Data protection, digital policy and cyber security

Data Protection: Refresher and Advanced Course for DPOs and Data Protection Experts

This course will help you to refresh and update your data protection knowledge. The most pressing data protection topics will be detailed by our speakers and practitioners, who are at the forefront of data protection. The course includes hands-on workshops designed to help you learn and share best practices within your organisation.

About this course

This Refresher and Advanced Course for DPOs and Data Protection Experts course will provide you with substantial and valuable knowledge in the field of data protection.

We believe in constantly updating professional knowledge, particularly in the field of data protection. In a time of unprecedented challenges posed by ever-evolving technologies and different ways to use personal data, continuous learning and updating your expertise is crucial.

The data protection officer (DPO) is a key element of accountability in every organisation as required by the General Data Protection Regulation (GDPR) And Regulation 2018/1725 (EUDPR). However, the expectations and knowledge required for the DPO are multifaceted. That requires not only mastering the GDPR or the EUDPR, but also being familiar with practical aspects of ensuring secure personal data processing and responding to data breaches.

This is why a multifaceted approach in delivering this Refresher and Advanced Course for DPOs and Data Protection Experts course is paramount. Experts and practitioners at the forefront of data protection will guide you along the legal framework of the European data protection legislation while elaborating on some of the most pressing privacy-related issues that have emerged and current topics and challenges that DPOs are facing nowadays.

This course is designed to help you to refresh and update your data protection knowledge. Concrete examples regarding the data protection legislative framework, analysis of the new CJEU case law, guidelines from the European Data Protection Supervisor (<EDPS) as well as relevant and realistic case studies will help you to refine your expertise and deepen your understanding of your duties and responsibilities. You will be able to benefit from the knowledge of the trainers to support the performance of your daily tasks, make it easier to deal with challenging and complex issues in a structured way, and take decisions that are pragmatic, but still compliant.

Successful completion of this course will renew your DPO certification.

You will learn:

  • How to deal with controllers’ expectations and manage diverging objectives in the business environment (stakeholder management);
  • How to understand the interplay between GDPR and other legal frameworks.
  • How to ensure data protection by design and by default in a fast-changing digital and legal environment;
  • How to assess data protection compliance and how it is interlinked with IT security;
  • Risk analysis and management;
  • How to assess issues related to personal data transfers;
  • What actions to take in case of personal data breaches;
  • How to implement controls.

Course methodology

We believe that practical know-how is the key to effective learning. This course therefore includes:

  • Individual preparation for the course – you are invited to bring along any information about the mission, vision, values and data protection (GDPR and EUDPR) framework and governance within your organisation for case study;
  • Group and individual assignments;
  • Practical exercises on DPO roles and responsibilities;
  • An interactive approach: the module’s structure will give you the opportunity to ask questions and share and discuss experiences, knowledge, needs and challenges with the trainers and other participants;
  • There will be time for note-taking on what you learn, so you can apply it to your own situation.

You will be able to:

  • facilitate the development of an effective data protection strategy and plan;
  • Be aware about the latest legal and case law developments.
  • draft specific policies and procedures;
  • manage data breaches;
  • ensure data protection compliant transfers of personal data;
  • define the pragmatic approaches to ensure GDPR compliance within your organisation;
  • support your organisation in identifying gaps to be addressed in view of GDPR compliance;
  • advise your organisation on how to manage personal data;
  • support a data protection communication and training plan;
  • develop your professional international network in the field of data protection.

After taking this course, you can join EIPA’s dedicated community of practice together with former participants. You will also have access to the course materials for three months after the course.

  • Managers and DPOs exposed to questions related to data protection and the management of the related risks, plans and solutions;
  • Data protection experts and advisors;
  • Research and educational administrators.
  • Certified DPOs;
  • Anyone in the public or private sector who is responsible for their organisation’s compliance with the GDPR and EUDPR.

Project number: 2511506

Course venue
European Institute of Public Administration (EIPA)
O.L. Vrouweplein 22
6211 HE, Maastricht
The Netherlands

Project Officer
Marieke Lardinois
Tel: +31 (0)43 32 96 205
m.lardinois@eipa.eu

Fee
The fee includes documentation, refreshments, lunches and a dinner. Accommodation and travel costs are at the expense of the participants or their administration.

Discounts
EIPA member fee
EIPA offers a discount to all civil servants working for one of EIPA’s supporting countries, and civil servants working for an EU institution, body or agency.

Who are the supporting countries?
Civil servants coming from the following EIPA supporting countries are entitled to get the reduced fee: Austria, Belgium, Bulgaria, Cyprus, Denmark, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Spain, Sweden.

For all other participants, the regular fee applies.

Loyalty coupon
As a token of appreciation we offer all our participants a loyalty coupon for one of our future courses. The offer can be shared with colleagues and relevant networks. The coupon will expire one year after its release. This discount is not cumulative with other discounts, except for the EIPA member fee.

Meals
Dietary preferences can be indicated on the registration form.

Hotels
EIPA has a special price arrangement with a few hotels. The hotels are within walking distance of EIPA. Payment is to be made directly and personally to the hotel upon checking out.

Confirmation
Confirmation of registration will be forwarded to participants on receipt of the completed online registration form.

Payment
Prior payment is a condition for participation.

Cancellation policy
For administrative reasons you will be charged €150 for cancellations received within 15 days before the activity begins. There is no charge for qualified substitute participants.

EIPA reserves the right to cancel the activity up to 2 weeks before the starting date. In that case, registration fees received will be fully reimbursed. EIPA accepts no responsibility for any costs incurred (travel, accommodation, etc.).

A few days before the start of the course you will receive the log-in details for accessing the course materials. You can log in here.

Our experts

Carlo Piltz

Carlo Piltz

Data protection, IT security and IT law

Programme

08.30Registration of participants
09.00Welcome: objectives of the course
Florina Pop, Data Protection Expert, EIPA, Maastricht (NL)
09.15Technological Trends and New Supervision Strategy
Gijs de Haan, Senior Adviser Surveillance Strategy, Dutch Data Protection Authority, The Hague (NL) (TBC)
10.15Q&A
10.30Coffee Break
11.00The interplay between the EU AI Act and the GDPR: present and future challenges for Data Protection Officers in the era of Artificial Intelligence
Robert Bateman, Data Protection Consultant, Privacy Partnership, Brighton (UK)
12.00Q&A
12.15Lunch break at EIPA restaurant
13.45Creating a safer online space: the interplay between the GDPR and the DSA
Dr Mark Leiser, Regulatory Theorist | Expert in AI Regulation, Consumer & Data Protection, Fundamental Rights, Digital Law, Platform Regulation, Deceptive Design
14.45Q&A
15.00Coffee Break
15.30Data Processing Agreements, Contracts, and Transfers of Personal Data
Dr. Carlo Piltz, Lawyer/Partner at Piltz Legal, Berlin (DE)
16.30Workshop on Data Processing Agreements & Contracts (with transfer of data)
Dr. Carlo Piltz
17:15Q&A
17.30End of the day
19.00Dinner at a restaurant in Maastricht
08.45Opening of the online platform
09.00Hands-on Exercise (interactive workshop)
Gloria Folguera Ventura, DPO, EUIPO, Cristobal Lander Rodriguez, Deputy DPO, EUIPO
11.00Coffee Break
11.30Data Protection Risk Framework: Evaluation and Control inside your Organisation
Gloria Folguera Ventura
12.15Q&A
12.30Lunch break at Hotel Derlon
13.45Respond to Data Subject’s Rights: Practical Approaches (interactive workshop)
Larisa Munteanu, PhD Researcher, Junior Fellow at Erasmus Center of Law and Digitalization, Department Law & Business and Director of Protector PriVit, Rotterdam (NL)
14.30Q&A
14.45Coffee Break
15.15Personal Data Outside the EU: How to conduct a Data Transfer Impact Assessment (DTIA) (interactive workshop)
Spyridon Makris, Lawyer serving European and International Affairs, CNIL, Paris (FR)
17.30End of the day
09.00Tips and tricks for successfully completing DPIA
Sjoera Nas, Sr. Privacy Consultant, Privacy Company, The hague (NL)
10.00Coffee Break with Limburg treat
10.30Tips and tricks for successfully completing DPIA (Interactive workshop)
Sjoera Nas
12.00Lunch at EIPA Restaurant
13.15Recent Relevant Case Law for Data Protection Officers
Dr Florin Coman-Kund, Senior Expert in EU Governance, EIPA, Maastricht (NL)
14.15Q&A
14.30How to Audit an ICT Provider – in Practice (interactive workshop)
Brian Honan, Director, BH Consulting, Dublin (IE)
15.30Q&A
15.45How to Audit and ICT Provicer – in Practice (interactive workshop)
Brian Honan
16.45Q&A
17.00Concluding Remarks
17.15End of the course

Why you should book this course

What former participants say

Data Protection: Refresher and Advanced Course for DPOs and Data Protection Experts

Confirmed
27 Oct 2025 - 29 Oct 2025
Maastricht (NL)
Register before: 23 Oct 2025
 1.625 per attendee
 1.460 for EIPA members

Related courses

Register before: 23 Oct 2025