Data Privacy Course

Data Privacy: Building and Running a Privacy Programme | Ārai Tika

ĀRAI TIKA

A Practitioner's Course

Data Privacy: Building and Running a Privacy Programme

A nine-session course on building and running a privacy programme that works in practice.

This course covers the full discipline of data privacy in a regulated organisation, from the legislative foundations through to the operational controls that stand up when a regulator calls, a breach occurs, or a rights request lands. It is built on the GDPR's six principles as its spine, with the New Zealand Privacy Act 2020 and Australia's Privacy Act 1988 covered fully in their own right throughout, not as an afterthought.

The course is written to be principle-led rather than jurisdiction-led. Privacy law changes, and it is changing in all three jurisdictions this course covers as it is being written. Understanding what a control is trying to achieve travels across borders and across future legislative change. Memorising the wording of one framework does not.

It is written for privacy officers and DPOs, compliance and risk professionals taking on privacy responsibility, and senior managers who need to understand what a functioning privacy programme looks like from the inside.

The nine sessions

Each session is self-contained and can be read on its own, though they build on each other in sequence. Each ends with a set of key takeaways and pointers to where the underlying legislation and regulatory guidance can be checked directly.

# Session What it covers
01 Introduction: Why Privacy Is an Operational Discipline What privacy law is actually trying to achieve, the three frameworks this course draws on, and why the course is written to be principle-led rather than jurisdiction-led.
02 The Legislative Framework The core definitions that decide scope, the GDPR's six principles, and how the UK, New Zealand and Australian frameworks compare against them.
03 Lawful Bases and Purpose The six GDPR lawful bases in practice, why consent is often the wrong default, and how NZ and Australia govern purpose without a lawful-basis structure.
04 Individual Rights in Practice Subject access requests, correction, erasure and objection, and the UK's rules for automated decision-making.
05 DPIAs and Privacy by Design When a Data Protection Impact Assessment is mandatory, what a properly conducted one contains, and embedding it into project governance.
06 Data Breach Management What constitutes a breach, the GDPR's 72-hour clock against the NZ and Australian serious harm thresholds, and building a response capability.
07 The Privacy Officer and Governance DPO versus Privacy Officer versus CPO, where the role should sit, and how it works with legal, IT and security, and the board.
08 Vendors, Data Mapping and Cross-Border Transfers Processor agreements, why a data map underpins every other control in this course, and how NZ's EU adequacy status changes what is required.
09 Building the Programme: Implementation Summary A ten-step build sequence, how to measure whether the programme is working, and a forward look at AI governance.

Primary frameworks covered

The frameworks below recur throughout the course. They are summarised here as a quick reference, not as an exhaustive statement of the law.

READY TO BEGIN

Start with Session One

Introduction: Why Privacy Is an Operational Discipline

For other practitioner material across AML, fraud and financial crime, transformation and risk, and information security and data privacy, visit araitika.com.

Ārai Tika

Written by Russel Fielding — LLM (Distinction), Fraud and Financial Crime · PMP · CIPM · PRINCE2 Practitioner