Skip to main content
Course

Privacy Operations & Data Subject Rights

Turn data subject rights into operations you can run.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

10 hours

Estimated time

What you will be able to do

  • Build and maintain a data inventory and a GDPR Article 30 record of processing (RoPA) that stands up to audit.
  • Intake, authenticate, and triage data subject and consumer rights requests, and track each one against its statutory deadline.
  • Fulfill access, deletion, correction, and opt-out requests end to end, gathering data across systems, redacting third-party information, and drafting compliant responses.
  • Apply the right lawful basis and exemptions to decide when a request must be honored, narrowed, or refused.
  • Stand up consent and preference management, including cookie and tracking consent and honoring opt-out signals like Global Privacy Control.
  • Screen projects for privacy risk and run a Data Protection Impact Assessment (DPIA) from trigger to documented sign-off.
  • Translate GDPR and CCPA/CPRA obligations into repeatable privacy operations workflows and SLAs.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Data Inventories & Records of Processing (RoPA)

    Personal data you cannot find is personal data you cannot govern. This module builds the foundation of any privacy program: the core concepts a Privacy Analyst works from, including controllers and processors, lawful bases, personal and sensitive data, and how GDPR differs from CCPA/CPRA, then the practical craft of discovering personal data across systems and turning that map into a defensible, current Record of Processing Activities under GDPR Article 30.

    2 lessons · 5 quiz questions

  2. 02

    Data Subject & Consumer Rights Requests

    The core of the Privacy Analyst role: turning an incoming rights request into a defensible, on-time outcome. You run the full lifecycle, from intake and identity verification through triage and routing against GDPR and CPRA deadlines, then fulfill access, deletion, correction, and opt-out requests across real systems, applying exemptions where they fit and documenting every decision.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Consent & Preference Management

    Consent is only lawful when it is freely given, specific, informed, easy to withdraw, and provable long after the click; this module teaches you to capture and govern defensible consent, then operate the preference centers, cookie banners, consent management platforms, and browser opt-out signals like Global Privacy Control that keep those choices honored across systems and jurisdictions.

    2 lessons · 5 quiz questions

  4. 04

    DPIAs & Privacy Reviews

    The best privacy work happens before data is ever collected. This module teaches you to screen new projects, features, and vendors for privacy risk and to run a Data Protection Impact Assessment from trigger through documented sign-off. You will scope an assessment, apply the GDPR Article 35 and EDPB high-risk criteria, test necessity and proportionality, rate and treat risk to individuals, record residual-risk decisions, and know when Article 36 prior consultation is required, so privacy reviews become a routine gate rather than a fire drill.

    2 lessons · 5 quiz questions · assignment