The subject access request
A customer asks for everything you hold on them. Learn what counts, the clock you are on, and how to answer without leaking someone else’s data.
Compliance training that sticks because it is about a task, not a regulation. Someone asks for their data, a spreadsheet of customers needs sending, a new tool wants access. Each exercise builds the instinct that keeps the organisation on the right side of the rules.
A customer asks for everything you hold on them. Learn what counts, the clock you are on, and how to answer without leaking someone else’s data.
An erasure request lands. Work out what can be deleted, what must be kept, and why a backup is not an exception you can ignore.
A colleague needs a report, so a full customer export is on its way. Practise minimising data, masking fields, and sharing the least that does the job.
A laptop with personal data is gone. Understand what makes it notifiable, who to tell, and how the first hour shapes the next 72.
Marketing wants to email a list. Consent or legitimate interest? Walk the decision that decides whether you can send it at all.
A new SaaS tool will hold customer records. Check the processor, the contract, and where the data actually lives before you sign up.
Data is about to leave the region. Know when that is fine, when it needs safeguards, and how to spot a transfer hiding inside a support ticket.
A bot joins the call to transcribe. Under the EU AI Act and privacy law, who consents, what is recorded, and where does the transcript go?
Old records pile up because deleting feels risky. Learn why keeping everything is the risk, and how a retention schedule protects people.