Skip To Content
Assess Risks Within A Defined Functional Area, And Develop Countermeasures And Contingency Plans is a Program

Assess Risks Within A Defined Functional Area, And Develop Countermeasures And Contingency Plans

Self-paced

Sorry! The enrollment period is currently closed. Please check back soon.

Full program description

Assess Risks Within A Defined Functional Area, And Develop Countermeasures And Contingency Plans

Course Overview

Download E-Brochure

Learners will learn how to assess current and potential risks within a functional area, and develop risk countermeasures and contingency plans.

Who Should Attend

1. Data Protection Officers

2. Staff who formulate and review data protection policies

3. Staff who develop data protection management programmes

Course Duration

2 Days/16 hours

Course Outline

1. Risk of non-compliance with the following obligations under PDPA:

1.1. Consent obligation

1.2. Notification obligation

1.3. Purpose limitation obligation

1.4. Accuracy obligation

1.5. Retention limitation obligation

1.6. Protection obligation

1.7. Access and correction obligation

1.8. Transfer limitation obligation

1.9. Openness obligation

1.10. DNC provisions

2. Risks relating to business processes

2.1. Developing a Data Inventory Map

2.2. Identify relevant activities

2.3. Examination of issues concerning activities

3. Risks relating to data intermediaries/third parties/service vendors

4. Risks relating to electronic processing of personal data

5. Risks relating to data sharing

6. Develop risk assessment report

6.1. Content of report

7. Managing risks with third parties/vendors/data intermediaries

7.1. Conduct due diligence

7.2. Monitor activities and performance

7.3. Managing contracts

8. Developing a DPIA

8.1. Assessing need

8.2. Stakeholders

8.3. Substantive considerations

8.4. Identifying personal data and personal data protection flows

8.5. Identify and assess risks

8.6. Create action plan

8.7. Implementation of action plan

Mode of Assessment

Learners will be required to undergo assessment, consisting of a written test and oral questioning. Both will be conducted in the classroom

Course Objectives

Learners will have knowledge of the following:

  • Risk identification and assessment techniques for business processes, third party/ service vendors, and processing of personal data electronically.
  • Risk assessment report development.
  • Complex or advanced methods to manage risks and safeguard stakeholders interests.
  • Implementation considerations and rationale for risk management processes.
  • Data protection risk assessment in relation to DP provisions.
  • Data protection risk assessment in relation to business processes when processing personal data throughout the data lifecycle (from collection, storage, use, disclosure, disposal and archival), including DPIA.
  • Data protection risk assessment in relation to data intermediaries in areas such as contracts and vendor performance management.
  • Data protection risk assessment in relation to electronic processing of personal data including data security, cloud technology, anonymisation, IT system/website.
  • Data protection risk

Learners will be able to perform the following:

  • Institutionalise DP risk management as part of organisation-level risk management approach
  • Establish baseline of vulnerabilities, gaps and exposures to data protection related risks
  • Develop implementation plan for organisation-wide personal data protection risk management processes and procedures
  • Determine need to conduct a DPIA
  • Manage existing and potential DP risks associated with technology
  • Manage existing and potential DP risks arising from data sharing
  • Coordinate with relevant department to mitigate contractual and technological risks arising from data protection

Pre-requisites

1. Learner has attended and is competent for module titled Fundamentals of Personal Data Protection Act or its equivalent

2. Learners are assumed to be able to:

  • Understand relevant organisational strategies, objectives, culture, policies, processes and products/services;
  • Have information gathering skills to gather and collate necessary data;
  • Have analytical skills to assess policies and procedures;
  • Have business writing skills to prepare management report;
  • Have interpersonal and communication skills to interact with relevant stakeholders;
  • Have facilitation skills to ask the right questions to elicit necessary information; and
  • Be aware of compliance requirements of organisation.

Price

 Before GSTWith GST
Original Course Fee$760.00$813.20
Course Fee after Funding for both Individual and 
Company Sponsored Candidates 50% e2i Funding 
capped at $15/hr for Singaporeans and PRs
$380.00$433.20
RML2