Learning path
GDPR — Data protection
The six blocks of the General Data Protection Regulation, from basic principles to security breach management.
Your progress
It is saved only in this browser on this device: no account needed and nothing leaves your machine. Clear the site data or open it on another device and you start from scratch.
- 1 Principles and lawful bases How to identify the legal basis for each personal data processing activity. Block 1
- 2 Record of processing activities How to keep the record of processing activities required by the GDPR up to date. Block 2
- 3 Data subject rights How to manage requests for access, rectification, erasure, and other data subject rights. Block 3
- 4 Security measures How to apply technical and organizational measures proportional to the processing risk. Block 4
- 5 Data protection impact assessment (DPIA) How to determine when a DPIA is mandatory and how to document it. Block 5
- 6 Security breaches and data processors How to respond to a security breach and control data processors. Block 6
Every GDPR block explained
The GDPR applies to any organization that processes personal data of European citizens, regardless of its size or sector.
This path explains each block with examples of how to document the record of processing activities, data subject rights, and responding to a security breach.
Keep exploring
Related pages
ISO 27001 · Information security
A free learning path on ISO 27001: the information security standard's seven clauses explained with examples…
ENS · National Security Framework
Free learning path on the National Security Framework (ENS): categorization, organizational and operational…
What your IT lead is going to ask
Encryption, access control, an audit log, verified backups, and a data processing agreement that reads…
Learn quality standards and BPM concepts without leaving the platform
Chapter-by-chapter guides on every ISO standard and sector protocol, plus the process management (BPM)…
Sources
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
- Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
- Spanish Data Protection Agency AEPD · Supervisory authority