Description

Data Protection Officer: Framing, Steering and Demonstrating Compliance

Holding the data protection officer role beyond a one-off record of processing activities

  • 5 days — 35 h
  • In-person or virtual
  • All levels
  • Up to 6 participants

The appointment has been made, the record of processing activities was completed once, and then the role gradually faded. The data protection officer learns about projects only after they have gone live, has no clear channel with the business functions and cannot demonstrate what has actually been verified.

Five days to establish the role for the long term. The programme covers the applicable framework, maintaining the record of processing activities, impact assessments, handling data subject requests and responding to incidents. Each sequence produces a usable deliverable: a record entry, a procedure, a control plan and an activity report.

Learning objectives

  • Position the duties and independence of the data protection officer
  • Maintain and update the record of processing activities
  • Conduct an impact assessment on a high-risk processing activity
  • Handle data subject requests within the applicable deadlines
  • Organise the response to a personal data breach
  • Demonstrate compliance through a control plan and an activity report

What makes this programme different

Each day produces a deliverable that goes straight into the compliance file
Data subject requests are handled using genuinely difficult cases
A data breach is simulated under time pressure with a notification decision

Programme

1The Framework and the Role

What the data protection officer must be able to demonstrate

  • Position the principles applicable to the processing of personal data under UAE and international frameworks
  • Distinguish the roles of controller and processor
  • Define the duties and independence of the data protection officer
  • Identify internal stakeholders and the competent supervisory authority

2Mapping and Maintaining the Record of Processing Activities

Knowing what the organisation actually processes

  • Collect processing activities from the business functions
  • Qualify purposes
  • lawful bases and retention periods
  • Identify cross-border transfers and the processors involved
  • Organise the ongoing update of the record

3Impact Assessments and Data Protection by Design

Addressing risk before go-live

  • Determine which processing activities require an impact assessment
  • Run the assessment with the business functions and the IT department
  • Evaluate measures that reduce risk for individuals
  • Embed requirements from the design stage of projects

4Individual Rights and Working with the Business

Responding on time and without conflict

  • Qualify a data subject request and verify identity
  • Organise the collection of information from internal departments
  • Draft a reasoned response including in the event of refusal
  • Handle excessive or out-of-scope requests

5Incidents, Monitoring and Activity Reporting

Demonstrating what has been done

  • Qualify a data breach and decide on notification
  • Build a control plan for sensitive processing activities
  • Audit a processor against its contractual commitments
  • Draft the annual activity report of the data protection officer

Who is it for

Newly appointed data protection officers · in-house counsel · IT managers and compliance focal points.

Prerequisites

A general understanding of how the organisation operates and how it processes data will make the programme easier to follow.

Dates & locations

36 scheduled dates between November 2026 and December 2027. Seats are confirmed in the order enquiries are received.

November 2026

December 2026

January 2027

March 2027

April 2027

May 2027

June 2027

September 2027

October 2027

November 2027

December 2027

None of these dates suit you? We open additional sessions on request, and any programme can be run privately for your team.

Practical details

Before the programme
Online positioning questionnaire. Your development objectives are shared with the trainer, who tailors the practical case studies to your context.
Teaching methods
Theoretical input, workshops and practical case studies. Digital course materials and method sheets provided.
Assessment
Multiple-choice tests and role-play exercises. Assessment of learning at the start and end of the programme, with immediate and 60-day follow-up evaluations.
After the programme
One year of access to the e-learning platform. Self-assessment of the skills acquired and a 30-day follow-up session with your trainer.
How to register
Registration online or on the basis of a quotation.
Lead time
11 working days after confirmation of registration.
Accessibility
Accessible to people of determination. Contact our accessibility coordinator to design a suitable solution: contact@mpf-academy.ae
Start dates
Rolling intake: in addition to the scheduled sessions, this programme can start on request.