GDPR in IT Training
For data protection inspectors and managers
and IT staff
Certificate and substantive support
after the training
8 key IT competencies
GDPR documentation templates
GDPR in IT Training
Organisations' drive for maximum flexibility in business processes, cloud data migration, multi-entity cooperation or outsourcing of certain operational areas means that IT infrastructure and systems must ensure the confidentiality, availability and integrity of processed data in a dynamic and changing environment.
Effectively combining security aspects with the ability to fulfil the rights of data subjects – in particular the right to erasure, portability and access to data – requires organisations to use a variety of software tools, develop a range of data processing procedures and assign the appropriate roles and responsibilities to individuals.
What's the detailed training schedule?
GDPR in IT
Knowledge in practice
Acquire eight new key skills
- 1.Understanding roles and responsibilities in the application of personal data protection rules.
- 2.Planning of a system in accordance with RODO.
- 3.Setting requirements in accordance with the principles of design by design and default by design by design.
- 4.Assessment of which tools will enable the rights of data subjects to be exercised in IT systems.
- 5.Selection/selection of safety measures appropriate to the risk level.
- 6.Building a secure IT infrastructure.
- 7.Understanding the security pitfalls in the cloud computing.
- 8.Involvement of the data protection inspector in a timely manner.
Guides
Training team

„We train in the way we wish to be trained. We discuss real-world problems and point out tools to help solve them.”
Tomasz Ochocki
Data Protection Officer (DPO) for the ODI content team
Materials to download

Templates of documentation to demonstrate compliance with the GDPR
See the full list of documentsOpinion of the participants
Tomasz G.
2 years ago
I wanted to thank you for the wonderful training I've had at your company, the materials were very well prepared, and the instructor has shown tremendous knowledge and experience.
Aleksandra P.
2 years ago
Training at a very high level, I highly recommend!!! Training materials very useful in everyday work.
Sławomir M.
2 years ago
Mrs. Mecenas, it was an honor to be able to take part in this training, and thank you very much for your professional approach and valuable practical guidance.
Wacław T.
3 years ago
The IOD course organized by ODO24 has met all my expectations, a very practical approach, concrete examples and professional support.
Maria K.
1 year ago
The training was conducted in a way that was understandable even to those without previous experience in this field.
Piotr N.
10 months ago
Very good training, a lot of practical examples, a little bit too little time to ask questions, but overall I'm satisfied.
Anna W.
8 months ago
A professional approach, a great atmosphere during the training, the instructor answered all the questions thoroughly, and I highly recommend ODO24!
Jan K.
1 year ago
It's the best personal data protection training I've ever had, specific examples from real life, not just a dry theory, I recommend it to anyone who works with GDPR.
Katarzyna J.
6 months ago
The training meets my expectations. A lot of practical knowledge, good materials. The only drawback is too much group, so less time for individual consultations.
Michał L.
4 months ago
Excellent training! A very competent conductor with vast experience. Everything explained in a clear and understandable way. The training materials are very useful.
Joanna D.
3 months ago
I recommend ODO24 training to anyone seeking a sound knowledge of the field of ODO: professional service, excellent organisation and excellent teaching facilities.
Andrzej S.
2 months ago
Sometimes the pace was a little too fast, but the conductor was happy to return to the topics discussed earlier at the request of the participants.
Our greatest value is the trust of our customers.
Each person who makes payment for the training at least 14 days before the date will receive a PLN 100 discount.
RODO in IT - questions and answers
We want our participants to be able to familiarise themselves with the materials before the training, therefore before it takes place we provide the training presentations and the complete RODO documentation corresponding to the purchased course.
After the training we want to be a support for our participants, therefore we provide access to legal advice, the ODO Nawigator application, and in the case of the trainings "DPIA and risk analysis" and "Practical DPO course" – 90-day access to the Dr RODO application and, additionally: a complete set of guides, a certificate confirming participation in the training and recommended articles that will help take further steps in personal data protection.
Yes, after completion of the training each participant receives a personalised certificate confirming their participation in the training.
Yes, it is even recommended. 😊 When conducting our training, we do not want it to be an ex cathedra lecture. We favour a workshop-based approach to prepare our trainees as best as possible for the challenges posed by personal data protection.
Due to the workshop format of our courses we endeavour to keep groups to no more than 12 participants.
If the training is financed at least 70% by public funds, this provides a basis for exemption from VAT. In such a case, in the registration form in the third step (Invoice) we ask you to select the option: "I declare that the training is financed at least 70% by public funds. Consequently, I request exemption from VAT".
In accordance with the regulations of our training courses, the selected service must be paid for no later than two days before the training.
Yes, in such a case please provide this information in the fourth step of our form, in the "Additional remarks" field.
This is not necessary. We conduct online training via the Microsoft Teams application, which also allows us to send a link that can be opened in a web browser.
This is not necessary; however, to facilitate asking questions and exchanging experiences, we recommend using a headset with a microphone.
Yes, in such a case please provide this information in the fourth step of our form, in the "Additional remarks" field.
In most cases we confirm the training course one week before the scheduled start date. We want to ensure that participants in our training courses have the opportunity to familiarise themselves with the materials in advance.
As soon as the training has concluded, the books will be sent by courier to the address provided in the registration.
We are aware that certain documents can sometimes present difficulties, so we will gladly help with completing them. In such cases, please contact our training coordinator.
Our training coordinator is available at the e-mail address: [email protected].
We also invite you to contact us by telephone at: 22 740 99 99 or +48 690 004 852
The first thing is certainly an IT audit: performing an analysis of the entire infrastructure, identifying and describing organisational and technical safeguards, and consequently indicating the areas where we should make changes. Risk analysis is the next stage, which will help us adapt documentation and systems to RODO. The risk analysis is one of the most important documents of the whole process, in which we assess the risk of vulnerabilities occurring for the resources present in our organisation. We conclude everything with a risk treatment plan and documentation compliant with RODO guidelines.
IT outsourcing is a good solution for organisations that do not have their own IT department; unfortunately, we cannot always count on full support in terms of RODO. At such times, entrusting the appropriate tasks to an external entity can help. It is the external entity that should identify any gaps – we can expect recommendations that improve the functioning of the entire organisation. Depending on the contract signed, we can expect additional benefits in the form of employee training, informational bulletins or support during the term of the agreement.
In accordance with the guidelines of RODO, the data controller is obliged to implement appropriate technical and organisational measures to ensure that processing is carried out in accordance with the Regulation and to be able to demonstrate this. The selection of appropriate hardware depends on the size of the organisation. Regardless of size, the first line of defence should be securing the interface between the public network and the LAN by using appropriate equipment: router, firewall, switch. It is on this equipment that we should enable services such as: DLP, IPS/IDS, port rules. The next challenge is authentication, assigning permissions, and monitoring access rights to IT systems and the software used in daily work: 2FA, login rules via AD, and performing backups. Regardless of technical safeguards, we should also remember the physical security of our organisation: external access control, monitoring systems, alarm systems, fire protection.
The security of IT systems is one aspect of the protection of personal data that we should attend to in daily work, but not the only one. Building user awareness is another very important aspect of protecting personal data.
In addition to standard first-day training, we should also take care of the employee's development throughout their period of employment by:
- •implementation of an e-learning platform;
- •informational newsletters regarding formal-legal aspects and information security;
- •a circular concerning current threats originating from the Internet;
- •external training;
- •internal intranet – publishing current procedures and policies accessible to users.
This is not precluded, although it may give rise to a conflict of interest which the data controller is obliged to prevent. Typically, the main duties of the IT systems administrator include administering the servers within which personal data are processed, implementing appropriate IT system safeguards and identifying threats. Consequently, a person responsible for the ongoing processing of personal data and for the security of those data in IT systems would simultaneously supervise the lawfulness of their own actions. Such a situation may lead to an actual lack of oversight over the compliance of data processing with legal provisions and to a clear conflict of interest. According to UODO, in such situations the assessment of whether the above-mentioned conflict of interest does not occur in the case of a particular person and the tasks they perform should always be made individually, taking into account the specific circumstances.
RODO says a lot about cybersecurity, because it aims to protect personal data and ensure that they are processed securely. A few key points regarding cybersecurity in the context of RODO are:
- •Appropriate technical and organisational measures: RODO requires that entities processing personal data implement appropriate technical and organisational measures to ensure the security of data.
- •Risk assessment: The data controller must carry out a risk assessment related to the processing of personal data, covering potential threats to data security and ways of minimising them.
- •Processing by external entities: RODO requires monitoring of entities processing personal data, such as cloud service providers, to ensure that they meet appropriate data security requirements.
- •Understanding of technology: The Data Protection Officer (DPO) should have a general understanding of IT technologies and information systems used in the organisation, including knowledge of computer networks, databases, operating systems and cloud infrastructure.
- •Incident management skills: The Data Protection Officer (DPO) should be able to effectively manage data security incidents, including responding to data breaches, conducting investigations and taking remedial actions.
- •Awareness of threats and trends: The Data Protection Officer (DPO) should be aware of current threats to data security and trends in cybersecurity and data protection in order to be able to take appropriate preventive measures.
- •Auditing skills: The Data Protection Officer (DPO) should have the ability to carry out data security audits, including assessing compliance with legal and regulatory requirements and the effectiveness of the data protection measures applied.
What our customers say about our services
Marcin Wieczorek

„I am very impressed with the high level of substantive expertise of the training staff"
From 13 to 17 March I attended the "Course for Information Security Administrators" organized by ODO 24 sp. z o.o. I am very impressed with the high substantive level of the training staff and the comprehensive program. Working as an ABI requires knowledge not only of legal provisions but also of IT matters, which ODO 24 took into account. Noteworthy is the curriculum, which gradually introduces increasingly advanced nuances of personal data protection, starting from the legal basics and ending with practical aspects of auditing and working with documents within a company. The complete set of materials, editable documents and publications I received will facilitate my daily work as an ABI. I can certainly recommend ODO 24 as a reliable partner offering training services of a high standard.
Magdalena Węglewska

„We can wholeheartedly recommend ODO 24 as a professional and reliable partner"
For many years we have consistently placed great importance on the protection of the personal data of our customers as well as our employees. We took an active part in creating the "Code of Good Practice for the Protection of Personal Data of Customers and Potential Customers,” developed jointly by GIODO and the Polish Automotive Industry Association. Due to the complexity and variability of the rules on personal data protection, as well as Mazda’s dynamic development in Poland and the increasing volume of data we process, we decided to entrust the ABI function to a company specialized in this field. The decision to use the services of ODO 24 was primarily influenced by the experience and competence of the team of experts, the comprehensiveness of the offering and its flexibility in adapting to our organization. After a year of cooperation we can recommend ODO 24 as a professional and reliable partner.
Agnieszka Karłowicz

„A practical approach, continuous advisory availability, and positive working relationships"
We have been working with ODO24 for over a year. For us it has been a year of peaceful breathing and a sense of security: at least regarding personal data protection :-) The people at ODO are professionals who explain matters that are incomprehensible to the average person in an understandable way. They understand not only their profession but, which is very important to us, business and its requirements. A practical approach, constant advisory availability, and great relationships — all of this means I can recommend this Company to anyone who wants to work and sleep peacefully.
Tomasz Siwicki

„I recommend the company ODO 24 as a professional partner"
For several years we have been cooperating with ODO 24 in the field of personal data protection. A professional team that efficiently helped us to comply with the requirements of the GDPR. We make use not only of the experts’ knowledge but also of professionally prepared e‑training, thanks to which we were able to train several hundred employees in a very short time. I highly recommend ODO 24 as a professional partner delivering services at the highest level.
Training online
Training in Warsaw
You don't like the training schedule?
Tell us about it, and we'll figure it out.

