The course covers both the fundamentals of current data protection law and technical and organizational data protection measures, as well as efficient data protection management systems and the implementation of a successful audit program. In addition, the course addresses the topic of compliance and demonstrates how appropriate and effective measures can be taken to ensure compliance with all types of regulations within the company, including those related to liability issues.
-
Certificates: Data protection officer" certificate
-
Additional Certificates: Certificate "Data protection officer with TÜV Rheinland-certified qualification"
Certificate "Data protection auditor with TÜV Rheinland certified qualification"
Certificate "Compliance Officer with TÜV Rheinland-certified qualification" -
Examination: Praxisbezogene Projektarbeiten mit Abschlusspräsentationen
Datenschutzbeauftragte:r mit TÜV Rheinland geprüfter Qualifikation
Datenschutzauditor:in mit TÜV Rheinland geprüfter Qualifikation
Compliance Officer mit TÜV Rheinland geprüfter Qualifikation -
Teaching Times: Full-timeMonday to Friday from 8:30 a.m. to 3:35 p.m. (in weeks with public holidays from 8:30 a.m. to 5:10 p.m.)
-
Language of Instruction: German
-
Duration: 12 Weeks
Data protection officer with TÜV Rheinland-certified qualification
Data protection in the company - basics (approx. 1 day)
History of data protection and objectives
Structure of the European General Data Protection Regulation
The Federal Data Protection Act - subject matter and objectives
GAP analysis between BDSG and GDPR
Material and geographical areas of application
Definitions of terms
Principles (approx. 1 day)
Principles for the processing of personal data
Legitimate interests
Consent
Transparency requirement
Duty to inform
Special categories of personal data
Rights of data subjects (approx. 1 day)
Rights of data subjects
Right to information
Rectification and erasure
Right to object
Right to data portability
Profiling and direct marketing
Right to lodge a complaint
Restrictions
Responsible persons and processors (approx. 2 days)
Risk analysis and TOM
Privacy by design & default
Order processing
Joint controllers
Register of processing activities (VVT)
Security of processing
Entry, access and access controls
Data protection impact assessment (DPIA)
Data protection officer (appointment, position, tasks)
Code of Conduct
Certification: pre-audit, main audit, post-audit
Other bodies with a data protection function (approx. 0.5 days)
The role of the works council (co-determination)
The DPO and the works council
Basics of social data protection
Basics of employee data protection
Personnel file, data access and information rights
Artificial intelligence (AI) and data protection (approx. 0.5 days)
Presentation of specific AI technologies
and possible applications in the professional environment
Risks and opportunities when using AI, especially in connection with pbD
Transfer of personal data (approx. 2 days)
General principles of natural transfers
Data transfers to third countries
Standard contractual clauses
Supervisory authorities
Responsibilities, tasks, powers
Legal remedies, liability and sanctions (approx. 1 day)
Legal remedies
Liability, fines, sanctions
Special processing situations
Final provisions
Federal Data Protection Act (approx. 1 day)
Scope of application, video surveillance of public areas
Exceptions to the rights of data subjects
DPOs of public and non-public bodies
LDAs, fine regulations, sanctions
IT security and data protection (approx. 3 days)
Network components, storage components (RAID)
Basics of access management
IT security basics
IT baseline protection standards
Risk factors
Improvement options
Further areas of responsibility (approx. 3 days)
Development and operation of a data protection management system and SDM
Deletion concept
Backup concept
The legal framework of outsourcing from a data protection perspective
Data protection in the area of marketing and advertising measures
Telecommunications Digital Services Data Protection Act (approx. 1 day)
Structure and contents of the TDDDG
Project work, certification preparation and certification exam "Data Protection Officer with TÜV Rheinland certified qualification" (approx. 3 days)
Data protection auditor with TÜV Rheinland-certified qualification
Basics (approx. 2 days)
Objectives of data protection audits
Basic knowledge of data protection policy (company objectives, principles of action)
EU-DSGVO
Requirements for internal audits and auditors
Data protection management system (approx. 3 days)
Requirements for setting up a data protection management system
Process models for setting up and introducing a data protection management system
Methods, techniques and tools
As-is recording and analysis, identification of weak points, risk analysis
Artificial intelligence (AI) in the work process
Presentation of specific AI technologies
and possible applications in the professional environment
Standard data protection model (approx. 1 day)
Current status and introduction
SDM implementation and requirements from GDPR
Warranty objectives of the SDM
Generic measures
SDM building blocks
Data protection concept (approx. 2 days)
Relationships to other operational management systems (DIN EN ISO 9000ff., 27001ff.)
Creation of an audit program (approx. 2 days)
Preparation of an audit program
Creation of audit questionnaires
Audit depth
Audit implementation (approx. 4 days)
Interviews as a source of information
Document review on site
Inspection of technical equipment
Examination of the structural and process organization
Examination of technical and organizational security measures
Inspections
Audit evaluation (approx. 3 days)
Evaluation, audit report and follow-up measures
Preparation of an audit report
Tracking of measures
Presentation of possible tools (checklists, questionnaire, audit plans, deviation reports)
Corrective measures
Project work, certification preparation and certification exam "Data protection auditor with TÜV Rheinland certified qualification" (approx. 3 days)
Compliance Officer with TÜV Rheinland-certified qualification
Compliance Basics (approx. 1 day)
Terminology, Significance, and Development of Compliance and Compliance Management
Legal Requirements and Regulatory Framework
Business Judgment Rule
Relevant Standards and Audit Criteria (ISO 37301 and IDW PS 980)
Basic Structure and Content of CMS Models
Compliance Culture (approx. 0.5 days)
The Importance of Corporate Culture
Role of Corporate Leadership
Values and Integrity Management
Tone from the Top/Tone at the Top
Leadership Commitment and Awareness Building
Compliance Objectives (approx. 0.5 days)
Compliance Objectives and Scope
Connection to Risk Management
Elements of an Effective Compliance Strategy
Compliance Organization (approx. 1 day)
Responsibilities of Company Management
Delegation of Compliance Tasks
Structure and Elements of a CMS
Organizational Structure and Workflows
Roles, Responsibilities, and Reporting Lines
Compliance Officer (approx. 1 day)
Position and Role within the Compliance Organization (Trusted Business Advisor)
Duties and Job Requirements
Rights, Duties, and Liability Risks
Employment Contract, Job Description, Reporting Lines, and Authority to Issue Instructions
Civil and Criminal Liability
Future Prospects for the Role
Compliance Risk Management (approx. 2 days)
Introduction to Compliance Risk Management
Compliance Risk Assessment as an Element of the CMS
National and International Legal Frameworks (ISO 31000)
Terminology, Systematics, and Structural and Operational Organization
Identification of Compliance Risks
Prioritization and Assessment of Risks
Use of Risk Matrices
Risk management through avoidance, mitigation, transfer, and acceptance strategies
Risk monitoring
Risk reporting and documentation
Compliance Program and Implementation Measures (approx. 1 day)
Introduction and Requirements (ISO 37301, IDW PS 980)
Preventive Measures
Detection Measures
Response Measures
Further Development of the Compliance Program
Project Management: Implementation and Operation in Compliance Practice
In-Depth Review of Selected Compliance Measures (approx. 1 day)
Regulatory Frameworks: Significance, Design, and Implementation
Training and Compliance Communication
HR Compliance Across Key HR Processes
Employee Data Protection and AI Applications in an HR Context
Business Partner Compliance and Risk-Based Audits
Whistleblower Systems (approx. 1 day)
Classification as a component of the CMS
National and international legal frameworks
Whistleblower Protection Act (HinSchG)
Establishment of internal reporting offices and reporting channels
Reporting Process, Follow-Up Measures, and Conclusion of the Process
Protection system, protection needs, and limitations
Interfaces with trade secret protection, data protection, and labor law
Compliance Monitoring and Continuous Improvement (approx. 1 day)
Three Lines of Defense
Process-Integrated and Process-Independent Controls
Adequacy and effectiveness assessments
Internal and external audits (ISO 19011)
CMS Certification
Evaluation Based on KPIs and Indicators
Development and implementation of improvement measures
Compliance reporting
Responses to Compliance Violations and Crisis Situations (approx. 1 day)
Internal Investigations and Measures in the Event of Violations
Sanctions, Liability, and Reporting Requirements
Government investigations and crisis management
Crisis Communication: Principles and Strategies
Antitrust Compliance (approx. 1 day)
European antitrust law under the TFEU and German antitrust law under the GWB
Risks and Consequences of Antitrust Violations
Prohibited Conduct Toward Competitors
Limitations in sales as well as in dealer and supplier relationships
Abuse of dominant market positions
Antitrust Compliance Management System
Corruption Prevention (approx. 1 day)
Fundamentals and Legal Framework
Requirements of ISO 37001
Definition of Corruption and Mechanisms of Its Origin
Corruption Risks in the Company
Monitoring, Prevention, and Best Practices
Establishing an Anti-Corruption Management System
Anti-Money Laundering (approx. 1 day)
Introduction and Typologies
Scope of Application and Obligated Entities
Risk Management and Safeguards
Requirements for Anti-Money Laundering Officers
Due Diligence Obligations (KYC)
Beneficial Owners, PEPs, and Source of Funds
Suspicious Transactions and Reporting Obligations
Export Control and Export Compliance (approx. 1 day)
The Principle of Free Foreign Trade and Its Restrictions
Legal Basis, Licensing Requirements, and Jurisdictions
Restrictions on goods, end-use, destination countries, and individuals
Sanctions list checks and screenings
Legal Consequences of Violations
Procedures, Oversight, and Internal Compliance Program
Supply Chain Compliance (approx. 1 day)
Background and Fundamentals
Supply Chain Due Diligence Act (LkSG): Definitions and Scope of Application
Protected Legal Positions and Due Diligence Obligations
Policy Statement and Preventive Measures
Legal Consequences and Regulatory Oversight
Outlook: A Comparison of the LkSG and the CSDDD
Data Protection Compliance (approx. 1 day)
GDPR and BDSG
Risk-Based Approach to Data Protection
Data Protection Principles and Legal Bases
Data Subject Rights
Responsibilities, Data Processing, and Data Protection Officer
Technical and Organizational Measures (TOM)
Response to Breaches, Liability, and Sanctions
Project work, certification preparation and certification exam "Compliance Officer with TÜV Rheinland certified qualification" (approx. 3 days)
Changes are possible, the course content is updated regularly.
After completing the course, you will be familiar with the essential tasks in data protection. You will have the necessary knowledge based on the current EU GDPR for the legally compliant handling of personal data as well as knowledge of data protection organization and IT security. You will also have specialist knowledge of an efficient data protection management system and be able to successfully plan, carry out and evaluate data protection audits.
You will also be prepared for your duties as a compliance officer. You know the basics of company law and can thus minimize liability risks. You will also be familiar with the requirements of a compliance management system.
The course is aimed at employees from the areas of human resources, administration, quality management or the legal department.
The compliance officer's area of responsibility is growing all the time. Companies in the banking and financial services, insurance and service industries are therefore increasingly reliant on their services. Compliance officers are also increasingly sought after in public administrations, associations and some organizations and corporations.
Didactic concept
Your lecturers are highly qualified both professionally and didactically and will teach you from the first to the last day (no self-study system).
You will learn in effective small groups. The courses usually consist of 6 to 25 participants. The general lessons are supplemented by numerous practical exercises in all course modules. The practice phase is an important part of the course, as it is during this time that you process what you have just learned and gain confidence and routine in its application. The final section of the course involves a project, a case study or a final exam.
Virtual classroom alfaview®
Lessons take place using modern alfaview® video technology - either from the comfort of your own home or at our premises at Bildungszentrum. The entire course can see each other face-to-face via alfaview®, communicate with each other in lip-sync voice quality and work on joint projects. Of course, you can also see and talk to your connected trainers live at any time and you will be taught by your lecturers in real time for the entire duration of the course. The lessons are not e-learning, but real live face-to-face lessons via video technology.
The courses at alfatraining are funded by Agentur für Arbeit and are certified in accordance with the AZAV approval regulation. When submitting a Bildungsgutscheinor Aktivierungs- und Vermittlungsgutschein, the entire course costs are usually covered by your funding body.
Funding is also possible via Europäischen Sozialfonds (ESF), Deutsche Rentenversicherung (DRV) or regional funding programs. As a regular soldier, you have the option of attending further training courses via Berufsförderungsdienst (BFD). Companies can also have their employees qualified via funding from Agentur für Arbeit (Qualifizierungschancengesetz).