Learners will understand basic data classification and risk assessment techniques so as to enable them to identify, assess and address personal data protection risks. At the end of the course, learners are able to identify and resolve risks in relation to data protection and DNC provisions, business processes and data intermediaries. Learners will also learn how to conduct a Data Protection Impact Assessment.
Course Objectives
You will have knowledge of the following:
- Basic data classification, data lifecycle, and risk identification and assessment techniques
- Internal protocols, past solutions and widely-known best practices in risk management or prevention with respect to data protection
- Risk management measures and implementation steps
- Data protection risks in relation to:
- DP and DNC provisions
- Business processes
- Data Intermediaries
- Electronic processing of Personal Data
- Data Protection Impact Assessment (DPIA) to identify, assess and address personal data protection risks
You will be able to perform the following:
- Identify risks and use SOPs to mitigate risks
- Conduct risk assessment using the DPIA
- Highlight red flags and other key findings in risk assessment report
- Propose processes and actions steps to address risks
- Propose enhancements to risk countermeasures
- Monitor and check compliance to personal data content clauses, contracts and technical/commercial agreements
- Manage contracts with third parties (including data intermediary) for products and services
- Monitor activities and performance of vendors
- Document changes and updates to contracts and agreements
- Monitor the effectiveness of security initiatives
- Identify security risks, threats and vulnerabilities
- Assist users on various techniques that can anonymise personal data
Pre-requisites
- Learner has attended and is competent for module titled Fundamentals of Personal Data
Protection Act or its equivalent
- Learners are assumed to be able to:
- Understand relevant organisational strategies, objectives, culture, policies, processes and products/services
- Have information gathering skills to gather and collate necessary data
- Have analytical skills to assess policies and procedures
- Have business writing skills to prepare management report
- Have interpersonal and communication skills to interact with relevant stakeholders
- Have facilitation skills to ask the right questions to elicit necessary information
- Be aware of compliance requirements of organisation
Hardware & Software
This course will be conducted as a Virtual Live Class (VLC) via Zoom platform. Participants must own a zoom account and have a laptop or a desktop with “Zoom Client for Meetings” installed. This can be downloaded from https://zoom.us/download
System Requirement |
Must Have:
Please ensure that your computer or laptop meets the following requirements.
Good to Have:
Not Recommended: Using tablets is not recommended due to their smaller screen size, which could cause eye strain and discomfort over the course of the program's duration. |
Course Outline
Introduction
- Data classification
- Data lifecycle
- Risk identification and risk assessment techniques
Data protection risks relating to:
- DP and DNC processes
- Business processes
- Data Intermediaries
- Electronic processing of personal data
Risk rating/scoring
Responding to risks
- Risk modification
- Risk retention
- Risk avoidance
- Risk sharing
Data Protection Impact Assessment (DPIA)
- Conduct risk assessment using a DPIA
Managing contracts in compliance with PDPA
- Consent clauses
- Contracts and technical agreements
Managing risks with third parties/vendors/data intermediaries
- Conduct due diligence
- Monitor activities and performance
- Terms of contractual agreements
Categories
More Information
- NTUC LearningHub
Add a review