Privacy Incident & Breach Response
When the 72-hour clock starts, be the analyst who knows exactly what to do.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
9 hours
Estimated time
What you will be able to do
- Distinguish a privacy incident from a security incident and decide when an event is a reportable personal-data breach
- Scope a breach by data category, volume, and affected individuals to build a defensible impact picture
- Score a breach's risk of harm from severity and likelihood to reach a no-risk, risk, or high-risk verdict
- Apply GDPR's Article 33 and 34 tests, including the 72-hour clock, to determine supervisory-authority and individual notification duties
- Run a multi-jurisdiction notification analysis across US state breach laws and HIPAA's Breach Notification Rule
- Draft regulator and individual breach notifications that meet content and timing requirements
- Stand up and maintain an audit-ready breach register that satisfies GDPR Article 33(5) accountability
- Lead a post-incident review that turns a breach into concrete lessons learned and control improvements
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Incident or Breach? Triage and Classification
Builds the vocabulary and decision logic to tell a privacy incident from a security incident, and to recognize when an event becomes a reportable personal-data breach. Across two lessons you learn where the security and privacy circles overlap and where they split, then use the confidentiality-integrity-availability model to classify any event. By the end you can run an intake and classification routine in the first hour of a suspected breach.
2 lessons · 5 quiz questions
- 02
Assessing the Breach and Its Risk of Harm
A breach is only as well-managed as the assessment beneath it. This module gives Privacy Analysts a defensible, repeatable method for scoping what was affected and scoring the resulting risk of harm. You will inventory data categories, count affected individuals without confusing records for people, and apply the ENISA severity method (SE = DPC x EI + CB) to place a breach in the no-risk, risk, or high-risk tier that drives every GDPR notification decision.
2 lessons · 5 quiz questions · assignment
- 03
Notification Thresholds and Timelines
Run a single privacy incident through the three notification regimes a Privacy Analyst meets most: the GDPR's 72-hour clock and high-risk test, the patchwork of US state breach laws, and HIPAA's Breach Notification Rule. You will learn where each clock starts, what trips each duty, and how to satisfy all three at once when a breach spans jurisdictions.
2 lessons · 5 quiz questions
- 04
Notifying, Documenting, and Learning
Turn a breach decision into defensible execution: draft regulator and individual notifications that meet their content requirements, then stand up a breach register and post-incident review that hold up in an audit. You will produce a notification packet and a lessons-learned record for a realistic cross-border incident.
2 lessons · 5 quiz questions · assignment