Skip to content
Home » Training Courses » Policy and Regulation » Data Protection Compliance – Policy, Governance, and Risk Management

Data Protection Compliance – Policy, Governance, and Risk Management

Overview

In an era where data breaches and regulatory scrutiny are on the rise, ensuring robust data protection compliance is essential for any organisation. This full-day training course provides a practical and strategic approach to developing and managing a comprehensive data protection compliance programme. Attendees will gain a deep understanding of key requirements under UK data protection laws, including GDPR, the Data Protection Act, and upcoming legislative changes. With expert guidance, real-life case studies, and interactive discussions, this course will equip participants with the skills to strengthen their organisation’s data governance, accountability, and risk management practices.

Whether you are responsible for data protection, compliance, legal oversight, or IT security, this course will give you the tools, policies, and strategies needed to meet regulatory expectations and mitigate risks. From registering data processing activities and conducting internal audits to handling data breaches and managing third-party processors, attendees will leave with practical knowledge to enhance compliance and foster a culture of data protection within their organisation. If you want to stay ahead of evolving regulations and safeguard your organisation’s reputation, this is a must-attend course.

Learning Outcomes: 

  • Understand the history of UK data protection laws and upcoming legislative changes.
  • Develop and manage a data protection compliance programme within your organisation.
  • Demonstrate ‘accountability’ to internal and external stakeholders.
  • Identify key compliance tools, including Data Protection Impact Assessments (DPIAs) and Registers of Processing Activities.
  • Learn when and how to communicate with regulators such as the Information Commissioner’s Office (ICO).
  • Implement effective policies for consent management, data retention, and privacy notices.
  • Strengthen staff training and awareness programmes to promote a data protection culture.
  • Conduct internal audits and assess third-party data processing agreements.
  • Understand international data transfer risks and compliance requirements.
  • Build strong relationships with boards, senior management teams, and staff to embed data protection into organisational culture.

Agenda

9:30
Registration and GovPD Welcome Address 
09:40
Brief History of Data Protection
10:00
Your Organisation
  • Identifying who should be on your data protection team
  • Defining the relationship with the board, senior management and staff
  • Promoting a good data protection culture
  • Identifying the internal and external data protection risks facing your organisation.
11:00
Break
11:30
Your Data Protection Compliance Tools (Part 1)
  • Record of Processing Activities (RoPA)
  • Staff Training and Awareness Programmes
  • Consent Management
  • Data Protection & Information Security Policies
13:00
Lunch
13:40
Your Data Protection Compliance Tools (Part 2)
  • Data Protection Impact Assessments
  • Conducting Internal Audits
  • Data Processor Due Diligence
  • International Transfer Risk Assessments
15:00
Comfort Break
15:20
Keeping on Top of Data Protection Legislation
  • When to communicate with Regulations
  • How to keep up to date with data protection laws
  • Data (Use and Access) Act 2025
  • Useful Resources
16:20
Trainer’s Summary and Q&A

*Programme subject to change

Who should attend?

This course is designed for professionals responsible for overseeing, implementing or supporting data protection and compliance activities within their organisation. It is particularly suitable for:

  • Data Protection Officers (DPOs) and GDPR leads
  • Information Governance and compliance professionals
  • Risk, audit and assurance managers
  • Legal and regulatory compliance teams
  • IT, cybersecurity and information security professionals
  • HR professionals handling employee data and records management
  • Senior managers and directors responsible for governance, risk or organisational compliance
  • Public sector, NHS, education and private sector staff with data protection responsibilities
  • Anyone involved in developing policies, conducting DPIAs, managing data breaches or overseeing third-party processors

The course is suitable for both experienced practitioners seeking to strengthen or refresh their compliance approach and professionals newer to data protection who need a practical understanding of UK GDPR and organisational accountability requirements.

Course Instructor

Kellie Peters

Kellie Peters is a seasoned GDPR and Data Protection Consultant with an extensive background in data governance, compliance, and security. As the co-founder of Databasix UK Ltd, she has spent nearly a decade providing strategic data protection consultancy to organisations across multiple industries, including healthcare, public sector, and corporate enterprises. Prior to this, Kellie held senior roles in Public Health England and Solutions for Public Health, where she played a pivotal role in data management, regulatory compliance, and stakeholder engagement. She successfully led national initiatives, including the design and rollout of England’s chemotherapy national patient-based database, ensuring compliance with data protection and governance frameworks.

With over 20 years of experience, Kellie has specialised in GDPR audits, internal compliance programmes, and regulatory risk assessments. As an Outsourced Data Protection Officer (DPO), she has provided guidance on data breach management, DPIAs, vendor due diligence, and policy development. Her expertise extends to conducting internal audits, reviewing data protection impact assessments, and advising on international data transfers. Having worked in both governmental and private sector environments, Kellie brings a wealth of knowledge in navigating complex data protection regulations and ensuring organisations remain compliant. Her deep understanding of data protection law, regulatory frameworks, and risk mitigation strategies makes her exceptionally well-placed to deliver expert-led training in data protection compliance.

Get In Touch