EXIN Privacy & Data Protection Professional – PDPP
Official EXIN
- Duration: 24 hours
- Portuguese and English
Corporate training clients
About the course
About the Course
Validity period: by decision of the course organisation, PDPP is valid until 31/12/2026. Complete the course and generate your certificate of completion by that date to keep the option of taking the exam; otherwise you will no longer be eligible for it.
This course is updated with EXIN's new version of the “Privacy Information Management System (PIMS)” module, based on the ISO/IEC 27701 standard.
EXIN Privacy and Data Protection Practitioner is a certification that validates a professional's knowledge and understanding of European privacy and data protection legislation and its international relevance, as well as their ability to apply that knowledge and understanding to their daily professional practice.
Combined with the EXIN Privacy & Data Protection Foundation certification, this gives candidates a broad understanding of security as a whole. See the image below:
EXIN Privacy and Data Protection Practitioner is a certification that validates a professional's knowledge and understanding of European privacy and data protection legislation and its international relevance, as well as their ability to apply that knowledge and understanding to their daily professional practice.
With the ever-growing explosion of information flooding the internet, every company must plan how to manage and protect people's privacy and their data. As a result, many new laws in the EU, as well as in the US and many other regions, are being drafted to regulate privacy and data protection.
The European Commission published the General Data Protection Regulation (GDPR) in the EU, which means that, as of 25 May 2018, all organisations involved must comply with specific rules. This Practitioner-level certification builds on the topics covered by the Foundation exam, focusing on developing and implementing policies and procedures to comply with new and existing legislation, applying guidelines and best practices for privacy and data protection, and establishing a Data Protection Management System (DPMS).
The new standard in the ISO/IEC 27000 series — ISO/IEC 27701:2019 Security Techniques – Extension to ISO/IEC 27001 and ISO/IEC 27002 for Privacy Information Management – Requirements and Guidelines — is useful for organisations wishing to demonstrate GDPR compliance. The content of the new ISO standard helps organisations meet their GDPR obligations regarding the processing of personal data.
Neither the GDPR nor the ISO standard is part of the exam literature. However, the literature matrix in Chapter 4 is designed to show the link between the exam requirements, the literature, the GDPR and the ISO/IEC 27701:2019 standard, to give the certification a broader context.
The EXIN Privacy & Data Protection Practitioner certification is part of the EXIN Privacy & Data Protection qualification programme.
Who should attend
Target Audience
Number of questions: 40 questions
Test duration: 2 hours
Passing grade: 65% (26/40)
Difficulty level: Intermediate
Prerequisites: PDPP preparatory course + Practical Course Exercises
Open-book exam: No
Exam format: Online
Certification & exam
Exam and Certification
This course prepares you for the official EXIN PDPP certification exam.
- Exam language
- Portuguese and English
- Number of questions
- 40 questions
- Test duration
- 2 hours
- Passing grade
- 65% (26/40)
- Difficulty level
- Intermediate
- Prerequisites
- PDPP preparatory course + Practical Course Exercises
- Open-book exam
- No
- Exam format
- Online
- 99
Pass rate among PMG Academy students
Our students consistently outperform global averages. The content is developed by the official translator of the PeopleCert exam itself.
- 1y
Exam voucher validity
Your included PeopleCert exam voucher is valid for 12 months, giving you full flexibility to schedule when you’re ready.
- T2
Take2 re-sit option available
Optional Take2 re-sit and PeopleCert Plus Membership are available at checkout for complete peace of mind.
About the instructor
About the Instructor
15 years of training excellence with over 71,000 students who have passed.
Adriano is an ITIL Master, consultant and author of 6 books, bringing 25 years of experience and more than 50 certifications in IT Management, Security and Governance. As the leader of the largest ITSM and DPSM community (over 220,000 YouTube subscribers), he combines his MBA from FGV — one of the world's leading business schools — with a specialization in Neuroscience to guide a global network of more than 71,000 students. His mission is clear: to demystify complex management and turn technical knowledge into tangible value and market impact.
Official translator of the ITIL Foundation Guide (Version 5)
- 71k+
- Students trained
- 220k
- YouTube subscribers
- 25y
- Years of experience
Curriculum
What you will learn
-
00 Module 1 – Introduction 6 lessons
- Welcome
- GDPR and LGPD
- PDPP Course Overview
- Objectives and Target Audience of the PDPP Certification
- Practical Activities
- About the PDPP Exam
-
01 Module 2 – Data Protection Policies 31 lessons
- Introduction – Data Protection Policies
- Reviewing the Main Definitions
- Policies and GDPR
- Policies and Compliance
- Policy Elements
- Policy Availability
- Example of Data Protection Policy Topics
- Information Security Policy
- Content of Information Security Policies
- Effective Policies
- Data Protection by Design
- Application of Data Protection by Design (by design)
- Data Protection by Default
- Application of Data Protection by Default (by default)
- Data Protection Officers by Design and by Default
- Processors and Data Protection
- Third-Party Organizations and Data Protection
- What Should Be Done in Practice
- When Actions Should Be Taken
- Data Protection by Design Framework
- The 7 Fundamental Principles of Data Protection
- 1: Proactive, Not Reactive; Preventive, Not Corrective
- 2: Privacy by Default
- 3: Privacy by Design
- 4: Full Functionality – Positive-Sum, Not Zero-Sum
- 5: End-to-End Security and Protection Throughout the Data
- Data Life
- 6: Visibility and Transparency
- 7: Respect for User Privacy
- Corporate Governance Framework
- PDPP – Module 2 Exercise
-
02 Module 3 – Privacy Information Management System (PIMS) 41 lessons
- Introduction
- What to expect from this module?
- What is Private Information Management?
- Examples of Problems Related to Personal Information
- GDPR Principles
- Those Involved in Privacy
- Country of Operation
- Management of Processing with Third Parties
- What is 'Personal Information'
- Reason for Processing Personal Information
- What Needs to Be Considered
- Internal and External Issues
- Stakeholders
- Balance between Organizations and Individuals
- Format and Storage Medium
- Subcontractor
- ISO/IEC 27701
- Documentation
- Audit
- Management System Review
- Available Resources
- Privacy Impact Assessment (PIA)
- Privacy Risks
- Privacy Risk Assessment
- Perspectives by Amount of Information Processed
- Applying PIMS Controls
- Privacy Information Management Controls
- Extension of ISO/IEC 27001 Controls
- Additional Guidelines Aligned with ISO/IEC 27002
- Conditions for Data Collection and Processing
- Obligations for Data Subjects
- Privacy by Design and by Default
- Sharing, Transfer, and Disclosure of Personal Information
- Annexes in ISO/IEC 27701
- Dealing with Private Information Leaks
- Compliance and Audit
- Certification
- Certification at Horizonte
- Certification Audit
- Additional Audit Applications
- PDPP – Module 3 Exercise
-
03 Module 4 – Controller, Processor and DPO Roles 34 lessons
- Roles of the Controller, Processor, and Data Protection Officer (DPO)
- Definition of the Role of the Data Controller
- Details About the Data Controller
- More Tasks of the Data Controller
- Role of the Data Processor
- Tasks of the Data Processor
- More details about the Data Processor
- Controllers and Processors outside the EU
- Responsibilities of the Controller's Representative
- Processing Records
- Records as Evidence
- Controller and Processor Records
- Introduction to the Role of Data Protection Officer (DPO)
- Data Protection Officer (DPO) Role Requirements – Core Activities
- Requirements of the Data Protection Officer (DPO) Role – Large-Scale Processing
- Requirements of the Role of Data Protection Officer (DPO) – Regular and Systematic Monitoring
- Voluntary Designation of a DPO
- Companies Sharing a DPO
- DPO under a Service Contract
- Publication of the DPO Contact
- DPO Position
- Provision of Resources
- Independent Role of the DPO
- Protection of the DPO Role
- Conflict of Interest
- Designating a DPO
- DPO's First Task
- Second Task of the DPO
- Third, Fourth, and Fifth Tasks of the DPO
- The DPO and the Organization
- The DPO and the Supervisory Authority
- Data Protection Impact Assessment and Risk Assessment
- Internal or Contracted DPO
- PDPP – Module 4 Exercises
-
04 Module 5 – Data Protection Impact Assessment (DPIA) 23 lessons
- Data Protection Impact Assessment (DPIA)
- Introduction to the Data Protection Impact Assessment (DPIA)
- Expected Results of the DPIA
- Benefits of DPIA
- Fundamentals of the Data Protection Impact Assessment (DPIA)
- Stages of a DPIA
- DPIA – 1 – Identify the Need for a DPIA
- Reasons for Conducting a DPIA
- Examples of DPIA Situations
- DPIA – 2 – Describe the Information Flows
- DPIA – 3 – Identify Privacy-Related Risks
- Risk Assessment
- A Little More About Risks
- DPIA – 4 – Identify and Evaluate Privacy Solutions
- Risk Treatment
- Risk Register
- Risk Management and Personal Data
- DPIA – 5 – Complete and Record DPIA Results
- DPIA – 6 – Integrate DPIA Results into a Project Plan
- DPIA – 7 – Consult Stakeholders Throughout the DPIA
- Consulting External Stakeholders
- Who Needs to Be Involved in the DPIA
- PDPP – Module 5 Exercises
-
05 Module 6 – Data Breach, Notification and Incident Response 17 lessons
- Data Breach, Notification and Incident Response
- Data Security Breaches
- What is a Personal Data Breach?
- Forms of Data Breach
- Vulnerabilities and Violations
- Protecting Information
- Responding to a Data Breach
- Events and Incidents
- Forms of Incidents
- Incident Response Plans
- Roles in Incident Management
- Notification to the Supervisory Authority
- Notification to Data Subjects
- Exceptions to Notification of Data Subjects
- Final Considerations
- FIM
- PDPP – Module 6 Exercises
-
06 Module 7 – Mandatory Practical Exercises
3 PDPP Practical Exercises
-
07 Module 8 – Preparatory Practice Exams 3 lessons
- Practice Exam 1: 40 Questions
- Simulated 2: 40 Questions
- Simulado 3: 40 Questions
Student reviews
Trusted by professionals at leading organizations
-
O curso foi bastante agregador.
7 de abril de 2026
-
O treinamento oferecido pela PMG Academy é excelente. Não é à toa que refiz o PDPP aqui, a fim de me atualizar como DPO.
Join professionals from these organizations
Impact
Training teams of 5 or more?
PMG Academy offers corporate licensing, team dashboards, progress tracking, and dedicated support — built around your organization’s schedule and compliance requirements.