Description

Data Protection Officer: Mapping, Advising and Steering Compliance

Take on the data protection officer role and actually perform it day to day

  • 5 days — 35 h
  • In-person or virtual
  • Foundation
  • Up to 6 participants

Appointing a data protection officer is not enough on its own. The record of processing activities stays incomplete, processor contracts are left unframed, data subject requests arrive with no procedure in place and a personal data breach is handled through improvisation. Business teams launch their projects without involving the function.

Five days to hold the post: roles and responsibilities, building the processing register, lawful bases and retention periods, data protection by design, impact assessments, data subject rights, incident handling and steering the compliance plan. All work is based on the participants' own processing activities.

Learning objectives

  • Position the core data protection principles and the role of each stakeholder
  • Maintain and update the record of processing activities
  • Determine the lawful basis and retention period for a processing activity
  • Conduct a data protection impact assessment
  • Organise the handling of data subject rights requests
  • Manage a personal data breach and document the measures taken

What makes this programme different

The processing register is built on the participant's own real activities
An impact assessment is carried out end to end on a sensitive processing activity
A six-month compliance roadmap is drafted during the programme

Programme

1Framework and Stakeholders in Data Protection

Knowing who answers for what

  • Identify the principles applicable to personal data processing
  • Distinguish between controller and processor
  • Position the missions and independence of the data protection officer
  • Position the function in relation to executive management and business teams

2Data Mapping and the Processing Register

Starting from real processing activities

  • Survey processing activities with the business teams
  • Complete the register and keep it up to date
  • Determine the lawful basis for each processing activity
  • Set retention periods and organise data purges
  • Document recipients and cross-border transfers

3Data Protection by Design

Embedding compliance into projects

  • Apply data minimisation and purpose limitation
  • Draft a clear privacy notice
  • Frame the relationship with processors contractually
  • Conduct an impact assessment and arbitrate on mitigation measures
  • Support an IT project from the scoping stage onwards

4Data Subject Rights and Incidents

Responding without improvising

  • Organise the intake of data subject rights requests
  • Process an access or erasure request
  • Qualify a personal data breach
  • Build the incident management procedure
  • Document the decisions taken

5Steering Compliance

Keeping the programme alive

  • Build a prioritised compliance roadmap
  • Raise awareness and train the teams
  • Conduct an internal compliance audit
  • Report to executive management
  • Prepare engagement with the competent supervisory authority

Who is it for

Newly appointed data protection officers · in-house legal counsel · IT managers · compliance focal points.

Prerequisites

No prerequisites

Dates & locations

36 scheduled dates between November 2026 and December 2027. Seats are confirmed in the order enquiries are received.

November 2026

December 2026

January 2027

March 2027

April 2027

May 2027

June 2027

September 2027

October 2027

November 2027

December 2027

None of these dates suit you? We open additional sessions on request, and any programme can be run privately for your team.

Practical details

Before the programme
Online positioning questionnaire. Your development objectives are shared with the trainer, who tailors the practical case studies to your context.
Teaching methods
Theoretical input, workshops and practical case studies. Digital course materials and method sheets provided.
Assessment
Multiple-choice tests and role-play exercises. Assessment of learning at the start and end of the programme, with immediate and 60-day follow-up evaluations.
After the programme
One year of access to the e-learning platform. Self-assessment of the skills acquired and a 30-day follow-up session with your trainer.
How to register
Registration online or on the basis of a quotation.
Lead time
11 working days after confirmation of registration.
Accessibility
Accessible to people of determination. Contact our accessibility coordinator to design a suitable solution: contact@mpf-academy.ae
Start dates
Rolling intake: in addition to the scheduled sessions, this programme can start on request.