Over 71,000 students

Privacy & Data Protection Foundation – PDPF (2026)

Official EXIN

  • Duration: 16 hours
  • Portuguese and English
5.0 · PeopleCert Pass Rate 99%

Corporate training clients

About the course

About the Course

This course is a complete introduction to the fundamentals of privacy and data protection under the GDPR (the European Union's General Data Protection Regulation), structured into comprehensive modules leading to your international certification as a Data Protection Officer (DPO).

The first module covers the importance of privacy and data protection, the context of European legislation, the legal definition of personal data and the fundamental rights of data subjects.

The second module deals with organising data protection within companies, including meeting GDPR requirements, the obligations and records of controllers and processors, the role of supervisory authorities and the rules for international data transfers.

The third module presents advanced governance practices such as Privacy by Design & Default, the Data Protection Impact Assessment (DPIA), Data Lifecycle Management (DLM) and Compliance Audits, along with guidelines for handling data online, cookies and social media.

The fourth module — updated to the new exam standard — goes deeper into the critical challenges of Artificial Intelligence (AI) and Machine Learning under the GDPR, the new European regulatory ecosystem (such as the AI Act, DORA and NIS2), and the new rules for global transfers, including the EU-U.S. Data Privacy Framework.

The course is aimed at privacy and information security professionals, data managers, lawyers and other specialists who need to master the concepts and practices of data protection.

This course is part of the DPO Track. To become an EXIN certified Data Protection Officer, you must complete this training in combination with the Information Security exams (ISFS / ISO 27001) and the professional level (PDPP). The EXIN Certified Data Protection Officer certification naturally starts at the Foundation level. Because information security is vital for aspiring DPOs, the InfoSec discipline is a mandatory part of the track, giving candidates a broad, multidisciplinary understanding of corporate security.

DPOs play a vital role in organisations that process large volumes of data. Business digitalisation and rapid technological advances require companies of every size to take the right measures to handle data responsibly, shielding their business and protecting their customers.

Combined with the EXIN Privacy & Data Protection Foundation certification, this gives candidates a broad understanding of security as a whole.

DPOs play a vital role in organisations that process large amounts of data. Business digitalisation means the vast majority of companies are processing ever-growing volumes of data.

To protect their customers and themselves, these organisations need to make sure they take the right measures to handle data responsibly.

ITIL Foundation course dashboard
71k+ Certified students
99% Exam pass rate
15+ Years of excellence
500+ Corporates served

Who should attend

Target Audience

The target audience for this course is made up of professionals working with data protection and privacy, including, for example, data protection officers (DPOs), information security professionals, project managers, consultants and lawyers working in the privacy and data protection field.

The course suits both beginners who want a basic understanding of data protection concepts and regulations, and those who want to deepen their knowledge and prepare for the EXIN PDPF exam.

Certification & exam

Exam and Certification

This course prepares you for the official EXIN PDPF certification exam.

Exam language
Portuguese and English
Number of questions
40 questions
Test duration
1 hour
Passing grade
65% (26/40)
Difficulty level
Easy
Prerequisites
EXIN strongly recommends the PDPF preparatory course
Open-book exam
No
Exam format
Online
  • 99

    Pass rate among PMG Academy students

    Our students consistently outperform global averages. The content is developed by the official translator of the PeopleCert exam itself.

  • 1y

    Exam voucher validity

    Your included PeopleCert exam voucher is valid for 12 months, giving you full flexibility to schedule when you’re ready.

  • T2

    Take2 re-sit option available

    Optional Take2 re-sit and PeopleCert Plus Membership are available at checkout for complete peace of mind.

Adriano Martins Antonio, ITIL Master and course instructor

About the instructor

About the Instructor

15 years of training excellence with over 71,000 students who have passed.

Adriano is an ITIL Master, consultant and author of 6 books, bringing 25 years of experience and more than 50 certifications in IT Management, Security and Governance. As the leader of the largest ITSM and DPSM community (over 220,000 YouTube subscribers), he combines his MBA from FGV — one of the world's leading business schools — with a specialization in Neuroscience to guide a global network of more than 71,000 students. His mission is clear: to demystify complex management and turn technical knowledge into tangible value and market impact.

Official translator of the ITIL Foundation Guide (Version 5)

71k+
Students trained
220k
YouTube subscribers
25y
Years of experience

Curriculum

What you will learn

  • Duration: 16 hours
  • 5 modules
  • Knowledge test per module
  • Official PeopleCert aligned
  • 00 Module 1 - Fundamentals of Privacy 42 lessons
    • Welcome
    • GDPR and LGPD
    • Course Introduction
    • About the Exam
    • Module Objectives
    • Why Protection and Privacy Are Such Important Issues
    • Legacy of Regulations and Laws
    • Timeline
    • Related EU Legislation
    • Considerations, Explanations or Preamble
    • Privacy and Data Protection
    • Personal Data
    • Definition of Personal Data
    • Examples of Privacy and Data Protection
    • Types of Personal Data
    • Special Personal Data
    • Data Controller
    • Data Processing
    • Need for a Data Protection Officer (DPO)
    • Data Controller and Data Processor
    • Responsibility of a Data Protection Officer (DPO)
    • Recipient and Third Parties
    • ISO/IEC 27001 and GDPR
    • Processing of Personal Data
    • Principles in Data Processing
    • Legitimate Grounds and Purpose Limitation
    • Purpose Limitation and Purpose Specification
    • Proportionality and Subsidiarity
    • Data Subject Rights
    • Transparency
    • Right of Access – Inspection – By the Data Subject
    • Rectification and Erasure
    • Right to Restriction of Processing
    • Obligation of Notification
    • Right to Data Portability
    • Right to Object
    • Data Breach
    • Breach Procedure
    • Notifying a Breach
    • The Role of Controllers in Notification
    • Notification of a Breach to the Affected Data Subject
    • PDPF – Module 1 Exercises
  • 01 Module 2 - Organising Data Protection 26 lessons
    • Module Objectives
    • Complying with GDPR Requirements
    • Legal Framework
    • Data Protection Impact Assessments
    • Detailed Records
    • Controller Record
    • Processor Record
    • Challenges in Records
    • Personal Data Breach Register
    • Supervisory Authorities
    • Responsibilities of the Supervisory Authorities
    • Tasks of a Supervisory Authority
    • Powers of a Supervisory Authority
    • Consistency Mechanisms
    • Cooperation between Authorities
    • Roles and Responsibilities Related to Data Breaches
    • Personal
    • General Conditions for the Imposition of Administrative Fines
    • One-Stop-Shop
    • Cross-Border Processing
    • Substantially Affect
    • Data Transfer
    • Data Transfer Framework
    • Data Transfer Conditions
    • Binding Corporate Rules (BCR)
    • PDPF – Module 2 Exercises
  • 02 Module 3 - Data Protection Practices 26 lessons
    • Module Objectives
    • Data Protection by Design and by Default
    • Data Protection by Design
    • Data Protection by Default
    • Those Involved in Data Protection
    • Processing the Data
    • 7 Principles of Data Protection by Design
    • Benefits of Applying the Principles
    • Written Contracts between the Controller and the Processor
    • Data Protection Impact Assessment (DPIA)
    • DPIA Objectives
    • Phases of a DPIA Process
    • Benefits of a DPIA
    • Data Lifecycle Management (DLM)
    • How to Improve Data Lifecycle Management
    • Data Protection Audit
    • Focus of the Data Protection Audit
    • Benefits of an Audit
    • Audit Methods
    • Marketing and Social Media Context
    • Marketing and Social Media Tools and Techniques
    • Prosumers
    • Cookies
    • Profile Creation
    • Big Data
    • PDPF – Module 3 Exercises
  • 03 PDPF - Module 4 - Artificial Intelligence and Cybersecurity 17 lessons
    • Module Objectives
    • Machine LearningRename
    • Algorithms and Data
    • The Danger of Bias (The Example of Predictive Policing)
    • Unpredictability From Conception
    • The Double Regulatory Burden (GDPR + AI Act)
    • The 6 Major Challenges of AI in the GDPR
    • Official Case Study: Fraud Detection
    • Ensuring Compliance in Practice
    • IAR Completion
    • The New Ecosystem of European Laws
    • International Transfers (Europe – USA)
    • The Top 5 Causes of Data Breaches
    • ISO 27701 Update and New Acronyms
    • The LGPD Trap (Final Warning)
    • We've reached the end
    • PDPF – Module 4 Exercises
  • 04 Preparatory Mock Exams for the PDPF Exam 7 lessons
    • PDPF Practice Test 1: 40 Questions
    • PDPF Practice Test 2: 40 Questions
    • PDPF Mock Exam 3: 40 Questions
    • PDPF Mock Exam 4: 40 Questions
    • PDPF Mock Exam 5: 40 Questions
    • PDPF Practice Test 6: 40 Questions
    • PDPF Mock Exam 7: 40 Questions

Student reviews

Trusted by professionals at leading organizations

5.0 Based on 200+ reviews
  • 5★ 92%
  • 4★ 6%
  • 3★ 2%
  • 2★ 0%
  • 1★ 0%
  • Crhistian Bergamini

    Anglo American

    O curso de Data Privacy da PMG foi muito enriquecedor, trazendo conceitos importantes de forma clara e aplicável ao dia a dia profissional. Uma excelente oportunidade para ampliar conhecimentos e reforçar a importância da proteção de dados relacioando a GDPR/LGDP.

    23 de agosto de 2026

  • Gustavo Oliveira

    Ipiranga Produtos de Petróleo S.A

    4 de março de 2026 O curso Privacy and Data Protection Foundation foi uma experiência extremamente enriquecedora e fundamental para aprofundar meu entendimento sobre proteção de dados e privacidade. Ao longo do curso, pude compreender de forma clara os principais conceitos relacionados à governança de dados, princípios de privacidade, bases legais para tratamento de dados pessoais, direitos dos titulares e responsabilidades das organizações. Um dos pontos mais relevantes foi a abordagem estruturada sobre frameworks internacionais e regulamentações como o General Data Protection Regulation (GDPR), que servem de base para diversas leis ao redor do mundo. O conteúdo foi apresentado de maneira didática e objetiva, facilitando tanto a compreensão teórica quanto a aplicação prática no contexto corporativo. A metodologia contribuiu para desenvolver uma visão estratégica sobre riscos, conformidade, segurança da informação e cultura organizacional voltada à proteção de dados. Além disso, o curso ampliou minha capacidade de identificar vulnerabilidades, propor melhorias em processos internos e compreender o papel da governança no fortalecimento da confiança entre empresas, clientes e parceiros. Recomendo fortemente o Privacy and Data Protection Foundation para profissionais que desejam atuar ou se especializar em privacidade, compliance, segurança da informação e gestão de riscos, pois oferece uma base sólida e alinhada às melhores práticas internacionais.entário....

Join professionals from these organizations

Impact

Training teams of 5 or more?

PMG Academy offers corporate licensing, team dashboards, progress tracking, and dedicated support — built around your organization’s schedule and compliance requirements.

local