Privacy Operations & Data Subject Rights
Turn data subject rights into operations you can run.
Tuition
$399
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- Build and maintain a data inventory and a GDPR Article 30 record of processing (RoPA) that stands up to audit.
- Intake, authenticate, and triage data subject and consumer rights requests, and track each one against its statutory deadline.
- Fulfill access, deletion, correction, and opt-out requests end to end, gathering data across systems, redacting third-party information, and drafting compliant responses.
- Apply the right lawful basis and exemptions to decide when a request must be honored, narrowed, or refused.
- Stand up consent and preference management, including cookie and tracking consent and honoring opt-out signals like Global Privacy Control.
- Screen projects for privacy risk and run a Data Protection Impact Assessment (DPIA) from trigger to documented sign-off.
- Translate GDPR and CCPA/CPRA obligations into repeatable privacy operations workflows and SLAs.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Data Inventories & Records of Processing (RoPA)
Personal data you cannot find is personal data you cannot govern. This module builds the foundation of any privacy program: the core concepts a Privacy Analyst works from, including controllers and processors, lawful bases, personal and sensitive data, and how GDPR differs from CCPA/CPRA, then the practical craft of discovering personal data across systems and turning that map into a defensible, current Record of Processing Activities under GDPR Article 30.
2 lessons · 5 quiz questions
- 02
Data Subject & Consumer Rights Requests
The core of the Privacy Analyst role: turning an incoming rights request into a defensible, on-time outcome. You run the full lifecycle, from intake and identity verification through triage and routing against GDPR and CPRA deadlines, then fulfill access, deletion, correction, and opt-out requests across real systems, applying exemptions where they fit and documenting every decision.
2 lessons · 5 quiz questions · assignment
- 03
Consent & Preference Management
Consent is only lawful when it is freely given, specific, informed, easy to withdraw, and provable long after the click; this module teaches you to capture and govern defensible consent, then operate the preference centers, cookie banners, consent management platforms, and browser opt-out signals like Global Privacy Control that keep those choices honored across systems and jurisdictions.
2 lessons · 5 quiz questions
- 04
DPIAs & Privacy Reviews
The best privacy work happens before data is ever collected. This module teaches you to screen new projects, features, and vendors for privacy risk and to run a Data Protection Impact Assessment from trigger through documented sign-off. You will scope an assessment, apply the GDPR Article 35 and EDPB high-risk criteria, test necessity and proportionality, rate and treat risk to individuals, record residual-risk decisions, and know when Article 36 prior consultation is required, so privacy reviews become a routine gate rather than a fire drill.
2 lessons · 5 quiz questions · assignment