Skip to main content
Course

Privacy Program Foundations

Break into privacy: the principles, data skills, and laws behind every privacy program.

Beginner

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

8 hours

Estimated time

What you will be able to do

  • Define core privacy terms and explain how privacy differs from information security using real-world examples
  • Use the Fair Information Practice Principles (FIPPs) to assess how an organization handles personal data
  • Tell personal data, PII, PHI, and special-category data apart, and spot when data is genuinely de-identified
  • Trace personal data across its lifecycle and draft a basic data inventory or record of processing (RoPA)
  • Explain Privacy by Design and by Default and suggest data-minimization improvements to a process
  • Summarize the scope, core rights, and key obligations of GDPR, CCPA/CPRA, and HIPAA
  • Identify which regulator enforces each major law, from EU data protection authorities to the California CPPA and HHS OCR
  • Speak the working language of a privacy team and contribute to a privacy program from your first week

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Privacy Foundations & Vocabulary

    Build the conceptual and vocabulary foundation every privacy program rests on. You will learn what information privacy actually protects and how it differs from security, recognize the real-world harms privacy prevents, and master the Fair Information Practice Principles along with the core roles you will use daily as a Privacy Analyst: data subject, controller, and processor.

    2 lessons · 5 quiz questions

  2. 02

    Knowing the Data: PII, PHI & Special Categories

    Not all data carries the same risk. This module trains you to recognize personal data and PII, tell direct identifiers from quasi-identifiers, distinguish pseudonymized data from truly anonymized data, and classify the sensitive tiers regulators watch most closely: PHI under HIPAA and special categories under GDPR Article 9. You finish able to classify a real dataset the way an auditor would.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Data Lifecycle, Mapping & Privacy by Design

    Privacy work follows the data. This module traces personal information across its full lifecycle, shows you how to build a basic data map and a Record of Processing Activities (RoPA), and explains how Privacy by Design, Privacy by Default, and data minimization bake protection into systems and processes from the start.

    2 lessons · 5 quiz questions

  4. 04

    The Legal Landscape: GDPR, CCPA/CPRA & HIPAA

    US and EU regulators have given privacy real force of law. This module builds a working command of the three regimes a Privacy Analyst meets most: the EU's GDPR, California's CCPA/CPRA, and the US health-privacy law HIPAA. You will learn what each covers, who it applies to, the rights it grants individuals, and which authority enforces it, so you can look at a data flow and know which rules apply and who is watching.

    2 lessons · 5 quiz questions · assignment