Over 71,000 students

EXIN Privacy & Data Protection Professional – PDPP

Official EXIN

  • Duration: 24 hours
  • Portuguese and English
5.0 · PeopleCert Pass Rate 99%

Corporate training clients

About the course

About the Course

Validity period: by decision of the course organisation, PDPP is valid until 31/12/2026. Complete the course and generate your certificate of completion by that date to keep the option of taking the exam; otherwise you will no longer be eligible for it.

This course is updated with EXIN's new version of the “Privacy Information Management System (PIMS)” module, based on the ISO/IEC 27701 standard.

EXIN Privacy and Data Protection Practitioner is a certification that validates a professional's knowledge and understanding of European privacy and data protection legislation and its international relevance, as well as their ability to apply that knowledge and understanding to their daily professional practice.

Combined with the EXIN Privacy & Data Protection Foundation certification, this gives candidates a broad understanding of security as a whole. See the image below:

EXIN Privacy and Data Protection Practitioner is a certification that validates a professional's knowledge and understanding of European privacy and data protection legislation and its international relevance, as well as their ability to apply that knowledge and understanding to their daily professional practice.

With the ever-growing explosion of information flooding the internet, every company must plan how to manage and protect people's privacy and their data. As a result, many new laws in the EU, as well as in the US and many other regions, are being drafted to regulate privacy and data protection.

The European Commission published the General Data Protection Regulation (GDPR) in the EU, which means that, as of 25 May 2018, all organisations involved must comply with specific rules. This Practitioner-level certification builds on the topics covered by the Foundation exam, focusing on developing and implementing policies and procedures to comply with new and existing legislation, applying guidelines and best practices for privacy and data protection, and establishing a Data Protection Management System (DPMS).

The new standard in the ISO/IEC 27000 series — ISO/IEC 27701:2019 Security Techniques – Extension to ISO/IEC 27001 and ISO/IEC 27002 for Privacy Information Management – Requirements and Guidelines — is useful for organisations wishing to demonstrate GDPR compliance. The content of the new ISO standard helps organisations meet their GDPR obligations regarding the processing of personal data.

Neither the GDPR nor the ISO standard is part of the exam literature. However, the literature matrix in Chapter 4 is designed to show the link between the exam requirements, the literature, the GDPR and the ISO/IEC 27701:2019 standard, to give the certification a broader context.

The EXIN Privacy & Data Protection Practitioner certification is part of the EXIN Privacy & Data Protection qualification programme.

ITIL Foundation course dashboard
71k+ Certified students
99% Exam pass rate
15+ Years of excellence
500+ Corporates served

Who should attend

Target Audience

Exam language: Portuguese and English

Number of questions: 40 questions

Test duration: 2 hours

Passing grade: 65% (26/40)

Difficulty level: Intermediate

Prerequisites: PDPP preparatory course + Practical Course Exercises

Open-book exam: No

Exam format: Online

Certification & exam

Exam and Certification

This course prepares you for the official EXIN PDPP certification exam.

Exam language
Portuguese and English
Number of questions
40 questions
Test duration
2 hours
Passing grade
65% (26/40)
Difficulty level
Intermediate
Prerequisites
PDPP preparatory course + Practical Course Exercises
Open-book exam
No
Exam format
Online
  • 99

    Pass rate among PMG Academy students

    Our students consistently outperform global averages. The content is developed by the official translator of the PeopleCert exam itself.

  • 1y

    Exam voucher validity

    Your included PeopleCert exam voucher is valid for 12 months, giving you full flexibility to schedule when you’re ready.

  • T2

    Take2 re-sit option available

    Optional Take2 re-sit and PeopleCert Plus Membership are available at checkout for complete peace of mind.

Adriano Martins Antonio, ITIL Master and course instructor

About the instructor

About the Instructor

15 years of training excellence with over 71,000 students who have passed.

Adriano is an ITIL Master, consultant and author of 6 books, bringing 25 years of experience and more than 50 certifications in IT Management, Security and Governance. As the leader of the largest ITSM and DPSM community (over 220,000 YouTube subscribers), he combines his MBA from FGV — one of the world's leading business schools — with a specialization in Neuroscience to guide a global network of more than 71,000 students. His mission is clear: to demystify complex management and turn technical knowledge into tangible value and market impact.

Official translator of the ITIL Foundation Guide (Version 5)

71k+
Students trained
220k
YouTube subscribers
25y
Years of experience

Curriculum

What you will learn

  • Duration: 24 hours
  • 8 modules
  • Knowledge test per module
  • Official PeopleCert aligned
  • 00 Module 1 – Introduction 6 lessons
    • Welcome
    • GDPR and LGPD
    • PDPP Course Overview
    • Objectives and Target Audience of the PDPP Certification
    • Practical Activities
    • About the PDPP Exam
  • 01 Module 2 – Data Protection Policies 31 lessons
    • Introduction – Data Protection Policies
    • Reviewing the Main Definitions
    • Policies and GDPR
    • Policies and Compliance
    • Policy Elements
    • Policy Availability
    • Example of Data Protection Policy Topics
    • Information Security Policy
    • Content of Information Security Policies
    • Effective Policies
    • Data Protection by Design
    • Application of Data Protection by Design (by design)
    • Data Protection by Default
    • Application of Data Protection by Default (by default)
    • Data Protection Officers by Design and by Default
    • Processors and Data Protection
    • Third-Party Organizations and Data Protection
    • What Should Be Done in Practice
    • When Actions Should Be Taken
    • Data Protection by Design Framework
    • The 7 Fundamental Principles of Data Protection
    • 1: Proactive, Not Reactive; Preventive, Not Corrective
    • 2: Privacy by Default
    • 3: Privacy by Design
    • 4: Full Functionality – Positive-Sum, Not Zero-Sum
    • 5: End-to-End Security and Protection Throughout the Data
    • Data Life
    • 6: Visibility and Transparency
    • 7: Respect for User Privacy
    • Corporate Governance Framework
    • PDPP – Module 2 Exercise
  • 02 Module 3 – Privacy Information Management System (PIMS) 41 lessons
    • Introduction
    • What to expect from this module?
    • What is Private Information Management?
    • Examples of Problems Related to Personal Information
    • GDPR Principles
    • Those Involved in Privacy
    • Country of Operation
    • Management of Processing with Third Parties
    • What is 'Personal Information'
    • Reason for Processing Personal Information
    • What Needs to Be Considered
    • Internal and External Issues
    • Stakeholders
    • Balance between Organizations and Individuals
    • Format and Storage Medium
    • Subcontractor
    • ISO/IEC 27701
    • Documentation
    • Audit
    • Management System Review
    • Available Resources
    • Privacy Impact Assessment (PIA)
    • Privacy Risks
    • Privacy Risk Assessment
    • Perspectives by Amount of Information Processed
    • Applying PIMS Controls
    • Privacy Information Management Controls
    • Extension of ISO/IEC 27001 Controls
    • Additional Guidelines Aligned with ISO/IEC 27002
    • Conditions for Data Collection and Processing
    • Obligations for Data Subjects
    • Privacy by Design and by Default
    • Sharing, Transfer, and Disclosure of Personal Information
    • Annexes in ISO/IEC 27701
    • Dealing with Private Information Leaks
    • Compliance and Audit
    • Certification
    • Certification at Horizonte
    • Certification Audit
    • Additional Audit Applications
    • PDPP – Module 3 Exercise
  • 03 Module 4 – Controller, Processor and DPO Roles 34 lessons
    • Roles of the Controller, Processor, and Data Protection Officer (DPO)
    • Definition of the Role of the Data Controller
    • Details About the Data Controller
    • More Tasks of the Data Controller
    • Role of the Data Processor
    • Tasks of the Data Processor
    • More details about the Data Processor
    • Controllers and Processors outside the EU
    • Responsibilities of the Controller's Representative
    • Processing Records
    • Records as Evidence
    • Controller and Processor Records
    • Introduction to the Role of Data Protection Officer (DPO)
    • Data Protection Officer (DPO) Role Requirements – Core Activities
    • Requirements of the Data Protection Officer (DPO) Role – Large-Scale Processing
    • Requirements of the Role of Data Protection Officer (DPO) – Regular and Systematic Monitoring
    • Voluntary Designation of a DPO
    • Companies Sharing a DPO
    • DPO under a Service Contract
    • Publication of the DPO Contact
    • DPO Position
    • Provision of Resources
    • Independent Role of the DPO
    • Protection of the DPO Role
    • Conflict of Interest
    • Designating a DPO
    • DPO's First Task
    • Second Task of the DPO
    • Third, Fourth, and Fifth Tasks of the DPO
    • The DPO and the Organization
    • The DPO and the Supervisory Authority
    • Data Protection Impact Assessment and Risk Assessment
    • Internal or Contracted DPO
    • PDPP – Module 4 Exercises
  • 04 Module 5 – Data Protection Impact Assessment (DPIA) 23 lessons
    • Data Protection Impact Assessment (DPIA)
    • Introduction to the Data Protection Impact Assessment (DPIA)
    • Expected Results of the DPIA
    • Benefits of DPIA
    • Fundamentals of the Data Protection Impact Assessment (DPIA)
    • Stages of a DPIA
    • DPIA – 1 – Identify the Need for a DPIA
    • Reasons for Conducting a DPIA
    • Examples of DPIA Situations
    • DPIA – 2 – Describe the Information Flows
    • DPIA – 3 – Identify Privacy-Related Risks
    • Risk Assessment
    • A Little More About Risks
    • DPIA – 4 – Identify and Evaluate Privacy Solutions
    • Risk Treatment
    • Risk Register
    • Risk Management and Personal Data
    • DPIA – 5 – Complete and Record DPIA Results
    • DPIA – 6 – Integrate DPIA Results into a Project Plan
    • DPIA – 7 – Consult Stakeholders Throughout the DPIA
    • Consulting External Stakeholders
    • Who Needs to Be Involved in the DPIA
    • PDPP – Module 5 Exercises
  • 05 Module 6 – Data Breach, Notification and Incident Response 17 lessons
    • Data Breach, Notification and Incident Response
    • Data Security Breaches
    • What is a Personal Data Breach?
    • Forms of Data Breach
    • Vulnerabilities and Violations
    • Protecting Information
    • Responding to a Data Breach
    • Events and Incidents
    • Forms of Incidents
    • Incident Response Plans
    • Roles in Incident Management
    • Notification to the Supervisory Authority
    • Notification to Data Subjects
    • Exceptions to Notification of Data Subjects
    • Final Considerations
    • FIM
    • PDPP – Module 6 Exercises
  • 06 Module 7 – Mandatory Practical Exercises

    3 PDPP Practical Exercises

  • 07 Module 8 – Preparatory Practice Exams 3 lessons
    • Practice Exam 1: 40 Questions
    • Simulated 2: 40 Questions
    • Simulado 3: 40 Questions

Student reviews

Trusted by professionals at leading organizations

5.0 Based on 200+ reviews
  • 5★ 92%
  • 4★ 6%
  • 3★ 2%
  • 2★ 0%
  • 1★ 0%
  • Silvana Reis Fuezi

    DRUMMOND PARTICIPAÇÕES

    O curso foi bastante agregador.

    7 de abril de 2026

  • Rodrigo

    25 de março de 2026

    O treinamento oferecido pela PMG Academy é excelente. Não é à toa que refiz o PDPP aqui, a fim de me atualizar como DPO.

Join professionals from these organizations

Impact

Training teams of 5 or more?

PMG Academy offers corporate licensing, team dashboards, progress tracking, and dedicated support — built around your organization’s schedule and compliance requirements.

local