Privacy and data protection training

My Privacy — Professional GDPR Training

The complete path to build a privacy system that is effective, accountable and demonstrable over time.

Privacy principles applied to daily work: procedures, roles, documents and security measures.

Legal framework

What the GDPR is

The GDPR is EU Regulation 2016/679, the European law governing the processing of personal data of natural persons.

It recognises data protection as a fundamental right, guarantees uniform protection across the European Union and works alongside national laws (in Italy, Legislative Decree 196/2003 as amended by 101/2018).

Privacy is not a one-off task, it is a continuous process.
Fundamental right

Personal data protection is safeguarded by the EU Charter of Fundamental Rights.

Uniform protection

The same directly applicable rules across every member state.

National coordination

The Italian Privacy Code complements the Regulation on specific points.

Continuous process

The privacy system must be maintained, checked and updated every year.

The foundations

The 7 GDPR principles

Every processing activity must comply with all principles at the same time.

1
Lawfulness, fairness and transparency

Process data only on a valid legal basis and inform the data subject clearly.

2
Purpose limitation

Collect data for specified, explicit and legitimate purposes only.

3
Data minimisation

Process only data that is adequate, relevant and limited to what is necessary.

4
Accuracy

Keep data up to date and correct or erase inaccurate data without delay.

5
Storage limitation

Keep data only as long as necessary, following a defined retention plan.

6
Integrity and confidentiality

Ensure appropriate security against unauthorised access, loss and destruction.

7
Accountability

The controller must be able to demonstrate compliance with documents and evidence.

People first

Data subject rights

Every request must be handled through a defined, traceable procedure, normally within 30 days.

  • Access to their data
  • Rectification of inaccurate data
  • Erasure (right to be forgotten)
  • Restriction of processing
  • Data portability
  • Objection to processing
  • No automated decisions without safeguards

Roles and responsibilities

Key GDPR roles

Who does what: appointments, duties and concrete business examples.

Controller

Determines purposes and means of processing and answers for overall compliance.

Duties: Record of processing, notices, appointments, security measures, rights handling.

Example: The company or professional deciding which data to collect and why.

Internal manager

Coordinates a business area under the controller's direction.

Duties: Apply procedures, supervise staff, report issues and incidents.

Example: The head of HR or administration.

External processor

Processes data on behalf of the controller under an Art. 28 contract.

Duties: Adequate guarantees, documented instructions, authorised sub-processors, confidentiality.

Example: Accountant, payroll provider, IT or cloud supplier.

Joint controller

Determines purposes and means together with another controller.

Duties: Joint controllership arrangement setting out roles, duties and contact point.

Example: Two companies running a shared platform or campaign.

Authorised staff

Physically handles data within the instructions received.

Duties: Follow procedures, confidentiality, regular training, report anomalies.

Example: Front desk, technicians, administrative staff.

DPO — Data Protection Officer

Monitors compliance, advises the controller, is the contact point for the authority.

Duties: Independence, expertise, no conflict of interest, reporting.

Example: Mandatory for public bodies, large-scale processing and special categories.

System Administrator

Manages infrastructure, access and technical security of information systems.

Duties: Specific appointment, access logs retained and reviewed, annual audit.

Example: The internal IT technician or supplier managing servers, network and backups.

Organisation

Privacy governance and compliance

The pillars that make the privacy system demonstrable and sustainable.

Record of processing activities

Full map of data, purposes, legal bases, recipients and retention periods.

Privacy org chart

Who decides, who processes, who checks: formalised, up-to-date roles.

Appointments and contracts

Appointments of processors, staff and system administrators; Art. 28 contracts.

Notices and consent

Clear texts and traceable consent collection where consent is the correct basis.

Risk analysis and DPIA

Assessment of risks to people's rights and DPIA where required.

Operational procedures

Data breach, rights handling, retention and secure deletion.

Continuous training

Trained, up-to-date staff: an explicit accountability requirement.

The compliance cycle

  1. 1Map
  2. 2Formalise
  3. 3Protect
  4. 4Train
  5. 5Review

Technical and organisational measures

Data security

Measures appropriate to the risk, applied to both digital and paper.

Strong passwords
Multi-factor authentication (MFA)
Verified backup and recovery
Firewall and network segmentation
Antivirus and updates
Logging and access tracking
Removable media management
Paper document custody

Paper documents: golden rules

  • Clean desk: no unattended documents
  • Cabinets and drawers locked
  • No unauthorised copies and no paper recycling
  • Secure destruction with a shredder

Incident management

Data breach: what to do

72 hours

to notify the supervisory authority from becoming aware of the breach

1
Notify the authority

Within 72 hours, unless the breach is unlikely to result in a risk to rights.

2
Inform the data subject

Without undue delay when the risk is high.

3
Document the incident

Breach register: facts, effects and remedial action taken.

4
Corrective measures

Containment, recovery and actions to prevent recurrence.

Supervision

Supervisory bodies

Italian Data Protection Authority (Garante)
EDPB — European Data Protection Board
Guardia di Finanza — Privacy Unit
National Labour Inspectorate
Judicial authority

Consequences

GDPR fines

up to €20M or 4% of turnover

of total worldwide annual turnover, whichever is higher

Profiling without a valid legal basis
Data subject rights denied or ignored
DPO not appointed where mandatory
Non-EU transfers without safeguards
Security measures inadequate to the risk
Data breach not notified in time

Alongside administrative fines there may be damages, processing bans and criminal liability.

Maintenance

The annual compliance programme

Ten steps to repeat every year to keep the privacy system alive and demonstrable.

  1. 1Overall document review
  2. 2Update of the record of processing
  3. 3Review and renewal of appointments
  4. 4Check of contracts with external processors
  5. 5Review of notices and consent
  6. 6Verification of security measures
  7. 7Update of the risk analysis
  8. 8DPIA for high-risk processing
  9. 9Testing of data breach procedures
  10. 10Staff training and refresh

Who it's for

A path for those who must be genuinely compliant

Companies and SMEs
Professionals and firms
Controllers and managers
Privacy officers and DPOs
Technicians and IT departments

Access the full My Privacy course

Build a privacy system that is solid, documented and audit-ready.

Sede

Via Foscolo, 28
26015 Soresina (CR)
PI 01235350194

Orari

9:00 — 18:00