Skip to main content
Course

Privacy & Data Protection Bootcamp

Become a privacy professional across the US, UK and EU: GDPR, UK GDPR and the Data Protection Act 2018, CCPA/CPRA and the US state patchwork, privacy program management, privacy engineering, breach response, and IAPP exam preparation.

Intermediate

Level

15

Modules

75

Lessons

15

Graded quizzes

15

Assignments

42 hours

Estimated time

What you will be able to do

  • Explain what privacy work is, and distinguish personal data, sensitive data, and the principles every framework shares
  • Apply GDPR: choose a lawful basis, fulfill data subject rights, run a DPIA, and assess a cross-border transfer
  • Apply UK GDPR and the Data Protection Act 2018, and explain where the UK and EU regimes diverge
  • Apply CCPA/CPRA and navigate the wider US state privacy patchwork
  • Stand up a privacy program: notices, training, metrics, and executive reporting
  • Review a system design for privacy risk and distinguish pseudonymization from anonymization
  • Run a breach response under the GDPR 72-hour rule and US state notification laws
  • Choose the right IAPP certification path and read scenario-based privacy exam questions

What is inside

15 modules, 75 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Privacy Foundations: Why Privacy Is a Discipline, Not Just Compliance

    Before you touch a single law or framework, you need to understand what privacy work actually is, why the line between ordinary personal data and sensitive data changes everything downstream, and how the same handful of principles recur across every privacy law you will ever study. This module builds that foundation using Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in the EU and US, as the running example for all five lessons. You finish able to explain what privacy professionals actually do, classify data correctly, apply the core principles to a real business process, and describe precisely where privacy and security responsibilities diverge.

    5 lessons · 15 quiz questions · assignment

  2. 02

    Global Privacy Landscape: How the Major Laws Relate to Each Other

    Before you go deep on any single privacy law, you need a working map of the whole territory: which laws exist, who they cover, and why a company with no overseas office can still answer to a foreign regulator. This module builds that map using Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in the EU and the US, as the running example throughout. You finish able to explain why Lumen answers to GDPR, CCPA/CPRA, and a growing list of other regimes at the same time, and you build a first-draft compliance map that later modules in this bootcamp will deepen law by law.

    5 lessons · 15 quiz questions · assignment

  3. 03

    GDPR I: Scope, Lawful Basis, and Core Principles

    This module builds the real foundation of GDPR practice: who counts as a controller versus a processor, when the regulation reaches a company with no EU office at all, and how to pick and defend a lawful basis under Article 6 for a given piece of processing. It also covers GDPR's genuinely strict consent standard and the heightened rules for special category data under Article 9. Every concept runs through Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in both the EU and US, so you finish able to map real processing activities to real legal bases, not just recite article numbers.

    5 lessons · 15 quiz questions · assignment

  4. 04

    GDPR II: Data Subject Rights and How to Actually Fulfill Them

    GDPR gives individuals eight concrete rights over their personal data, and every one of them eventually lands on a real person's desk as a real request with a real deadline. This module walks through each right using Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in both the EU and US, as the running example: how to verify identity without over-collecting data, how the one-month clock actually works, when erasure has to give way to a genuine legal exception, and how to build an intake workflow that catches a rights request no matter which door it walks through.

    5 lessons · 15 quiz questions · assignment

  5. 05

    GDPR III: DPIAs, Records of Processing, and the DPO Role

    This module builds the operational machinery that turns GDPR principles into a running privacy program: knowing when Article 35 requires a Data Protection Impact Assessment and how to run one, what actually belongs in an Article 30 Record of Processing Activities, when Article 37 requires a Data Protection Officer and what independence that role needs under Article 38, and how Article 25 privacy by design and by default gets built into product decisions before launch. Every lesson works the same running example, Lumen Retail Co.'s new personalization engine, so you finish able to screen, document, and defend a real high-risk processing decision end to end.

    5 lessons · 15 quiz questions · assignment

  6. 06

    GDPR IV: Cross-Border Data Transfers and International Mechanisms

    This module covers the most operationally tricky part of GDPR for a US-facing company: the Chapter V rules that restrict moving personal data out of the EU. You will learn what legally counts as a transfer, how adequacy decisions work, how Standard Contractual Clauses function after Schrems II and the transfer impact assessment they now require, and when Binding Corporate Rules or a narrow Article 49 derogation is the right tool instead. We use Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in both the EU and US, as the running example throughout.

    5 lessons · 15 quiz questions · assignment

  7. 07

    US Privacy Law I: CCPA/CPRA Fundamentals

    California's privacy law is the framework every US privacy program has to reckon with, and it changed shape substantially when the California Privacy Rights Act (CPRA) amended the original California Consumer Privacy Act (CCPA) and created a dedicated regulator, the California Privacy Protection Agency (CPPA). This module builds the full consumer rights framework, the applicability thresholds, the sale and share distinction with the Global Privacy Control signal, and sensitive personal information handling, using Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in both the EU and US, as the running example throughout. You finish able to determine whether a business is covered, explain what a California consumer can demand and what a business must do in response, and design a defensible rights-request workflow.

    5 lessons · 15 quiz questions · assignment

  8. 08

    US Privacy Law II: The State Privacy Law Patchwork Beyond California

    California was first, but it is no longer the only US state with a comprehensive privacy law, and the two dozen laws that followed it do not all say the same thing. This module builds the pattern that Virginia, Colorado, Connecticut, and most of the newer state laws share, maps out exactly where they diverge on thresholds, rights, and enforcement, and walks through the federal rules (the FTC Act, GLBA, COPPA, and sector rules) that keep applying underneath all of it. Using Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in both the EU and US, as the running example, you finish able to determine which state laws actually apply to a given business and design one compliance program that scales across the patchwork instead of one law at a time.

    5 lessons · 15 quiz questions · assignment

  9. 09

    Privacy Program Management

    Knowing the law is not the same as running a privacy program. This module builds the operational management layer that sits on top of everything covered so far: standing up a program with real executive authority, writing notices people can actually read and that actually comply, training a workforce so privacy becomes a habit rather than an annual checkbox, choosing metrics that show real risk reduction instead of activity theater, and reporting program health to an executive team in language that gets decisions made. Lumen Retail Co. runs as the through line, moving from a company with no formal privacy program to one with a working, measured, board-reported operation.

    5 lessons · 15 quiz questions · assignment

  10. 10

    Privacy by Design and Privacy Engineering

    This module moves from privacy law into privacy engineering: what it actually takes to build a system that enforces an organization's privacy decisions instead of just describing them in a policy document. You will work Article 25's design and default obligations, data minimization and purpose limitation at the schema and access-control level, and the pseudonymization versus anonymization distinction that IAPP's CIPT exam tests harder than almost anything else. The module closes with a full design review of Lumen Retail Co.'s personalization engine, applying every technique to one concrete system.

    5 lessons · 15 quiz questions · assignment

  11. 11

    Data Mapping, Vendor Risk, and Third-Party Data Sharing

    Privacy programs live or die on unglamorous operational work: knowing what data a company actually has, where it actually goes, and whether the vendors touching it are contractually and technically accountable for protecting it. This module builds the practical skills of data mapping, vendor privacy risk assessment, Data Processing Agreement negotiation, and sub-processor accountability, using Lumen Retail Co., a fictional mid-size e-commerce retailer selling to customers in both the EU and US, as the running example. You finish able to build a real data flow map, run a defensible vendor risk assessment, identify the DPA clauses that actually matter versus boilerplate, and trace accountability through a multi-tier vendor chain.

    5 lessons · 15 quiz questions · assignment

  12. 12

    Breach Response and Incident Management for Privacy

    A breach does not wait for a privacy team to finish arguing about which law applies, and this module builds a working incident response capability rather than a list of statutes to memorize. You learn the GDPR's 72-hour notification discipline under Articles 33 and 34, the fragmented but pattern-following US state breach notification landscape, and a real likelihood-and-severity risk assessment methodology, then run all three through one full detection-to-notification walkthrough using Lumen Retail Co. as the incident. You finish able to classify a breach correctly, run its GDPR clock and its US jurisdictional matrix at the same time, and decide, with a documented rationale, who has to be told and by when.

    5 lessons · 15 quiz questions · assignment

  13. 13

    Sector-Specific Privacy: Health, Children's Data, and AI/Automated Decisions

    This module moves from general privacy law into the sector-specific rules a generalist privacy professional still has to know: health data protection outside HIPAA's narrow covered-entity scope, COPPA's verifiable parental consent requirements and their common traps, GDPR Article 22's rules on solely automated decision-making, and how emerging AI governance frameworks like the EU AI Act intersect with existing privacy obligations. Lumen Retail Co.'s wellness-perks loyalty tier and children's product line anchor every lesson, giving you one concrete case to carry all the way through to a full end-to-end risk assessment in the module's final lesson. You finish able to correctly scope HIPAA's actual reach, apply COPPA's consent mechanics, run an Article 22 analysis on an automated feature, and place a proposed AI feature within both GDPR and the EU AI Act's risk framework.

    5 lessons · 15 quiz questions · assignment

  14. 14

    IAPP Exam Strategy and Certification Pathways

    This closing module shifts from privacy law itself to the craft of the IAPP certification exams built on that law: which of CIPP/US, CIPP/E, CIPM, and CIPT fits which career goal, how the exams are actually formatted and scored, and how to read a scenario-based question the way IAPP writes it. Every lesson works through Lumen Retail Co.'s privacy team, from choosing a DPO's credential to debriefing a mixed-domain practice run under real time pressure. You finish with a concrete personal study and certification path plan and this course's hardest, most exam-realistic quiz, mixing domains from across the entire bootcamp.

    5 lessons · 15 quiz questions · assignment

  15. 15

    UK Data Protection: UK GDPR, the Data Protection Act 2018, and the ICO

    You already know EU GDPR in depth, so this module teaches the UK layer on top of it: how UK GDPR was retained after Brexit, how the Data Protection Act 2018 supplements it, and where the UK regime mirrors and diverges from the EU. You will work through the ICO's enforcement powers, PECR's cookie and marketing rules, the UK's own transfer mechanisms (the IDTA and the UK Addendum), and the Children's Code, all applied to Lumen Retail Co. as it formalises compliance for a growing UK customer base.

    5 lessons · 15 quiz questions · assignment