Modelling GDPR-related processes effectively
Your processes need to be understood before they can be improved. Model activities, exchanges and responsibilities to make friction points visible. Develop a BPM approach that supports dialogue between business teams and those responsible for transforming how the organisation works.
- Duration
- 3 days 21 hours
- Code
- GDPR02FR Code
Presentation
The General Data Protection Regulation (GDPR) is a European regulation through which the European Parliament, the Council of the European Union and the European Commission seek to strengthen and standardise data protection across EU countries, while also controlling transfers outside the Union. Its main objectives are to give citizens control over their personal information and unify the regulatory framework for multinational businesses.
Adopted in April 2016, it will enter into force on 25 May 2018 after a two-year transition period. Unlike directives, it does not need to be incorporated into national legislation and is directly applicable.
As the application date approaches, businesses need to control the personal data they hold, understand the applicable rules and identify who is responsible. In short, they need effective information governance and business processes that support risk management and regulatory compliance.
Processes relating to GDPR must therefore be described clearly and in a way that all stakeholders can understand: the Data Protection Officer, HR, IT and, where relevant, the quality function.
A universal language adopted by all BPM vendors is now available for describing and modelling business processes rigorously, particularly those relating to GDPR: BPMN (Business Process Model & Notation) 2.0.
Objectives
This course aims to help you:
- discover the capabilities of the BPMN 2.0 standard, enabling organisations that use BPM to document processes in a structured, rigorous and effective way;
- learn a methodology and best practices for documenting processes in BPMN 2.0;
- apply the course content using modelling software;
- understand how a business process becomes a business application.
Program
Module 1: Modelling principles
- Concepts and definitions.
- Examples of GDPR-related processes:
- Acquiring, accessing and maintaining personal data.
- Routine GDPR processing: responding to access requests and deleting data on request.
- Exceptional GDPR processing: notifications of irregularities.
- Control-flow patterns.
- BPMN 2.0 objectives.
Module 2: Introduction to the modelling tool
Course workshops use Bizagi Modeler, a freely downloadable tool compliant with BPMN 2.0. They can also use the modelling tool already deployed by the organisation.
Module 3: Level 1 modelling
- Task types: user, script, service, send and receive.
- Business rules and business rule tasks.
- Subprocess types: embedded, event, ad hoc and transaction.
- Reusable subprocess types: embedded and call activities.
- Data-based gateways.
- Event types: start, end and intermediate.
Workshops: modelling simple GDPR processes.
Module 4: Level 2 modelling
- Collaboration between processes: messages and signals.
- Intermediate events: in the flow or on the boundary of a task or subprocess.
- Event-based gateways.
- Complex gateways.
- Repeating activities: loops and multi-instance activities.
Workshops: modelling more complex GDPR processes.
Module 5: Modelling best practices
- Basic modelling principles.
- Model hierarchy.
- Labels for pools, gateways, activities and events.
- Basic usage rules.
Module 6: Turning processes into applications
- Modelling and executing a process.
Workshop: demonstration of a process converted into a business application using Oracle BPM.
Audience
This course is for anyone involved in processing data:
- data controllers;
- CIOs and CISOs;
- project managers;
- more broadly, anyone involved in personal data processing, including legal and HR professionals.
Prerequisites
No prerequisites are required for this course.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en