Subject Access Requests (SARs) Training Course
Subject Access Requests (SARs) constitute a legal mechanism that empowers individuals to request access to the personal data that an organisation retains about them. Gaining proficiency in handling SARs effectively is vital for adhering to data protection regulations.
This live, instructor-led training (available either online or on-site) is designed for compliance officers, legal teams, and data protection professionals at intermediate to advanced levels who aim to ensure their organisation’s SAR procedures are efficient, compliant, and free from risk.
Upon completion of this training, participants will be able to:
- Comprehend the legal framework governing SARs.
- Process SARs efficiently while upholding compliance.
- Recognise exemptions and limitations stipulated under data protection laws.
- Manage complex SAR scenarios, including those involving third-party data.
- Adopt best practices for SAR documentation and responses.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical practice.
- Hands-on implementation within a live laboratory environment.
Customisation Options
- To arrange a bespoke training session for this course, please contact us.
Course Outline
Introduction to Subject Access Requests (SARs)
- Definition of a Subject Access Request
- Legal foundation and significance of SARs
- Overview of key regulations (e.g., GDPR, CCPA)
Legal Framework and Compliance Requirements
- Data subject rights under GDPR and other legislations
- Response timeframes and deadlines
- Consequences of non-compliance
Processing a Subject Access Request
- Validating and verifying the requester's identity
- Locating and collating the requested data
- Ensuring secure data transmission
Managing Third-Party and Sensitive Data
- Identifying third-party information within SARs
- Applying redaction and anonymisation techniques
- Balancing data access rights with privacy obligations
Exemptions and Limitations
- Circumstances under which an organisation may refuse a SAR
- Exemptions pertaining to security, confidentiality, and legal privilege
- Managing disproportionate or unreasonable SARs
Best Practices for SAR Management
- Developing an internal SAR policy
- Establishing a streamlined SAR response workflow
- Leveraging technology to automate SAR handling
Case Studies and Practical Exercises
- Analysing real-world SAR cases
- Simulating a SAR request and response cycle
- Group discussions on SAR challenges and solutions
Summary and Next Steps
Requirements
- Fundamental understanding of data protection and privacy legislation
- Familiarity with organisational data management policies
- Experience in managing customer or employee data (recommended)
Target Audience
- Data Protection Officers (DPOs)
- Compliance Officers
- Legal and Human Resources professionals
- IT and data management teams
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793
Subject Access Requests (SARs) Training Course - Enquiry
Testimonials (2)
Really enjoyed the topics covered and the way that the trainer ran the session
Richard
Course - BCS Practitioner Certificate in Data Protection
The variety of the information shared and the clarity to explain terms in plain English.
Arisbe Mendoza - Fairtrade International
Course - GDPR Workshop
Related Courses
BCS Foundation Certificate in Data Protection
21 HoursThis course is designed for individuals seeking to comprehend data protection principles, with a specific focus on the General Data Protection Regulation (GDPR).
Upon completing the course, candidates will be equipped to:
- Achieve a recognised qualification in data protection.
- Understand the pivotal changes introduced to data protection by the GDPR and the Data Protection Act (2018).
- Comprehend the new rights granted to data subjects under the GDPR and Data Protection Act (2018), alongside the implications of these rights.
- Gain insight into the individual and organisational responsibilities mandated by the GDPR and Data Protection Act (2018), particularly emphasising the necessity for effective record-keeping.
- Appreciate the heightened obligations assumed by data controllers and data processors due to the enforcement of the GDPR and the enactment of the Data Protection Act (2018).
- Better support their organisation in processing customer data in strict compliance with the GDPR and Data Protection Act (2018).
BCS Practitioner Certificate in Data Protection
35 HoursTarget Audience:
- Individuals who currently hold data protection responsibilities within their organisation.
- Professionals seeking to expand their foundational knowledge in this domain and gain a comprehensive grasp of the practical application of data protection legislation.
- Although this certificate is grounded in the UK Data Protection Act, many other jurisdictions have implemented broadly similar laws. Consequently, international candidates may also find this qualification beneficial.
Learning Outcomes:
Upon completion, candidates will be able to:
- Comprehend the significant changes and implications introduced by the GDPR and the UK Data Protection Act 2018 concerning data protection.
- Understand the obligations of both individuals and organisations under the GDPR and the UK Data Protection Act, with particular emphasis on the necessity for effective record-keeping.
- Apply the new rights afforded to data subjects and appreciate the implications of these rights.
- Demonstrate knowledge of the designation, positioning, and role or tasks associated with a Data Protection Officer.
- Prepare organisations to manage and process personal data in strict compliance with the GDPR and the UK Data Protection Act.
CIPP/E – Certified Information Privacy Professional/Europe
14 HoursThe CIPP/E training course offers a comprehensive examination of the GDPR and essential data protection principles. The module on Principles of Data Protection in Europe addresses fundamental pan-European and national data protection legislation, alongside industry-standard best practices for corporate compliance.
Data Breach Management
14 HoursThis instructor-led, live training in Botswana (online or on-site) is aimed at intermediate-level to advanced-level IT professionals and business leaders who wish to develop a structured approach to handling data breaches.
By the end of this training, participants will be able to:
- Understand the causes and consequences of data breaches.
- Develop and implement data breach prevention strategies.
- Establish an incident response plan to contain and mitigate breaches.
- Conduct forensic investigations and assess the impact of breaches.
- Comply with legal and regulatory requirements for breach notification.
- Recover from data breaches and strengthen security postures.
Data Protection Impact Assessment (DPIA)
7 HoursA Data Protection Impact Assessment (DPIA) is a compulsory risk evaluation procedure mandated by the GDPR and various other data protection statutes. Its primary objective is to identify and address risks to individuals' personal data during processing activities that carry high risk.
This instructor-led, live training session, available both online and onsite, is designed for professionals with intermediate-level expertise who wish to gain the knowledge and skills necessary to perform DPIAs, thereby ensuring compliance with data privacy regulations and mitigating risks associated with data processing projects.
Upon completion of this training, participants will be equipped to:
- Comprehend the legal and regulatory framework surrounding DPIAs.
- Identify when a DPIA is necessary and effectively define its scope.
- Navigate the entire DPIA lifecycle, from initiation through to documentation and review.
- Integrate DPIA practices into wider data governance structures.
Course Format
- Interactive lectures and discussions.
- Ample opportunities for exercises and practice.
- Practical implementation using real-world scenarios.
Customisation Options
- For organisations seeking a tailored training experience for this course, please contact us to make arrangements.
System Center Data Protection Manager (DPM) Backup and Recovery
35 HoursMicrosoft System Center Data Protection Manager (DPM) serves as Microsoft’s enterprise-grade backup and recovery solution, designed to safeguard critical workloads including file servers, databases, and virtual machines.
This instructor-led live training, available either online or on-site, is tailored for intermediate-level IT professionals looking to deploy, configure, and manage DPM to protect data and ensure business continuity.
Upon completing this training, participants will be capable of:
- Installing and configuring DPM servers and agents.
- Creating and managing protection groups.
- Executing backup and recovery operations.
- Integrating DPM with other disaster recovery solutions.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical sessions.
- Hands-on implementation within a live lab environment.
Customisation Options
- To request a customised training session for this course, please get in touch with us to arrange it.
GDPR Workshop
7 HoursAcquire a comprehensive understanding of the General Data Protection Regulation through this intensive one-day workshop, specifically tailored for managers, department heads, and compliance personnel. The curriculum covers GDPR fundamentals, the rights of data subjects, core data protection principles, consent requirements, obligations regarding breach notifications, and the concept of privacy by design. Attendees will gain practical frameworks for implementing GDPR compliance strategies throughout their organization, ensuring lawful data processing and fostering a culture of accountability in data protection.
How to Audit GDPR Compliance
14 HoursDesigned primarily for auditors and administrative personnel responsible for verifying that control systems and IT environments adhere to current laws and regulations, this course offers a comprehensive overview of the General Data Protection Regulation (GDPR). It begins by elucidating core GDPR concepts and illustrating their impact on auditing practices. Participants will delve into the rights of data subjects, the obligations of data controllers and processors, and the enforcement mechanisms governing compliance. Additionally, the training incorporates ISACA's audit programme, empowering auditors to evaluate GDPR governance, response strategies, and supporting processes to effectively mitigate risks linked to non-compliance.
GDPR - Certified Data Protection Officer
35 HoursThe PECB Certified Data Protection Officer training course equips you with the necessary knowledge and skills to develop the competence required to perform the role of a data protection officer within a GDPR compliance program implementation.
Why should you attend?
As data protection gains increasing value, the imperative for organisations to safeguard this data is constantly growing. Non-compliance with data protection regulations not only violates the fundamental rights and freedoms of individuals but can also expose organisations to risky situations that may damage their credibility, reputation, and financial standing. This is where your expertise as a data protection officer becomes crucial.
The PECB Certified Data Protection Officer training course will assist you in acquiring the knowledge and skills to serve as a Data Protection Officer (DPO), thereby helping organisations ensure adherence to the General Data Protection Regulation (GDPR) requirements.
Through practical exercises, you will master the DPO role and become competent in informing, advising, and monitoring GDPR compliance, as well as cooperating with the supervisory authority.
Upon completing the training course, you may sit for the exam. If you pass successfully, you can apply for the “PECB Certified Data Protection Officer” credential. This internationally recognized certificate validates your professional capabilities and practical knowledge to advise controllers and processors on fulfilling their GDPR compliance obligations.
Who should attend?
- Managers or consultants seeking to prepare and support an organisation in planning, implementing, and maintaining a GDPR-based compliance program.
- DPOs and individuals responsible for maintaining conformance with GDPR requirements.
- Members of information security, incident management, and business continuity teams.
- Technical and compliance experts preparing for a data protection officer role.
- Expert advisors involved in the security of personal data.
Learning objectives
- Understand GDPR concepts and interpret its requirements.
- Comprehend the content and correlation between the General Data Protection Regulation and other regulatory frameworks and applicable standards, such as ISO/IEC 27701 and ISO/IEC 29134.
- Acquire the competence to perform the DPO role and daily tasks within an organisation.
- Develop the ability to inform, advise, and monitor GDPR compliance and cooperate with the supervisory authority.
Educational approach
- This training course is founded on both theory and best practices for exercising the DPO role.
- Lecture sessions are illustrated with practical exercises based on a case study, including role-playing and discussions.
- Participants are encouraged to interact, engage in discussions, and participate in exercises.
- Practice exercises and quizzes mirror the certification exam format.
General Information
- Participants will receive training course materials containing over 450 pages of explanatory information and practical examples.
- An Attendance Record worth 31 CPD (Continuing Professional Development) credits will be issued to participants who complete the training course.
PECB GDPR - Certified Data Protection Officer
35 HoursThe PECB Certified Data Protection Officer training course empowers you with the essential knowledge, skills, and competence to effectively execute the role of a Data Protection Officer within a GDPR compliance framework.
Why attend this course?
As data protection grows in value, organisations face increasing pressure to safeguard this information. Non-compliance with data protection regulations not only violates the fundamental rights and freedoms of individuals but also exposes organisations to significant risks that can damage their credibility, reputation, and financial standing. This is where your expertise as a Data Protection Officer becomes vital.
This PECB Certified Data Protection Officer training course equips you with the knowledge and skills needed to serve as a Data Protection Officer (DPO), helping organisations meet General Data Protection Regulation (GDPR) requirements.
Through practical exercises, you will master the DPO role, gaining the competence to inform, advise, and monitor GDPR compliance, as well as collaborate with supervisory authorities.
Upon completing the training, you may sit for the exam. If you pass, you can apply for the \"PECB Certified Data Protection Officer\" credential. This internationally recognised certificate demonstrates your professional capability and practical knowledge to advise controllers and processors on fulfilling their GDPR obligations.
Who should attend?
- Managers or consultants aiming to prepare and support organisations in planning, implementing, and maintaining a GDPR-based compliance programme
- DPOs and individuals responsible for maintaining GDPR conformance
- Members of information security, incident management, and business continuity teams
- Technical and compliance professionals preparing for a Data Protection Officer role
- Expert advisors involved in personal data security
Learning objectives
- Understand GDPR concepts and interpret its requirements
- Grasp the content and correlation between GDPR and other regulatory frameworks and applicable standards, such as ISO/IEC 27701 and ISO/IEC 29134
- Acquire the competence to perform the daily tasks and role of a Data Protection Officer within an organisation
- Develop the ability to inform, advise, and monitor GDPR compliance, and cooperate with supervisory authorities
Personal Data Protection Officer - Basic Level
21 HoursPurpose of the Training
- Familiarising participants with the structured and comprehensive aspects of personal data protection under Polish and European law.
- Imparting practical knowledge regarding the new regulations governing the processing of personal data.
- Highlighting key legal risks associated with the implementation of the GDPR.
- Providing practical preparation for independently performing the duties of a Personal Data Protection Officer.
Personal Data Protection Officer - Advanced Level
14 HoursPurpose of the Training
- Gaining practical knowledge on how to perform the tasks of the Inspector
- Gaining practical knowledge of how to audit and how to assess risk
- Providing practical knowledge about the new rules for the processing of personal data
Veritas Backup Exec Administration and Configuration
10 HoursVeritas Backup Exec offers a comprehensive data protection solution designed for virtual, physical, and cloud environments.
This instructor-led live training (available online or onsite) is tailored for intermediate-level IT infrastructure professionals looking to configure and manage Veritas Backup Exec to ensure secure, efficient, and effective backup and recovery processes.
Upon completion of this training, participants will be equipped to:
- Grasp the architecture and key features of Veritas Backup Exec.
- Install and set up a backup solution using Backup Exec.
- Create and manage backup and restore jobs.
- Develop fundamental backup and recovery strategies.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To arrange customized training for this course, please contact us to make the necessary arrangements.