ĀRAI TIKA
A Practitioner's Course
Data Privacy: Building and Running a Privacy Programme
A nine-session course on building and running a privacy programme that works in practice.
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
This course covers the full discipline of data privacy in a regulated organisation, from the legislative foundations through to the operational controls that stand up when a regulator calls, a breach occurs, or a rights request lands. It is built on the GDPR's six principles as its spine, with the New Zealand Privacy Act 2020 and Australia's Privacy Act 1988 covered fully in their own right throughout, not as an afterthought.
The course is written to be principle-led rather than jurisdiction-led. Privacy law changes, and it is changing in all three jurisdictions this course covers as it is being written. Understanding what a control is trying to achieve travels across borders and across future legislative change. Memorising the wording of one framework does not.
It is written for privacy officers and DPOs, compliance and risk professionals taking on privacy responsibility, and senior managers who need to understand what a functioning privacy programme looks like from the inside.
The nine sessions
Each session is self-contained and can be read on its own, though they build on each other in sequence. Each ends with a set of key takeaways and pointers to where the underlying legislation and regulatory guidance can be checked directly.
| # | Session | What it covers |
|---|---|---|
| 01 | Introduction: Why Privacy Is an Operational Discipline | What privacy law is actually trying to achieve, the three frameworks this course draws on, and why the course is written to be principle-led rather than jurisdiction-led. |
| 02 | The Legislative Framework | The core definitions that decide scope, the GDPR's six principles, and how the UK, New Zealand and Australian frameworks compare against them. |
| 03 | Lawful Bases and Purpose | The six GDPR lawful bases in practice, why consent is often the wrong default, and how NZ and Australia govern purpose without a lawful-basis structure. |
| 04 | Individual Rights in Practice | Subject access requests, correction, erasure and objection, and the UK's rules for automated decision-making. |
| 05 | DPIAs and Privacy by Design | When a Data Protection Impact Assessment is mandatory, what a properly conducted one contains, and embedding it into project governance. |
| 06 | Data Breach Management | What constitutes a breach, the GDPR's 72-hour clock against the NZ and Australian serious harm thresholds, and building a response capability. |
| 07 | The Privacy Officer and Governance | DPO versus Privacy Officer versus CPO, where the role should sit, and how it works with legal, IT and security, and the board. |
| 08 | Vendors, Data Mapping and Cross-Border Transfers | Processor agreements, why a data map underpins every other control in this course, and how NZ's EU adequacy status changes what is required. |
| 09 | Building the Programme: Implementation Summary | A ten-step build sequence, how to measure whether the programme is working, and a forward look at AI governance. |
Primary frameworks covered
The frameworks below recur throughout the course. They are summarised here as a quick reference, not as an exhaustive statement of the law.
| GDPR / UK GDPR | Six principles, six lawful bases, eight individual rights. UK reformed by the Data (Use and Access) Act 2025, in force in stages through 2025 and 2026. |
| NZ Privacy Act 2020 | Thirteen Information Privacy Principles, plus IPP 3A on indirect collection, in force from 1 May 2026. |
| Australia Privacy Act 1988 | Thirteen Australian Privacy Principles, substantially reformed by the Privacy and Other Legislation Amendment Act 2024. |
For other practitioner material across AML, fraud and financial crime, transformation and risk, and information security and data privacy, visit araitika.com.
Ārai Tika