Data protection officer with compliance officer

The course covers both the fundamentals of current data protection law and technical and organizational data protection measures, as well as efficient data protection management systems and the implementation of a successful audit program. In addition, the course addresses the topic of compliance and demonstrates how appropriate and effective measures can be taken to ensure compliance with all types of regulations within the company, including those related to liability issues.

  • Certificates: Data protection officer" certificate
  • Additional Certificates: Certificate "Data protection officer with TÜV Rheinland-certified qualification"
    Certificate "Data protection auditor with TÜV Rheinland certified qualification"
    Certificate "Compliance Officer with TÜV Rheinland-certified qualification"
  • Examination: Praxisbezogene Projektarbeiten mit Abschlusspräsentationen
    Datenschutzbeauftragte:r mit TÜV Rheinland geprüfter Qualifikation
    Datenschutzauditor:in mit TÜV Rheinland geprüfter Qualifikation
    Compliance Officer mit TÜV Rheinland geprüfter Qualifikation
  • Teaching Times: Full-time
    Monday to Friday from 8:30 a.m. to 3:35 p.m. (in weeks with public holidays from 8:30 a.m. to 5:10 p.m.)
  • Language of Instruction: German
  • Duration: 12 Weeks

Data protection officer with TÜV Rheinland-certified qualification

Data protection in the company - basics (approx. 1 day)

History of data protection and objectives

Structure of the European General Data Protection Regulation

The Federal Data Protection Act - subject matter and objectives

GAP analysis between BDSG and GDPR

Material and geographical areas of application

Definitions of terms


Principles (approx. 1 day)

Principles for the processing of personal data

Legitimate interests

Consent

Transparency requirement

Duty to inform

Special categories of personal data


Rights of data subjects (approx. 1 day)

Rights of data subjects

Right to information

Rectification and erasure

Right to object

Right to data portability

Profiling and direct marketing

Right to lodge a complaint

Restrictions


Responsible persons and processors (approx. 2 days)

Risk analysis and TOM

Privacy by design & default

Order processing

Joint controllers

Register of processing activities (VVT)

Security of processing

Entry, access and access controls

Data protection impact assessment (DPIA)

Data protection officer (appointment, position, tasks)

Code of Conduct

Certification: pre-audit, main audit, post-audit


Other bodies with a data protection function (approx. 0.5 days)

The role of the works council (co-determination)

The DPO and the works council

Basics of social data protection

Basics of employee data protection

Personnel file, data access and information rights


Artificial intelligence (AI) and data protection (approx. 0.5 days)

Presentation of specific AI technologies

and possible applications in the professional environment

Risks and opportunities when using AI, especially in connection with pbD


Transfer of personal data (approx. 2 days)

General principles of natural transfers

Data transfers to third countries

Standard contractual clauses

Supervisory authorities

Responsibilities, tasks, powers


Legal remedies, liability and sanctions (approx. 1 day)

Legal remedies

Liability, fines, sanctions

Special processing situations

Final provisions


Federal Data Protection Act (approx. 1 day)

Scope of application, video surveillance of public areas

Exceptions to the rights of data subjects

DPOs of public and non-public bodies

LDAs, fine regulations, sanctions


IT security and data protection (approx. 3 days)

Network components, storage components (RAID)

Basics of access management

IT security basics

IT baseline protection standards

Risk factors

Improvement options


Further areas of responsibility (approx. 3 days)

Development and operation of a data protection management system and SDM

Deletion concept

Backup concept

The legal framework of outsourcing from a data protection perspective

Data protection in the area of marketing and advertising measures


Telecommunications Digital Services Data Protection Act (approx. 1 day)

Structure and contents of the TDDDG


Project work, certification preparation and certification exam "Data Protection Officer with TÜV Rheinland certified qualification" (approx. 3 days)

Data protection auditor with TÜV Rheinland-certified qualification

Basics (approx. 2 days)

Objectives of data protection audits

Basic knowledge of data protection policy (company objectives, principles of action)

EU-DSGVO

Requirements for internal audits and auditors


Data protection management system (approx. 3 days)

Requirements for setting up a data protection management system

Process models for setting up and introducing a data protection management system

Methods, techniques and tools

As-is recording and analysis, identification of weak points, risk analysis


Artificial intelligence (AI) in the work process

Presentation of specific AI technologies

and possible applications in the professional environment


Standard data protection model (approx. 1 day)

Current status and introduction

SDM implementation and requirements from GDPR

Warranty objectives of the SDM

Generic measures

SDM building blocks


Data protection concept (approx. 2 days)

Relationships to other operational management systems (DIN EN ISO 9000ff., 27001ff.)


Creation of an audit program (approx. 2 days)

Preparation of an audit program

Creation of audit questionnaires

Audit depth


Audit implementation (approx. 4 days)

Interviews as a source of information

Document review on site

Inspection of technical equipment

Examination of the structural and process organization

Examination of technical and organizational security measures

Inspections


Audit evaluation (approx. 3 days)

Evaluation, audit report and follow-up measures

Preparation of an audit report

Tracking of measures

Presentation of possible tools (checklists, questionnaire, audit plans, deviation reports)

Corrective measures


Project work, certification preparation and certification exam "Data protection auditor with TÜV Rheinland certified qualification" (approx. 3 days)

Compliance Officer with TÜV Rheinland-certified qualification

Compliance Basics (approx. 1 day)

Terminology, Significance, and Development of Compliance and Compliance Management

Legal Requirements and Regulatory Framework

Business Judgment Rule

Relevant Standards and Audit Criteria (ISO 37301 and IDW PS 980)

Basic Structure and Content of CMS Models


Compliance Culture (approx. 0.5 days)

The Importance of Corporate Culture 

Role of Corporate Leadership

Values and Integrity Management

Tone from the Top/Tone at the Top

Leadership Commitment and Awareness Building


Compliance Objectives (approx. 0.5 days)

Compliance Objectives and Scope

Connection to Risk Management

Elements of an Effective Compliance Strategy


Compliance Organization (approx. 1 day)

Responsibilities of Company Management

Delegation of Compliance Tasks

Structure and Elements of a CMS

Organizational Structure and Workflows

Roles, Responsibilities, and Reporting Lines


Compliance Officer (approx. 1 day)

Position and Role within the Compliance Organization (Trusted Business Advisor)

Duties and Job Requirements

Rights, Duties, and Liability Risks

Employment Contract, Job Description, Reporting Lines, and Authority to Issue Instructions

Civil and Criminal Liability

Future Prospects for the Role


Compliance Risk Management (approx. 2 days)

Introduction to Compliance Risk Management

Compliance Risk Assessment as an Element of the CMS

National and International Legal Frameworks (ISO 31000)

Terminology, Systematics, and Structural and Operational Organization

Identification of Compliance Risks

Prioritization and Assessment of Risks

Use of Risk Matrices

Risk management through avoidance, mitigation, transfer, and acceptance strategies

Risk monitoring 

Risk reporting and documentation


Compliance Program and Implementation Measures (approx. 1 day)

Introduction and Requirements (ISO 37301, IDW PS 980)

Preventive Measures

Detection Measures

Response Measures

Further Development of the Compliance Program 

Project Management: Implementation and Operation in Compliance Practice


In-Depth Review of Selected Compliance Measures (approx. 1 day)

Regulatory Frameworks: Significance, Design, and Implementation

Training and Compliance Communication

HR Compliance Across Key HR Processes

Employee Data Protection and AI Applications in an HR Context

Business Partner Compliance and Risk-Based Audits


Whistleblower Systems (approx. 1 day)

Classification as a component of the CMS

National and international legal frameworks

Whistleblower Protection Act (HinSchG) 

Establishment of internal reporting offices and reporting channels

Reporting Process, Follow-Up Measures, and Conclusion of the Process

Protection system, protection needs, and limitations

Interfaces with trade secret protection, data protection, and labor law


Compliance Monitoring and Continuous Improvement (approx. 1 day)

Three Lines of Defense

Process-Integrated and Process-Independent Controls

Adequacy and effectiveness assessments

Internal and external audits (ISO 19011)

CMS Certification 

Evaluation Based on KPIs and Indicators

Development and implementation of improvement measures

Compliance reporting


Responses to Compliance Violations and Crisis Situations (approx. 1 day)

Internal Investigations and Measures in the Event of Violations

Sanctions, Liability, and Reporting Requirements

Government investigations and crisis management

Crisis Communication: Principles and Strategies


Antitrust Compliance (approx. 1 day)

European antitrust law under the TFEU and German antitrust law under the GWB

Risks and Consequences of Antitrust Violations

Prohibited Conduct Toward Competitors

Limitations in sales as well as in dealer and supplier relationships

Abuse of dominant market positions

Antitrust Compliance Management System


Corruption Prevention (approx. 1 day)

Fundamentals and Legal Framework

Requirements of ISO 37001

Definition of Corruption and Mechanisms of Its Origin

Corruption Risks in the Company

Monitoring, Prevention, and Best Practices

Establishing an Anti-Corruption Management System


Anti-Money Laundering (approx. 1 day)

Introduction and Typologies

Scope of Application and Obligated Entities

Risk Management and Safeguards

Requirements for Anti-Money Laundering Officers 

Due Diligence Obligations (KYC)

Beneficial Owners, PEPs, and Source of Funds

Suspicious Transactions and Reporting Obligations


Export Control and Export Compliance (approx. 1 day)

The Principle of Free Foreign Trade and Its Restrictions

Legal Basis, Licensing Requirements, and Jurisdictions

Restrictions on goods, end-use, destination countries, and individuals

Sanctions list checks and screenings

Legal Consequences of Violations

Procedures, Oversight, and Internal Compliance Program


Supply Chain Compliance (approx. 1 day)

Background and Fundamentals

Supply Chain Due Diligence Act (LkSG): Definitions and Scope of Application

Protected Legal Positions and Due Diligence Obligations

Policy Statement and Preventive Measures

Legal Consequences and Regulatory Oversight

Outlook: A Comparison of the LkSG and the CSDDD


Data Protection Compliance (approx. 1 day)

GDPR and BDSG

Risk-Based Approach to Data Protection

Data Protection Principles and Legal Bases

Data Subject Rights

Responsibilities, Data Processing, and Data Protection Officer

Technical and Organizational Measures (TOM)

Response to Breaches, Liability, and Sanctions


Project work, certification preparation and certification exam "Compliance Officer with TÜV Rheinland certified qualification" (approx. 3 days)



Changes are possible, the course content is updated regularly.

After completing the course, you will be familiar with the essential tasks in data protection. You will have the necessary knowledge based on the current EU GDPR for the legally compliant handling of personal data as well as knowledge of data protection organization and IT security. You will also have specialist knowledge of an efficient data protection management system and be able to successfully plan, carry out and evaluate data protection audits.

You will also be prepared for your duties as a compliance officer. You know the basics of company law and can thus minimize liability risks. You will also be familiar with the requirements of a compliance management system.

The course is aimed at employees from the areas of human resources, administration, quality management or the legal department.

Knowledge of data protection is not only indispensable in the areas of auditing, quality management, law and organization. The specialist knowledge acquired in this course is of great benefit to all sectors that come into contact with personal data.

The compliance officer's area of responsibility is growing all the time. Companies in the banking and financial services, insurance and service industries are therefore increasingly reliant on their services. Compliance officers are also increasingly sought after in public administrations, associations and some organizations and corporations.

Didactic concept

Your lecturers are highly qualified both professionally and didactically and will teach you from the first to the last day (no self-study system).

You will learn in effective small groups. The courses usually consist of 6 to 25 participants. The general lessons are supplemented by numerous practical exercises in all course modules. The practice phase is an important part of the course, as it is during this time that you process what you have just learned and gain confidence and routine in its application. The final section of the course involves a project, a case study or a final exam.

 

Virtual classroom alfaview®

Lessons take place using modern alfaview® video technology - either from the comfort of your own home or at our premises at Bildungszentrum. The entire course can see each other face-to-face via alfaview®, communicate with each other in lip-sync voice quality and work on joint projects. Of course, you can also see and talk to your connected trainers live at any time and you will be taught by your lecturers in real time for the entire duration of the course. The lessons are not e-learning, but real live face-to-face lessons via video technology.

 

The courses at alfatraining are funded by Agentur für Arbeit and are certified in accordance with the AZAV approval regulation. When submitting a Bildungsgutscheinor Aktivierungs- und Vermittlungsgutschein, the entire course costs are usually covered by your funding body.
Funding is also possible via Europäischen Sozialfonds (ESF), Deutsche Rentenversicherung (DRV) or regional funding programs. As a regular soldier, you have the option of attending further training courses via Berufsförderungsdienst (BFD). Companies can also have their employees qualified via funding from Agentur für Arbeit (Qualifizierungschancengesetz).

We will gladly advise you free of charge.

0800 3456-500 Mon. - Fri. from 8 am to 5 pm
free of charge from all German networks.

Contact

We will gladly advise you free of charge. 0800 3456-500 Mon. - Fri. from 8 am to 5 pm free of charge from all German networks.