Skip to main content

Quick navigation

What are you looking for?

Suggestions

Enter at least two characters.

Compliance training

Practical GDPR: one day to structure your priorities

Operational training based on the GDPR and resources from the Belgian Data Protection Authority. Map your processing activities, responsibilities and the actions requiring validation in your context.

Illustration of the data protection framework.
Understand the rules and responsibilities. Editorial illustration.
Who it is for

Business leaders, internal coordinators and teams that process data

The visual guide

Practical materials to bring so we can work on your situation

  • Your documents

    Privacy information and your processing record, if one exists.

  • Your website

    Forms, cookie settings and the tools you use.

  • Your practices

    The roles and procedures of the team processing data.

  • Your questions

    Points requiring clarification or legal validation.

The session provides a working method. It is neither legal advice nor compliance certification.

The GDPR concerns organisations processing personal data, including through a website, newsletter, CRM, job applications or loyalty programme. The precise obligations depend on the processing activities, purposes, risks and the organisation’s role.

Typical participants: SME management, marketing and communications, human resources, IT managers and internal coordinators responsible for turning rules into practical procedures.

Prerequisites: none. Bring your current documents, such as privacy information, cookie settings or a processing record if one exists. The day helps you review them and prepare questions requiring legal or DPO validation.

This training is neither legal advice nor compliance certification. It provides a working method and refers to the official texts listed at the bottom of the page.

Programme

One day, five modules to put the rules into practice

Module 1 (1 hour 30 minutes)

European framework and the Belgian DPA’s role

GDPR principles, the Belgian Act of 30 July 2018, controller and processor responsibilities, the DPA’s role and how to find an official decision.

Module 2 (1 hour 30 minutes)

Records of processing activities

Article 30 provides for records and a limited exemption for some organisations with fewer than 250 employees. We examine regular processing, risks and the data involved, then prepare an appropriate record where needed.

Module 3 (2 hours)

Website: notices, cookies and forms

Identification information, privacy policy, cookies and trackers, consent mechanisms where required, forms and evidence for the chosen legal basis.

Module 4 (1 hour 30 minutes)

Requests to exercise individual rights

Receiving requests, checking identity, response templates and monitoring the GDPR’s one-month deadline, including possible extensions depending on the complexity and number of requests.

Module 5 (1 hour 30 minutes)

AI, data and responsibilities

Mapping the data sent to an AI service, purpose, contract, retention, transfers, internal access and assessment of high-risk uses. A no-training mode alone does not establish compliance.

Bonus

90-day action plan

A progressive roadmap to document processing activities, review trackers, formalise procedures and identify useful external validation.

Self-assessment

Which points have you already documented?

Tick what is in place. The result is a learning aid, not a legal measure of compliance.

Each item must be checked against your activities, processing and contractual responsibilities.

GDPR compliance criteria
Practical information

Format, pricing and deliverables

Format & pricing

  • One day (8 hours), groups of up to eight
  • In person in Brussels / remotely
  • Open course: €880 excluding VAT per person
  • In-house: €3,600 excluding VAT, fixed fee (3 to 8 people)
  • Full tailored GDPR audit: €2,800 excluding VAT
  • Check any potential funding conditions before registering

Deliverables

  • Summary materials and links to official texts
  • Working templates: processing record, information and AI policy
  • Guided review of your documents during the training
  • Prioritised 90-day action plan
  • Follow-up arrangements specified in the proposal
  • Kanexio certificate of attendance
FAQ

Your questions

Does this really apply to my small SME?

The GDPR applies whenever an organisation processes personal data within its scope. The processing-record exemption for some organisations with fewer than 250 employees is limited. It does not apply, in particular, where processing is regular, risky or involves certain sensitive or criminal-offence data. Actual processing must therefore be examined, rather than applying a generic percentage.

Does an SME need a DPO?

Article 37 covers, among other things, public bodies, regular and systematic large-scale monitoring, and certain large-scale processing of special-category or criminal-offence data. The Belgian DPA notes that no universal number defines large scale. An SME should therefore assess its core activities and may seek specialist advice.

Is AI (ChatGPT) compatible with GDPR?

It depends on the data, purpose, provider, contract, retention, transfers and security measures. A professional subscription or no-training mode may reduce some risks, but does not make every use compliant. The training helps you ask the right questions before validation.

Ready to structure your digital growth?

Let's discuss your project. An initial conversation with no obligation.