Operationalizing Privacy: Strategic Implementation of Data Protection and Compliance Programs
1h 51mIntermediate2025-06-10
Authors

Jordan Fischer
Course details
As companies face new privacy regulations and increasing complexity of data governance and management, understanding how to create effective, evergreen privacy law compliance programs is key. In this course, Jordan Fischer—an expert on the intersection of law and technology—provides an in-depth, actionable overview of how to operationalize privacy within a business. Learn how to create privacy oversight and leadership. Explore mapping data flows to understand privacy law applicability. Discover best practices around privacy documentation, demonstrating compliance, and addressing data privacy rights. Find out how to handle vendor or third party privacy risk management. Plus, delve into practical exercises and worksheets that you can take back to your organization to improve the current privacy strategy.
Learning objectives
Analyze organizational data flows to determine applicable privacy regulations and compliance requirements across jurisdictions.
Evaluate different privacy program frameworks to select the most appropriate approach for your organization's industry and regional context.
Design a comprehensive privacy oversight structure that establishes clear roles, responsibilities, and accountability measures.
Develop privacy documentation processes and procedures that demonstrate ongoing compliance with regulatory requirements.
Integrate privacy-by-design principles into vendor management and third-party risk assessment workflows.
Learning objectives
Analyze organizational data flows to determine applicable privacy regulations and compliance requirements across jurisdictions.
Evaluate different privacy program frameworks to select the most appropriate approach for your organization's industry and regional context.
Design a comprehensive privacy oversight structure that establishes clear roles, responsibilities, and accountability measures.
Develop privacy documentation processes and procedures that demonstrate ongoing compliance with regulatory requirements.
Integrate privacy-by-design principles into vendor management and third-party risk assessment workflows.
Concepts
Introduction
- The evolving privacy regulatory environment
Privacy Leadership and Oversight
- Assembling your team
- Identifying your roles
- Do you need a data protection officer (DPO)
- Communicating privacy strategy expectations
Privacy Program Foundations
- Privacy ownership
- Personal data vs. anonymized information
- Data identification and classification
- Data retention and data destruction
- How data governance brings it all together
Recording and Keeping Data
- Why you should map your data
- Data sources
- Demo - Mapping your data to a basic spreadsheet
- Demo - Walking through a data map
Privacy Disclosures and Notices
- What are privacy policies, and why do you need them
- Content to include in a privacy policy
- The dos and don'ts of cookie banners
- Just-in-time notices and accessible notices
Privacy Rights
- An introduction to privacy rights
- Limitations of privacy rights
- Responding to a data subject request (DSR)
- DSR best practices
Third-Party Privacy Risk Management
- Overview of privacy risk management
- Identifying, mitigating, and tracking privacy risks
- Data protection impact assessments (DPIA)
- Conducting a DPIA
Conclusion
- Tying everything together into a cohesive framework