← All courses

Data, Privacy & Compliance

How real companies must handle data: personal vs sensitive data, GDPR principles, retention and deletion, breach reporting, international transfers and audit-ready compliance frameworks.

🟡 Intermediate6 lessons
  1. Lesson 1

    Lesson 1 — What Counts as Personal Data?

    Names, emails, IP addresses, exam grades, photos — and why 'sensitive' data has extra rules.

    70
  2. Lesson 2

    Lesson 2 — The Seven Principles and Lawful Basis

    Why a company can't just collect data 'because it might be useful one day'.

    80
  3. Lesson 3

    Lesson 3 — The Data Lifecycle: Collect, Store, Retain, Delete

    Data has a birth, a working life and a death. Companies get fined for skipping the last part.

    85
  4. Lesson 4

    Lesson 4 — Security Controls and the 72-Hour Breach Clock

    Encryption, access control, logging — and exactly what to do in the first three days of a breach.

    90
  5. Lesson 5

    Lesson 5 — Children's Data, Special Categories and Sending Data Abroad

    Extra rules for the riskiest data — and what happens when your servers are in another country.

    95
  6. Lesson 6

    Lesson 6 — Frameworks, DPIAs and Surviving an Audit

    ISO 27001, PCI DSS, HIPAA, SOC 2 — what they are for and how companies prove they comply.

    100