ICS CDPP
ICS Certified Data Protection Practitioner
Descrizione
Holders of the ICS Certified Data Protection Practitioner certificate from the Irish Computer Society have a practical understanding of the Irish data-protection framework, the General Data Protection Regulation (GDPR), data-subject rights and the responsibilities of organisations processing personal data.
Exam Chapter 1: Irish Data Protection Framework
Syllabus Section 1: Data Protection Rationale and Legislation Background
- 1.1. Understand the purpose of privacy and data-protection law
- 1.2. Explain why individuals require protection when their personal data is collected, used, stored and disclosed
- 1.3. Understand the development of data-protection legislation in Ireland and Europe
- 1.4. Recognise the relationship between Irish data-protection legislation and European Union law
- 1.5. Understand the role of data protection in balancing individual rights with legitimate organisational and societal interests
Syllabus Section 2: General Data Protection Regulation (GDPR)
- 2.1. Explain the legal status and direct applicability of the GDPR
- 2.2. Understand how the GDPR applies throughout the European Economic Area
- 2.3. Distinguish between an EU Regulation and an EU Directive
- 2.4. Recognise the areas in which the GDPR permits Member States to introduce supplementary national rules
- 2.5. Understand the territorial scope of the GDPR
- 2.6. Recognise when processing may fall outside the scope of the GDPR, including processing for purely personal or household activities
Syllabus Section 3: Key Data Protection Terms
- 3.1. Define personal data and recognise information relating to an identified or identifiable individual
- 3.2. Distinguish between a data subject, controller, processor, recipient and third party
- 3.3. Identify special categories of personal data under Article 9 GDPR
- 3.4. Understand the separate rules applying to personal data relating to criminal convictions and offences
- 3.5. Distinguish between anonymised and pseudonymised data
- 3.6. Understand when structured paper records form, or are intended to form, part of a filing system
- 3.7. Recognise the meaning of processing, profiling and automated decision-making
Exam Chapter 2: Data Subject Governance
Syllabus Section 4: Subject Access Request
- 4.1. Recognise valid written and verbal subject access requests
- 4.2. Understand that a requester does not need to refer specifically to the GDPR
- 4.3. Apply reasonable and proportionate identity-verification measures
- 4.4. Understand the information and personal data that must be provided in response to a subject access request
- 4.5. Identify information that does not normally need to be disclosed in a subject access response
- 4.6. Apply the one-month response period and understand when an extension may be permitted
- 4.7. Recognise circumstances in which personal data may be temporarily withheld while identity or another legitimate issue is resolved
- 4.8. Understand the individual’s right to complain to the Data Protection Commission about an inadequate response
Syllabus Section 5: Data Protection Principles and Concepts
- 5.1. Explain the principle of lawfulness, fairness and transparency
- 5.2. Understand purpose limitation and the restrictions on using personal data for incompatible purposes
- 5.3. Apply the principle of data minimisation
- 5.4. Explain the controller’s responsibility for ensuring that personal data is accurate and, where necessary, kept up to date
- 5.5. Apply the storage-limitation principle when establishing retention periods
- 5.6. Understand the requirements relating to integrity, confidentiality and security
- 5.7. Explain the accountability principle and the requirement to demonstrate compliance
- 5.8. Apply data-protection principles to electronic and structured paper records
Syllabus Section 6: Lawful Bases for Data Processing
- 6.1. Identify the lawful bases available under Article 6 GDPR
- 6.2. Understand when processing is necessary for the performance of a contract or for taking steps before entering into a contract
- 6.3. Explain when processing is required to comply with a legal obligation
- 6.4. Understand processing carried out in the public interest or in the exercise of official authority
- 6.5. Apply the necessity and balancing tests associated with legitimate interests
- 6.6. Understand the limitations on public authorities relying on legitimate interests when performing public tasks
- 6.7. Identify the conditions that may permit the processing of special category personal data
- 6.8. Recognise processing necessary for employment-law obligations, legal claims, vital interests or substantial public interest
Syllabus Section 7: Consent
- 7.1. Explain the GDPR definition of consent
- 7.2. Understand the requirements that consent be freely given, specific, informed and unambiguous
- 7.3. Recognise the need for a clear affirmative action
- 7.4. Understand why consent may be invalid where there is an imbalance of power
- 7.5. Explain why consent may be unsuitable in certain employment situations
- 7.6. Understand the controller’s obligation to demonstrate that valid consent was obtained
- 7.7. Explain the individual’s right to withdraw consent as easily as it was given
- 7.8. Distinguish consent from other lawful bases for processing
Syllabus Section 8: Data Subject Rights
- 8.1. Identify the principal rights available to individuals under the GDPR
- 8.2. Understand the rights to rectification, erasure and restriction of processing
- 8.3. Explain the right to object to processing, including processing for direct-marketing purposes
- 8.4. Identify when the right to data portability applies
- 8.5. Understand the conditions applying to solely automated decision-making and profiling
- 8.6. Explain the right to obtain meaningful information about the logic involved in an automated decision
- 8.7. Recognise when an individual may request human intervention or contest an automated decision
- 8.8. Understand the right to seek compensation for material or non-material damage
Exam Chapter 3: Data Protection Accountability
Syllabus Section 9: Data Protection Transparency
- 9.1. Explain the purpose of a privacy notice
- 9.2. Identify the information that must be provided when personal data is collected directly from an individual
- 9.3. Understand the transparency obligations that apply when personal data is obtained from another source
- 9.4. Apply the deadlines for providing Article 14 transparency information
- 9.5. Understand the requirement to provide information before the first disclosure of indirectly obtained personal data
- 9.6. Recognise the importance of clear, accessible and plain-language privacy information
- 9.7. Understand the information that must be included in a controller’s Record of Processing Activities
- 9.8. Explain the GDPR accountability framework and the removal of the former general processing-notification requirement
Syllabus Section 10: Personal Data Breaches
- 10.1. Recognise when a security incident constitutes a personal data breach
- 10.2. Distinguish between confidentiality, integrity and availability breaches
- 10.3. Assess whether a breach is likely to result in a risk to individuals’ rights and freedoms
- 10.4. Understand when the Data Protection Commission must be notified
- 10.5. Apply the requirement to notify the supervisory authority without undue delay and, where feasible, within 72 hours
- 10.6. Understand when a breach must also be communicated to affected individuals
- 10.7. Explain the controller’s obligation to document personal data breaches
- 10.8. Understand the processor’s duty to notify the controller without undue delay
- 10.9. Apply breach-notification responsibilities in joint-controller arrangements
Syllabus Section 11: Key Players and Their Roles
- 11.1. Distinguish between the responsibilities of controllers and processors
- 11.2. Understand how joint controllers determine their respective responsibilities through a transparent arrangement
- 11.3. Explain the requirement for controllers to select processors that provide sufficient guarantees
- 11.4. Understand the purpose and mandatory content of a Data Processing Agreement
- 11.5. Recognise the processor’s confidentiality, security and assistance obligations
- 11.6. Explain the role, independence and statutory tasks of the Data Protection Officer
- 11.7. Identify when a controller or processor must appoint a Data Protection Officer
- 11.8. Understand the requirements that apply where an organisation voluntarily appoints a formal DPO
- 11.9. Distinguish the DPO’s advisory and monitoring role from the controller’s operational responsibility for compliance
Exam Chapter 4: Regulatory Oversight
Syllabus Section 12: Supervisory Authority
- 12.1. Understand the role of the Data Protection Commission as Ireland’s supervisory authority
- 12.2. Identify the investigative, corrective, advisory and authorisation powers of a supervisory authority
- 12.3. Explain the supervisory authority’s responsibility to promote public awareness and understanding of data-protection rights and risks
- 12.4. Understand the supervisory authority’s power to require information from organisations
- 12.5. Recognise the supervisory authority’s power to issue warnings, reprimands, processing restrictions and administrative fines
- 12.6. Distinguish data-protection regulation from the responsibilities of other national regulatory bodies
Syllabus Section 13: Organisational Responsibilities
- 13.1. Explain the controller’s responsibility for compliance with the GDPR
- 13.2. Understand the requirement to implement appropriate technical and organisational measures
- 13.3. Apply data protection by design and by default
- 13.4. Develop and apply appropriate retention schedules
- 13.5. Understand the importance of documented policies, procedures and records
- 13.6. Explain the requirement to maintain Records of Processing Activities where applicable
- 13.7. Understand the need for appropriate processor due diligence and contractual oversight
- 13.8. Apply confidentiality and access-control requirements to employees and other authorised persons
- 13.9. Understand organisational responsibilities relating to direct marketing and individual objections
Syllabus Section 14: Regulation and Enforcement
- 14.1. Understand how the GDPR is enforced by supervisory authorities and national courts
- 14.2. Explain the right of individuals to lodge a complaint with the Data Protection Commission
- 14.3. Understand the distinction between regulatory enforcement and civil claims for compensation
- 14.4. Recognise the circumstances in which corrective measures and administrative fines may be imposed
- 14.5. Explain the factors considered when determining the appropriate level of an administrative fine
- 14.6. Understand the treatment of processing for journalistic, academic, artistic or literary expression under Irish law
- 14.7. Explain when specified GDPR provisions may be restricted to protect freedom of expression and information
- 14.8. Recognise relevant offences and court-imposed penalties under Irish data-protection legislation
Exam Chapter 5: Data Protection Risk Management
Syllabus Section 15: Risks
- 15.1. Identify risks arising from the collection, use, storage, disclosure and deletion of personal data
- 15.2. Assess the likelihood and severity of risks to individuals’ rights and freedoms
- 15.3. Understand the distinction between risks to individuals and commercial or reputational risks to an organisation
- 15.4. Identify risks associated with special category data, financial data and other sensitive information
- 15.5. Apply data minimisation, access controls, pseudonymisation and encryption as risk-reduction measures
- 15.6. Understand the importance of confidentiality, integrity, availability and resilience
- 15.7. Explain the need to restore access to personal data promptly following a physical or technical incident
- 15.8. Understand the importance of regularly testing and evaluating security measures
Syllabus Section 16: Data Protection Impact Assessment (DPIA)
- 16.1. Explain the purpose of a Data Protection Impact Assessment
- 16.2. Identify processing activities that are likely to result in a high risk to individuals’ rights and freedoms
- 16.3. Understand when a DPIA must be carried out
- 16.4. Explain why a DPIA must be completed before the relevant processing begins
- 16.5. Identify and assess risks during the design and development of a processing activity
- 16.6. Understand the controller’s responsibility for carrying out the DPIA
- 16.7. Explain the DPO’s responsibility to provide advice, where requested, and monitor the performance of the DPIA
- 16.8. Understand when prior consultation with the Data Protection Commission may be required
Syllabus Section 17: Infringements, Fines and Sanctions
- 17.1. Distinguish between the lower and higher tiers of GDPR administrative fines
- 17.2. Identify infringements that may fall within each fine tier
- 17.3. Understand that the maximum fine may be based on a fixed amount or a percentage of worldwide annual turnover, whichever is higher
- 17.4. Explain why an administrative fine must be effective, proportionate and dissuasive
- 17.5. Understand the potential liability of controllers and processors for GDPR infringements
- 17.6. Recognise when a processor may be responsible for acting outside or contrary to the controller’s lawful instructions
- 17.7. Understand the availability of civil compensation for material and non-material damage
- 17.8. Recognise criminal offences and sanctions established under Irish data-protection legislation
Syllabus Section 18: Overseas Transfer of Data
- 18.1. Understand when the GDPR rules on international transfers apply
- 18.2. Distinguish transfers within the EEA from transfers to third countries or international organisations
- 18.3. Explain the effect of an adequacy decision
- 18.4. Understand the use of Standard Contractual Clauses and other appropriate safeguards
- 18.5. Recognise the roles of controllers and processors in international data transfers
- 18.6. Identify the limited derogations available under Article 49 GDPR
- 18.7. Apply derogations relating to contracts, legal claims, important public interests and vital interests
- 18.8. Understand the need to assess the circumstances and risks associated with a proposed international transfer
Business Outcomes
Holders of the ICS Certified Data Protection Practitioner certificate can:
- Explain the Irish and European legal framework governing the processing of personal data
- Recognise personal data, special category personal data and the principal roles defined under the GDPR
- Apply the data-protection principles and identify an appropriate lawful basis for processing
- Respond appropriately to subject access requests and other exercises of data-subject rights
- Prepare and maintain privacy notices, retention schedules, Records of Processing Activities and Data Processing Agreements
- Understand the responsibilities of controllers, processors, joint controllers and Data Protection Officers
- Identify and assess personal data breaches and apply the relevant notification requirements
- Support organisational compliance through appropriate policies, security measures and accountability documentation
- Recognise when a Data Protection Impact Assessment is required and contribute to the assessment of high-risk processing
- Understand the powers of the Data Protection Commission and the potential consequences of non-compliance
- Identify appropriate safeguards and derogations for overseas transfers of personal data
- Apply Irish data-protection requirements to practical situations involving employment, direct marketing, healthcare, recruitment and customer information
In general, an ICS Certified Data Protection Practitioner has the knowledge required to support practical GDPR compliance, identify and manage data-protection risks, respond to individual rights requests and contribute to the responsible processing of personal data within an organisation.
Pubblico destinatario
The ICS Certified Data Protection Practitioner qualification is aimed at professionals who handle personal data, support data-protection compliance or need a practical understanding of the GDPR and Irish data-protection law.
It is relevant for people working in data protection, privacy, compliance, legal, human resources, information security, risk management, governance, marketing, customer service, records management and business operations.
This includes roles such as Data Protection Officers, data-protection leads, compliance officers, legal advisers, HR professionals, information security professionals, records managers, project managers, business analysts, department managers and employees responsible for processing personal data or responding to data-subject requests.
The qualification is also suitable for consultants, public-sector employees, business owners and professionals who advise organisations on privacy, governance, risk or regulatory compliance.
It is appropriate for anyone who wants to build a solid practical understanding of data-protection principles, lawful processing, individual rights, organisational accountability, personal data breaches, Data Protection Impact Assessments and international data transfers.
Holders of the ICS Certified Data Protection Practitioner certificate can demonstrate that they have the knowledge required to support responsible personal data processing and contribute effectively to GDPR compliance within an organisation.
Requisiti
There are no formal prerequisites for taking the ICS Certified Data Protection Practitioner exam. However, candidates should have an interest in data protection, privacy, regulatory compliance or the responsible handling of personal data.
It is strongly recommended that candidates also:
- Have some practical experience of working with personal data in areas such as compliance, legal, human resources, information security, marketing, customer service, records management or business operations.
- Have a basic awareness of the General Data Protection Regulation (GDPR) and the role of Irish data-protection law.
- Complete an ICS Certified Data Protection Practitioner training course delivered by a recognised training provider.
Relevant professional experience is helpful but not essential. The qualification is suitable both for candidates who are new to data protection and for experienced professionals who wish to formalise and demonstrate their knowledge of GDPR requirements and practical data-protection compliance.
Achieving the ICS Certified Data Protection Practitioner certificate provides a strong foundation for professionals who wish to take on greater responsibility in data protection, privacy, governance, compliance or risk management.
syllabi e simulazioni di prova sono in arrivo!
syllabi e simulazioni di prova sono in arrivo!
Prenota un esame di certificazione:
Brightest Private Exams
Esami elettronici individuali amministrati da un esperto Pearson in tempo reale tramite webcam (ora disponibile anche per ISTQB).
Brightest Center
Exam
In varie lingue presso uno dei 5200+ Test Center, registrarsi è facile tramite la pagina Brightest del sito web Pearson.
Brightest Green
Exam
Esame elettronico per gruppi composti da un minimo di 6 persone, disponibile in sei lingue diverse in qualsiasi parte del mondo.
Brightest Paper
Exam
Esperienza classica dell'esame cartaceo per gruppi di almeno 6 partecipanti in sempre più lingue disponibili.