Data, Privacy & Compliance
How real companies must handle data: personal vs sensitive data, GDPR principles, retention and deletion, breach reporting, international transfers and audit-ready compliance frameworks.
- 70
Lesson 1
Lesson 1 — What Counts as Personal Data?
Names, emails, IP addresses, exam grades, photos — and why 'sensitive' data has extra rules.
- 80
Lesson 2
Lesson 2 — The Seven Principles and Lawful Basis
Why a company can't just collect data 'because it might be useful one day'.
- 85
Lesson 3
Lesson 3 — The Data Lifecycle: Collect, Store, Retain, Delete
Data has a birth, a working life and a death. Companies get fined for skipping the last part.
- 90
Lesson 4
Lesson 4 — Security Controls and the 72-Hour Breach Clock
Encryption, access control, logging — and exactly what to do in the first three days of a breach.
- 95
Lesson 5
Lesson 5 — Children's Data, Special Categories and Sending Data Abroad
Extra rules for the riskiest data — and what happens when your servers are in another country.
- 100
Lesson 6
Lesson 6 — Frameworks, DPIAs and Surviving an Audit
ISO 27001, PCI DSS, HIPAA, SOC 2 — what they are for and how companies prove they comply.