Course overview
Since the EU General Data Protection Regulation took effect in May 2018, privacy law has spread across jurisdictions at remarkable speed: California followed with the CCPA and its CPRA amendments, Brazil enacted the LGPD, and dozens of other legislatures have passed statutes borrowing from the same playbook. For any organization that collects personal data across borders, the question is no longer whether these laws apply but how to satisfy several of them at once. This course examines the major data protection regimes as legal instruments: what each statute requires, which supervisory authorities enforce it, what the penalties look like in practice, and where the obligations converge enough to be met with a single set of controls.
The five units move from the statutes themselves to the machinery of compliance. Participants study the GDPR's lawful bases and data subject rights alongside their Californian and Brazilian counterparts, then examine the operational obligations that follow: records of processing activities, transparency notices, processor contracts, and cross-border transfer mechanisms such as adequacy decisions and standard contractual clauses. Accountability structures, including the data protection officer role and privacy by design, receive dedicated treatment, as do data protection impact assessments and the 72-hour breach notification clock. The closing unit turns these elements into a durable, multi-jurisdiction compliance strategy.
Why regulators now set the terms of doing business with personal data
Enforcement has matured from warning letters into penalties measured in the hundreds of millions of euros, and supervisory authorities increasingly coordinate across borders on major cases. At the same time, court decisions have repeatedly redrawn the rules mid-game; the Schrems II judgment invalidated an entire EU-US transfer framework and forced thousands of organizations to renegotiate their transfer arrangements almost overnight. Customers and business partners have noticed: privacy commitments now appear in procurement questionnaires, deal due diligence, and contract negotiations. An organization that cannot explain its lawful bases, produce its processing records, or evidence its breach response readiness is exposed on every one of those fronts, regardless of how good its intentions are.
What you will be able to do afterwards
By the end of the course, participants will be able to:
- Compare GDPR, CCPA/CPRA, and LGPD scope and enforcement
- Determine and document lawful bases under the GDPR
- Operate a data subject rights process within statutory deadlines
- Maintain Article 30 records of processing activities
- Select lawful cross-border transfer mechanisms
- Scope and conduct data protection impact assessments
- Prepare a compliant breach response capability
Course outline
Unit 1: Introduction to global data protection regulations
- GDPR scope, extraterritorial reach, controller-processor split
- CCPA/CPRA and the California Privacy Protection Agency
- Brazil's LGPD and the ANPD
- Shared building blocks and penalty frameworks
Unit 2: Compliance requirements and obligations
- GDPR Article 6 lawful bases and evidencing them
- Data subject and consumer rights compared
- Article 30 records and transparency notices
- Cross-border transfers, SCCs, and Schrems II
Unit 3: Governance and accountability in data protection
- Data protection officer: mandate, independence, reporting
- Privacy by design and default (Article 25)
- Processor management and Article 28 terms
- ISO/IEC 27701 privacy information management
Unit 4: Risk management and incident response
- Data protection impact assessments (Article 35)
- 72-hour notification to authorities (Article 33)
- Communicating breaches to individuals (Article 34)
- Incident readiness and enforcement lessons
Unit 5: Building long-term compliance strategies
- One control set across GDPR, CCPA/CPRA, and LGPD
- Horizon scanning for new statutes and rulings
- Privacy-program maturity models and indicators
- Sustaining budget and executive attention
How the course is delivered
Teaching is built around the public record of enforcement: participants analyze documented supervisory authority decisions and published breach cases through facilitated discussion, tracing what the regulator faulted and what a compliant response would have required. Worked examples show how core artifacts are drafted, from an Article 30 register entry to a breach notification timeline, and guided walkthroughs take the group through selected GDPR provisions clause by clause. Because privacy compliance depends on the internal data discipline beneath it, the sessions also draw connections to Data Governance and Compliance Strategies, EuroQuest's companion course on managing data as an organizational asset.
Who should attend
This course is written for professionals responsible for keeping their organization on the right side of privacy law across one or more jurisdictions.
- Data protection officers and deputies, whether newly appointed or preparing for the role
- Compliance managers and privacy leads coordinating multi-jurisdiction obligations
- In-house legal counsel who advise on data processing, vendor contracts, and transfers
- Information security and IT managers who implement breach response and technical safeguards
- Risk and audit professionals who evaluate privacy controls and regulatory exposure
About EuroQuest International Training
Headquartered in Bratislava and founded in 2015, EuroQuest International Training serves professionals across Europe, the Gulf, and beyond through hubs in Geneva, Paris, Istanbul, and Dubai. Its catalog exceeds 1,000 courses in law, compliance, governance, and management, and more than 15,000 professionals have trained with EuroQuest to date.
Frequently asked questions
Will I receive a recognized privacy certification?
The course does not provide formal certification or a compliance assessment; attendees are issued an attendance certificate from EuroQuest. Participants preparing for external certification exams offered by professional privacy bodies report that the material provides useful grounding, but such credentials must be pursued directly with the issuing organization.
Is the content legal advice for my organization?
It is not. The course is educational and does not constitute legal advice; data protection requirements vary by jurisdiction, and organizations should consult qualified counsel before acting on any specific compliance question. Statutes are examined as subject matter, and EuroQuest has no affiliation with any supervisory authority or standards body mentioned.
My organization operates outside the EU, California, and Brazil. Is the course still relevant?
Yes. The GDPR, CCPA/CPRA, and LGPD serve as reference points because so many newer statutes imitate their structure. The analytical approach taught here, from scoping applicability to harmonizing controls, transfers directly to other regimes, and the sessions leave room to discuss the jurisdictions participants actually face.
Related courses
These EuroQuest courses extend the themes covered here.
- Legal Challenges in the Digital Economy – for the wider body of law affecting digital business beyond privacy
- Ethical AI and Responsible Digital Governance – for the intersection of privacy, AI systems, and responsible technology use
- Corporate Governance and Legal Compliance – for board-level governance duties surrounding regulatory risk
- The Future of Legal Compliance in Global Business – for a forward look at where global compliance obligations are heading
Register for this course
Contact EuroQuest to request upcoming dates and venues for Regulatory Compliance for Data Protection, or ask our team which session location best suits your group. We respond to every inquiry with scheduling options and joining details.
All Course Dates & Locations
27 dates · 17 cities · Oct 2026 – Jul 2027