| Section | Weight | Objectives |
| Topic 1: Compliance with European Data Protection Law and Regulation | 15%–22% | - Data Protection Officer (DPO): appointment, role, duties
- Breach notification: requirements, timelines, procedures
- Security of processing: technical and organizational measures
- Compliance programs, audits, and governance frameworks
|
| Topic 2: European Data Protection: Scope and Accountability | 17%–25% | - Accountability obligations: documentation, records, impact assessments
- Supervisory authorities: structure, powers, cooperation, consistency mechanism
- Enforcement: penalties, remedies, liability, appeals
- Territorial and material scope of GDPR application
|
| Topic 3: European Data Processing | 20%–30% | - Processing for specific purposes: employment, marketing, research, surveillance
- International data transfers: rules, mechanisms, safeguards
- Information obligations: privacy notices, transparency requirements
- Basis for processing: consent, contract, legal obligation, vital interests, public task, legitimate interest
|
| Topic 4: European Data Protection Law and Regulation | 18%–28% | - Roles: controller, processor, joint controllers, representatives
- Data subject rights and how to uphold them
- Key definitions: personal data, special categories, pseudonymous/anonymous data
- Lawful processing principles and conditions
|
| Topic 5: Introduction to European Data Protection | 7%–13% | - EU institutions, legislative framework and legal structure
- Core principles and foundational concepts of data protection
- Historical background and evolution of European privacy law
|