Pre-course
reading
3.5-hour
online sessions
40+ hours
self-study
Flexible live
interactive training
Exam
preparation
90-minute online
BCS examination
First launched in 1999, the BCS (formerly ISEB) Practitioner Certificate in Data Protection is the leading independent professional workplace qualification for individuals with privacy or data protection responsibilities. Over the years, the BCS has continued to evolve the practitioner certificate to keep pace with the advances in UK and EU legislation. In doing so, the BCS Practitioner Certificate has become the most trusted data protection training programme in the UK and is often listed by employers as a required qualification. The current version of the BCS syllabus (v9.7) from June 2023 covers the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). It takes into account the legislative changes following the end of the transition period on 31 December 2020, when the UK formally ceased to be a member state of the EU, and also considers the proposed changes within the Data Protection and Digital Information (No.2) Bill. It also examines the concepts of artificial intelligence and the overlap with information access requirements.
Pre-course
reading
3.5-hour
online sessions
40+ hours
self-study
Flexible live
interactive training
Exam
preparation
90-minute online
BCS examination
8 to 12 week programme
The BCS Practitioner Certificate in Data Protection recognises the ability of award holders to fulfil the mandatory role of a Data Protection Officer (DPO) or to lead UK General Data Protection Regulation (GDPR) compliance within their organisation, department or group.
This BCS-accredited GDPR training course requires participants to develop a deep understanding of both UK and EU data protection laws and how to apply them in a workplace environment. Rather than focus on the rigid mechanics of regulation, the data protection course places privacy in the context of human rights and promotes good practice within organisations.
The data protection training course examines the UK GDPR's 10 chapters, 99 articles and 173 recitals (specifically those that remain relevant after being saved into UK Law). It concentrates on the complexity of the interactions between the GDPR and the Data Protection Act 2018, including its derogations and exemptions, along with the Privacy and Electronic Communications Regulations (PECR).
The course is delivered online for convenience and for the significant environmental and sustainability benefits it offers. Delegates can gain a recognised practitioner-level workplace qualification at home or from their desk by attending ten consecutive 3.5-hour live online sessions across two weeks. This data protection course follows the latest BCS Syllabus (v9.7) and prepares participants for the 90-minute multiple-choice BCS Practitioner Certificate in Data Protection Exam, administered separately via Questionmark through online remote proctoring. Participants will also receive a separate 1-day online revision course to help prepare for the BCS Practitioner Exam.
The BCS Certificate in Data Protection is a GDPR training course conducted over 10 consecutive morning sessions (or 5 full days when delivered in-company).
The following schedule is intended as a guide:
Module 1 | Introductions, Learning outcomes |
BCS Exam details & techniques | |
Data protection, privacy and its history in the UK • Article 2 Material scope of UK and EU GDPR • Article 3 Territorial scope and jurisdiction of UK and EU GDPR • Awareness of EU Main Establishment, one-stop-shop mechanism (OSS)• Article 27 UK and EU requirements for Representation | |
Principles of Data Protection and Applicable Terminology • Article 4 Definitions of UK and EU GDPR • Article 5 Principles of UK and EU GDPR | |
Module 2 | Principles of Data Protection and Applicable Terminology (continued) |
Lawfulness of Processing Personal Data • Article 6 Lawful Basis of Processing • • Article 9 Processing special categories of personal data • Additional safeguards: UK GDPR Article 9 and DPA18 Schedule 1 | |
Module 3 | Lawfulness of Processing Personal Data (continued) • Article 9 Processing special categories of personal data (continued) • The Rules for processing criminal offence data |
Accountability Principle • Article 5(2) Accountability and Article 24 Responsibility of the controller (accountability obligations) • Article 35 Data Protection Impact Assessments (DPIA) • Article 30 Records of Processing Activity (ROPA) • Articles 13 and 14 Interplay with Privacy Notices | |
Module 4 | Accountability Principle (continued) • Article 25 Data Protection by Design and Default • Article 32 Security of personal data • Article 37-39 The position, tasks and role of the Data Protection Officer |
Obligations of Controller, Joint Controllers and Processors • Article 24 Responsibilities of the Controller • Article 28 Responsibilities of the Processor • Cloud Service Providers (CSPs) | |
Module 5 | Obligations of Controllers, Joint Controllers and Processors (continued) • Article 26 Joint Controllers • Article 28(3) Data processing agreements |
International Data Transfers under EU and UK GDPR • Article 44 General principles for transfers • Article 45 UK Adequacy Regulations and EU Adequacy Decisions • Article 46 Appropriate safeguards: - UK International Data Transfer Agreement (IDTA) - EU Standard Contractual Clauses (SCCs) • Article 47 Binding corporate rules • Article 49 Derogations for specific situations | |
Data Subjects Rights • Article 12 Transparency and Modalities • Articles 13 and 14 Information to be provided to a data subject • Article 15 Right of Access • Section 184 Prohibition against enforced subject access requests • Section 185 Void contractual terms relating to health records | |
Module 6 | Data Subjects Rights (continued) • Article 16 Right of rectification • Article 17 Right to erasure • Article 18 Right of restriction • Article 19 Notification obligations • Article 20 Data portability • Article 21 Right to object • Article 22 Automated decision making and profiling Restrictions that may affect Data Subject Rights (as per Article 23 Restrictions and DPA18, Schedules 2 and 3) • Access rights of FOI and EIR • Impact of AI on data rights |
The Role of the Supervisory Authority (EU) • The role and importance of supervisory authorities • Article 57 Tasks of the Independent Supervisory Authorities • Article 68-73 European Data Protection Board (EDPB) | |
Module 7 | The Information Commissioner’s Office (ICO) • The role of the ICO • Investigative and corrective powers of the ICO as the UK regulator • ICO guidance and codes of practice • Promoting public awareness • Promotion of Privacy Seals, certification schemes and commonly used standards • Advice and reporting to Parliament • Data Protection Fees and Exceptions |
Breaches, Enforcement and Liabilities and Role of the Tribunal • Articles 33 & 34 Obligations to report personal data breaches to ICO and data subjects • Data Protection Complaints • Sanctions that can be imposed due to breaches or complaints • Reprimands • Notices and Administrative fines • Liabilities of controllers and processors | |
Module 8 | Breaches, Enforcement and Liabilities and Role of the Tribunal (continued) • Criminal liabilities – Offences • Offences under the Computer Misuse Act 1990 • The role of the Tribunal |
Processing of personal data in relation to children • Article 8 Consent in relation to Information Society Service • Children’s right to erasure • Age Appropriate Design Code (Children's Code) | |
Specific provisions relevant to public authorities • Meaning of Public Authority/Body • Article 6(1)(e) Public Task lawful basis of processing considerations • DPA18 Section 7(2) interplay for public authorities with Article 6(1)(f) • Relevant exemptions from Schedules 2 & 3 | |
Module 9 | Application of data protection legislation in key areas of industry • Overview of ICO Codes of Practice: - Employment Code - Surveillance Cameras and Personal Information Code - How the use of cookies and digital technologies is governed by data protection law (and PECR) - Data Sharing Code AI and the processing of personal data • What is meant by AI • AI Risks and Benefits • The Data Protection Principles and AI • DPIAs and AI |
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) • Link to GDPR consent definition • Types of electronic marketing and obligations | |
Module 10 | Questions & Answers |
Individual 1-2-1 tutorials |
This course is suitable for the following individuals:
By obtaining the Practitioner Certificate in Personal Data Protection, individuals will:
Practitioner Certificate in Personal Data Protection (PC-DP)
Extracted from syllabus version 9.7
June 2023
Download the new syllabus (PDF)
This professional certification is not regulated by the following United Kingdom Regulators - Ofqual, Qualification in Wales, CCEA or SQA.
The topics covered in this session include:
Following the examination prep day, the instructor will evaluate each student’s mock paper and provide individual feedback. This will include direct comments on the answers and offer guidance for further study areas.
The BCS Practitioner Certificate in Data Protection exam format is a 90-minute multiple-choice examination. The exam is a closed book, i.e. no materials can be taken into the examination room.
Type | 40 Multiple Choice questions |
Duration | 90 minutes |
Supervised | Yes |
Open Book | No (no materials can be taken into the examination room) |
Pass Mark | 26/40 (65%) |
Delivery | Digital or paper-based |
Adjustments and/or additional time can be requested in line with the BCS reasonable adjustments policy for candidates with a disability or other special considerations, including English as a second language.
Get this BCS Practitioner Certificate in Data Protection for:
£2,349+VAT
10% OFF
Sign-up for our Privacy Newsfeed weekly newsletter to get your discount code. Receive additional offers by selecting training announcements option. Please choose your desired subscription option and then enter your details to subscribe.
In addition to the above course dates, you also need to select the dates for your examination events. Choose a date for your exam preparation day 3-6 weeks after the training course. Then book your BCS exam 2-6 weeks after the exam preparation day.
Duration: 1-day
Format: Online
Duration: 90 minutes
Location: Online
Freevacy has been shortlisted in the Best Educator category. The PICCASO Privacy Awards recognise the people making an outstanding contribution to this dynamic and fast-growing sector.