Overview
CONTINUING PROFESSIONAL DEVELOPMENT AI in GDPR and Compliance A practitioner’s course on making AI systems comply with UK data protection law — lawful basis, roles, rights, automated decisions, DPIAs, security, transfers and the compliance programme that holds it together. AI …
Course Details
AI in GDPR and Compliance
A practitioner’s course on making AI systems comply with UK data protection law — lawful basis, roles, rights, automated decisions, DPIAs, security, transfers and the compliance programme that holds it together.
What’s Included in the Course
Course Overview
Three lines are converging: UK data protection law was rewritten in tranches through 2025–26; ICO enforcement has shifted to fewer, larger penalties aimed at systemic failure; and AI adoption has pushed personal data into tools, prompts and models that most compliance frameworks were never designed to see.
This course works through what UK GDPR actually requires of AI systems, in the order the obligations arise: roles, basis, transparency, automated decisions, DPIAs, security, transfers, and the programme that evidences all of it.
It covers the law of England and Wales — UK GDPR as amended by the Data (Use and Access) Act 2025, and the Data Protection Act 2018 — stated at 26 August 2026. It is CPD, not a qualification, accreditation or licence, and not a substitute for a recognised data protection certification or your DPO’s judgement on your own facts.
Who This Course Is For
Written for practitioners who already own data protection, compliance, legal or governance responsibility, and now face AI systems.
Data protection practitioners and officers whose organisations already hold data protection responsibility
Compliance professionals responsible for data protection compliance who now face AI systems
Legal advisers working on AI systems that process personal data
Governance professionals overseeing AI adoption, procurement and risk
Learning Outcomes
On completing the course, you will be able to:
Identify which rules govern an organisation’s AI systems, and what changed under the 2025–26 reforms.
Determine who is legally responsible for what across an AI supply chain — controller, processor and joint controller.
Establish what lets an organisation process personal data through an AI system at all.
State what individuals are owed — notices, DSARs, rectification, erasure and complaints.
Apply the safeguards required when a system takes a significant automated decision.
Assess and evidence AI risk through a Data Protection Impact Assessment.
Recognise what “secure” looks like for an AI pipeline, and what to do if it fails.
Map where personal data actually goes through international transfers and third-party AI.
Build and prove an AI data protection programme on demand.
Career Path
This is CPD for practitioners who already hold data protection, compliance, legal or governance responsibility and now face AI systems. It is not a qualification, accreditation or licence, and not a substitute for a recognised data protection certification.
Data Protection Officer (DPO)
Compliance / Risk Lead
Legal and Governance Advisers
Procurement and Vendor Management
Incident Response and Security Teams
Board and Senior Leadership
Course Structure
Nine modules, working through the obligations in the order they arise — roles, basis, rights, automated decisions, DPIAs, security, transfers, and the programme.
01
Foundations
UK GDPR, DPA 2018 and DUAA 2025 applied to AI
02
Roles and Accountability
Controller, processor, joint control across an AI supply chain
03
Lawful Basis
Article 6, Article 9, purpose limitation, training v inference
04
Transparency and Rights
Notices, DSARs, rectification, erasure, complaints
05
Automated Decisions
Articles 22A–22D in operation from 5 February 2026
06
DPIAs and AI Risk
Article 35 applied to models; the ICO’s expectations
07
Security and Breaches
Article 32, shadow AI, AI-driven threats, 72-hour duty
08
International Transfers
The DUAA transfer test, IDTA, cloud and vendor AI
09
The Programme
RoPA, audits, training, enforcement readiness, horizon
Frequently Asked Questions
Click a question to view the answer.
Is this a qualification or a licence to practise?
No. It is continuing professional development — not a qualification, accreditation or licence, and not a substitute for a recognised data protection certification.
Is it legal advice?
No. It is not legal advice, and not a substitute for your DPO’s judgement on your own facts.
Is it accredited, and how many CPD hours does it carry?
Yes. The course is accredited by the CPD Standards Office and carries 20 CPD hours.
Does it cover EU GDPR?
No. It is not an EU GDPR course. The UK and EU regimes diverged in 2026 — the EU has no equivalent of Articles 22A–22D or recognised legitimate interests, and advising on the wrong one breaches both.
Does it cover Scotland and Northern Ireland?
Data protection is a reserved matter, so UK GDPR and the DPA 2018 apply UK-wide — but sectoral overlays such as health, policing and public administration are devolved and differ.
How current is the legal content?
It states the law as at 26 August 2026. It is not current indefinitely — DUAA commencement continued into June 2026 and the ICO’s statutory AI code is still being drafted, so it should be re-verified before every delivery.





