GDPR for IT & Software Professionals training course

What will the GDPR mean for your organisation's Software Development Lifecycle? Start on the journey to compliance and Learn the tools and technologies available to help?

JBI training course London UK

"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"

Brian Leek, Data Analyst, May 2022

Public Courses

03/08/26 - 2 days
£1500 +VAT
14/09/26 - 2 days
£1500 +VAT
26/10/26 - 2 days
£1500 +VAT

Customised Courses

* Train a team
* Tailor content
* Flex dates
From £1200 / day
EDF logo Capita logo Sky logo NHS logo RBS logo BBC logo CISCO logo
JBI training course London UK

  • Data Protection fundamentals
  • GDPR Scope GDPR Principles GDPR Definitions
  • Lawful Bases of Processing
  • Consent
  • Children
  • Special Categories of Data
  • Transparency
  • Rights of Data Subjects
  • Controller and Processor
  • Data Protection by Design and by Default
  • Security of Processing
  • International Transfers
  • Supervisory Authorities
  • Penalties

 

Our course will not only provide IT and software professionals with foundational knowledge and understanding of GDPR, but build on this to ensure that delegates take away a practical, realistic and balanced appreciation for how GDPR works in practice. Past delegates have told us that before attending this course they did not understand the thinking behind GDPR, what GDPR terminology meant or what the implications of GDPR for IT and software professionals are. While this course includes high level strategic content suitable for legal general counsels, CIOs, CTOs and other senior IT leaders, the focus is on practical advice for IT and software professionals, enabling delegates to appreciate:

1. The global political, economic, social and technological background to GDPR;

2. How GDPR affects Data Protection throughout the world, not only within the EU/EEA;

3. How to approach GDPR in a fully-compliant, yet pragmatic and economical way;

4. Why GDPR restricts International Transfers of Personal Data outside the EU/EEA, except to countries which have an EU Adequacy decision;

5. The nature of the Data Subject rights which GDPR provides both to individuals living in the EU/EEA and to people living worldwide whose Personal Data is processed in the EU/EEA or on behalf on an EU/EEA country;

6. How different Lawful Bases of Processing affect the costs and complexity of IT systems and how to comply with GDPR more efficiently;

7. What transparency means and why it is valuable to organisations and individuals;

8. What “Data Protection by Design and by Default” means and how to do this without significant costs, risks or delays;

9. Why it is important for Data Controllers to obtain written contractual GDPR compliance guarantees from Data Processors before Data Processing;

10. What “Records of Processing” are, why they’re needed and how to maintain them;

11. What “Security of Processing” and “Technical and Organisational Measures” mean and how to implement them “taking into account the state of the art”;

12. How to prepare for a “Data Breach” and minimise impacts;

13. What’s involved in performing a “Data Protection Impact Assessment” (DPIA) and how DPIAs can help with other aspects of GDPR compliance;

14. Who the GDPR regulators are and how they work together;

15. How GDPR evolves through case law and regulatory decisions;

16. How to proactively sustain GDPR compliance in the face of increasing security threats, technological changes and changes in society.

JBI training course London UK

IT and Software Professionals and senior business and IT leaders who need to understand and learn how to tackle the implications of GDPR for their organisation or clients.


5 star

4.8 out of 5 average

"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"

Brian Leek, Data Analyst, May 2022



“JBI  did a great job of customizing their syllabus to suit our business  needs and also bringing our team up to speed on the current best practices. Our teams varied widely in terms of experience and  the Instructor handled this particularly well - very impressive”

Brian F, Team Lead, RBS, Data Analysis Course, 20 April 2022

 

 

JBI training course London UK

Certification


Every delegate will be entitled to a certificate of achievement on completion of the course.

If you are missing your certificate - please use the link below to apply - you can also use this link to sign up for the JBI Training newsletter to receive technology tips directly from our instructors - Analytics, AI, ML, DevOps, Web, Backend and Security.
 



Our GDPR training course is aimed at IT and Software Professionals, who need to understand the impact of new EU legistlation and how to navigate the software development life cycle under the GDPR

Developed in response to the biggest shake up in European data protection and privacy for over two decades, this course prepares you to take the necessary steps to protect business continuity and strengthen organisational reputation in the UK and beyond.

The GDPR (General Data Protection Regulation) requires substantial work to assess the risks and implement new controls before it enters into law. This course will equip individuals and organisations with a solid knowledge of the practical implications of the GDPR which could ultimately avoid heavy fines and reputational damage.

Keep the course general or tailor it to your organisation, starting with a 1 day overview with follow-on sessions in which different business functions can realise the impact of GDPR more specifically.

Sit an optional exam and gain appropriate certification

JBI Training offers three GDPR and data privacy courses covering different audiences and levels of depth. The GDPR course is a four-day comprehensive programme covering all aspects of GDPR compliance for professionals who need an in-depth understanding of the regulation. GDPR for IT and Software Professionals is a two-day course tailored specifically to developers, architects, and technical teams who need to build GDPR compliance into the systems and software they design and build. GDPR for Non-EU Professionals is a two-day course designed for organisations and individuals outside the European Union who process the personal data of EU and UK residents and need to understand their obligations under GDPR. All courses are available as scheduled classroom sessions in London, as live online instructor-led training, or as customised onsite programmes for teams.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into force in May 2018 across the European Union. It sets out the legal requirements for how organisations collect, store, process, and share the personal data of individuals. Following Brexit, the UK adopted its own equivalent legislation — UK GDPR — which mirrors the EU regulation in most material respects and is enforced by the Information Commissioner's Office (ICO). GDPR matters for organisations because non-compliance can result in significant financial penalties — up to €20 million or 4% of global annual turnover, whichever is higher under EU GDPR — as well as reputational damage, regulatory enforcement action, and loss of customer trust. Any organisation that handles the personal data of EU or UK residents, regardless of where the organisation is based, is subject to GDPR obligations.
EU GDPR is the original regulation applicable across European Union member states, regulated and enforced by each member state's national supervisory authority. UK GDPR is the version of the regulation that was incorporated into UK law following Brexit, and is enforced by the Information Commissioner's Office (ICO) in the UK. In practice, UK GDPR and EU GDPR are very closely aligned in their core requirements — the lawful bases for processing, data subject rights, accountability obligations, and breach notification requirements are substantially the same. Key differences relate to international data transfer mechanisms, the role of the ICO versus EU supervisory authorities, and some specific provisions around research and national security. Organisations operating in both the UK and EU need to consider both regimes. JBI's GDPR courses cover both UK and EU GDPR.
The four-day GDPR course is a comprehensive programme covering the full scope of GDPR compliance. Topics include the history and context of data protection law, the scope and territorial reach of GDPR, the lawful bases for processing personal data, the rights of data subjects (including the right to access, rectification, erasure, portability, and objection), the obligations of data controllers and data processors, privacy by design and by default, data protection impact assessments (DPIAs), the role and responsibilities of the Data Protection Officer (DPO), data breach notification requirements, international data transfers, and the enforcement and penalty regime. It is suitable for data protection officers, compliance managers, legal and risk professionals, and senior managers who need a thorough working knowledge of the regulation.
The GDPR for IT and Software Professionals course is a two-day programme specifically designed for developers, software architects, database administrators, IT managers, and technical teams who need to implement GDPR compliance in the systems they build and maintain. It covers GDPR principles from a technical implementation perspective — including privacy by design and privacy by default, data minimisation and pseudonymisation techniques, encryption and security requirements, data retention and deletion in database systems, handling subject access requests from a technical standpoint, managing third-party processors and APIs, and the technical aspects of data breach detection and notification. It is a course for technical professionals who need to translate GDPR legal requirements into architectural and development decisions.
The GDPR for Non-EU Professionals course is designed for individuals and organisations based outside the European Union or United Kingdom who nonetheless process the personal data of EU or UK residents and are therefore subject to GDPR obligations. This commonly includes organisations in the United States, Asia-Pacific, Middle East, and other regions that operate websites, apps, or services accessible to EU and UK users, or that process EU and UK employee or customer data. The course covers the extraterritorial scope of GDPR, what obligations apply to non-EU data controllers and processors, the requirement to appoint an EU or UK representative, international data transfer mechanisms including Standard Contractual Clauses (SCCs) and adequacy decisions, and practical steps for achieving compliance from outside the EU.
A Data Protection Officer is a designated individual responsible for overseeing an organisation's data protection strategy and ensuring compliance with GDPR. Under GDPR, certain organisations are required to appoint a DPO — including public authorities, organisations that carry out large-scale systematic monitoring of individuals, and those that process special category data on a large scale. The DPO must have expert knowledge of data protection law and practices, operate independently, and act as the point of contact with the supervisory authority. The role, responsibilities, and statutory obligations of the DPO are covered in detail in the four-day GDPR course, making it appropriate preparation for individuals who are taking on or considering a DPO role.
GDPR requires that every processing activity involving personal data has a documented lawful basis. There are six lawful bases under GDPR: consent (the individual has given clear, informed, and freely given consent); contract (processing is necessary to perform a contract with the individual); legal obligation (processing is necessary to comply with a legal requirement); vital interests (processing is necessary to protect someone's life); public task (processing is necessary for a public authority to perform its official functions); and legitimate interests (processing is necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the individual's rights). Choosing and documenting the correct lawful basis for each processing activity is one of the most important practical aspects of GDPR compliance, and is covered in depth across all three JBI GDPR courses.
The use of AI systems — including large language models, automated decision-making tools, and data analytics platforms — raises significant GDPR considerations. GDPR Article 22 gives individuals the right not to be subject to solely automated decisions that have a significant effect on them, and requires transparency about automated processing. AI systems that process personal data must have a documented lawful basis, must comply with data minimisation principles, and must implement appropriate security measures. The use of personal data to train AI models raises additional questions around purpose limitation and consent. As AI adoption grows, understanding how GDPR applies to AI data processing is an increasingly important area for compliance, legal, and technical professionals. JBI's GDPR training addresses these considerations within the broader compliance curriculum.
Yes. All GDPR and data privacy courses at JBI can be delivered as customised closed-group programmes for corporate teams, onsite at your organisation's premises or online. Content can be tailored to your organisation's specific data processing activities, industry sector, existing compliance framework, and the roles of the delegates attending — for example, a programme for a financial services firm can focus on sector-specific regulatory requirements alongside GDPR, while a programme for a software development team can concentrate on technical implementation of privacy by design. JBI has delivered GDPR and compliance training for organisations including the BBC, NHS, RBS, Sky, EDF, and Capita.
Yes. Data protection law and its interpretation continue to evolve through ICO guidance, European Data Protection Board (EDPB) opinions, court judgements, and enforcement decisions. JBI's GDPR training content is continuously reviewed and updated to reflect these developments, including changes to international data transfer mechanisms, evolving guidance on consent and legitimate interests, ICO enforcement priorities, and the latest regulatory thinking on AI and data protection. Delegates learn the current state of GDPR compliance requirements rather than a static interpretation of the original 2018 regulation.

CONTACT
+44 (0)20 8446 7555

[email protected]

 

Copyright © 2026 JBI Training. All Rights Reserved.
JB International Training Ltd  -  Company Registration Number: 08458005
Registered Address: Wohl Enterprise Hub, 2B Redbourne Avenue, London, N3 2BS

Modern Slavery Statement & Corporate Policies | Terms & Conditions | Contact Us

POPULAR

AI training courses                                                                        CoPilot training course

Threat modelling training course   Python for data analysts training course

Power BI training course                                   Machine Learning training course

Spring Boot Microservices training course              Terraform training course

Data Storytelling training course                                               C++ training course

Power Automate training course                               Clean Code training course