Practical GDPR: one day to structure your priorities
Operational training based on the GDPR and resources from the Belgian Data Protection Authority. Map your processing activities, responsibilities and the actions requiring validation in your context.
Business leaders, internal coordinators and teams that process data
Practical materials to bring so we can work on your situation
-
Your documents
Privacy information and your processing record, if one exists.
-
Your website
Forms, cookie settings and the tools you use.
-
Your practices
The roles and procedures of the team processing data.
-
Your questions
Points requiring clarification or legal validation.
The GDPR concerns organisations processing personal data, including through a website, newsletter, CRM, job applications or loyalty programme. The precise obligations depend on the processing activities, purposes, risks and the organisation’s role.
Typical participants: SME management, marketing and communications, human resources, IT managers and internal coordinators responsible for turning rules into practical procedures.
Prerequisites: none. Bring your current documents, such as privacy information, cookie settings or a processing record if one exists. The day helps you review them and prepare questions requiring legal or DPO validation.
This training is neither legal advice nor compliance certification. It provides a working method and refers to the official texts listed at the bottom of the page.
One day, five modules to put the rules into practice
European framework and the Belgian DPA’s role
GDPR principles, the Belgian Act of 30 July 2018, controller and processor responsibilities, the DPA’s role and how to find an official decision.
Records of processing activities
Article 30 provides for records and a limited exemption for some organisations with fewer than 250 employees. We examine regular processing, risks and the data involved, then prepare an appropriate record where needed.
Website: notices, cookies and forms
Identification information, privacy policy, cookies and trackers, consent mechanisms where required, forms and evidence for the chosen legal basis.
Requests to exercise individual rights
Receiving requests, checking identity, response templates and monitoring the GDPR’s one-month deadline, including possible extensions depending on the complexity and number of requests.
AI, data and responsibilities
Mapping the data sent to an AI service, purpose, contract, retention, transfers, internal access and assessment of high-risk uses. A no-training mode alone does not establish compliance.
90-day action plan
A progressive roadmap to document processing activities, review trackers, formalise procedures and identify useful external validation.
Which points have you already documented?
Tick what is in place. The result is a learning aid, not a legal measure of compliance.
Each item must be checked against your activities, processing and contractual responsibilities.
Format, pricing and deliverables
Format & pricing
- One day (8 hours), groups of up to eight
- In person in Brussels / remotely
- Open course: €880 excluding VAT per person
- In-house: €3,600 excluding VAT, fixed fee (3 to 8 people)
- Full tailored GDPR audit: €2,800 excluding VAT
- Check any potential funding conditions before registering
Deliverables
- Summary materials and links to official texts
- Working templates: processing record, information and AI policy
- Guided review of your documents during the training
- Prioritised 90-day action plan
- Follow-up arrangements specified in the proposal
- Kanexio certificate of attendance
Your questions
Does this really apply to my small SME?▾
The GDPR applies whenever an organisation processes personal data within its scope. The processing-record exemption for some organisations with fewer than 250 employees is limited. It does not apply, in particular, where processing is regular, risky or involves certain sensitive or criminal-offence data. Actual processing must therefore be examined, rather than applying a generic percentage.
Does an SME need a DPO?▾
Article 37 covers, among other things, public bodies, regular and systematic large-scale monitoring, and certain large-scale processing of special-category or criminal-offence data. The Belgian DPA notes that no universal number defines large scale. An SME should therefore assess its core activities and may seek specialist advice.
Is AI (ChatGPT) compatible with GDPR?▾
It depends on the data, purpose, provider, contract, retention, transfers and security measures. A professional subscription or no-training mode may reduce some risks, but does not make every use compliant. The training helps you ask the right questions before validation.
Complement this with
Ready to structure your digital growth?
Let's discuss your project. An initial conversation with no obligation.