Module 1 — Technical track
For system administrators, developers and cybersecurity teams. This module turns legal requirements into concrete decisions: design, risk assessment, data life cycle, security, incidents and individual rights, then the specific case of a B2B SaaS vendor. Duration: about 30 minutes.
Prerequisite: Module 0 — Common core. Items marked "good practice" are not legal requirements.
Privacy by Design and by Default
Designing products and systems that protect privacy from the start. The privacy impact assessment (PIA / EFVP)
When to trigger a PIA and how technical teams contribute. Technical data life cycle
Retention, purge, secure destruction, pseudonymization and anonymization. Encryption, logging and security
Encrypt, manage keys and keep personal information out of logs. Confidentiality incidents
Detect, escalate and record a confidentiality incident. Implementing individual rights
Access, rectification, deletion, portability and automated decisions in the product. B2B SaaS vendor track
Multi-tenancy, dual role, telemetry, AI, location and contract end for a SaaS. Module 1 quiz
Check your understanding of the technical track of Law 25.
Designing products and systems that protect privacy from the start. The privacy impact assessment (PIA / EFVP)
When to trigger a PIA and how technical teams contribute. Technical data life cycle
Retention, purge, secure destruction, pseudonymization and anonymization. Encryption, logging and security
Encrypt, manage keys and keep personal information out of logs. Confidentiality incidents
Detect, escalate and record a confidentiality incident. Implementing individual rights
Access, rectification, deletion, portability and automated decisions in the product. B2B SaaS vendor track
Multi-tenancy, dual role, telemetry, AI, location and contract end for a SaaS. Module 1 quiz
Check your understanding of the technical track of Law 25.