
Alongside administrative fines there may be damages, processing bans and criminal liability.
Maintenance
The annual compliance programme
Ten steps to repeat every year to keep the privacy system alive and demonstrable.
- 1Overall document review
- 2Update of the record of processing
- 3Review and renewal of appointments
- 4Check of contracts with external processors
- 5Review of notices and consent
- 6Verification of security measures
- 7Update of the risk analysis
- 8DPIA for high-risk processing
- 9Testing of data breach procedures
- 10Staff training and refresh
Who it's for
A path for those who must be genuinely compliant
Access the full My Privacy course
Build a privacy system that is solid, documented and audit-ready.