Course ID: #N/A

Certified Information Privacy Technologist (CIPT)

Duration: 2 days Dates: 16 August 2027 31 May 2027 15 February 2027 16 November 2026

This course shows you how to build privacy into IT products, systems and services – from the collection of personal data to its deletion. It is based on the five domains of the IAPP Body of Knowledge for the Certified Information Privacy Technologist (CIPT) certification, version 4.0, effective since 1 September 2025. Topics include risk models and threat modelling, privacy-enhancing technologies, tracking and surveillance, AI in the workplace, and Privacy by Design and Privacy Engineering. The course prepares you for the CIPT exam.

The Role of Privacy Technologists in the Organisation

  • Privacy roles and responsibilities: data governance with DPO, data owner, data steward and data custodian, legal compliance, cybersecurity
  • Translating legal and regulatory requirements into technical and organisational solutions; implementing internal and external privacy notices, policies and procedures
  • Technical tasks: supporting privacy reviews and audits including third parties, assisting with data breaches and other incidents, risk concepts such as threat, vulnerability, attack and exploit
  • Risk models and frameworks: Contextual Integrity by Nissenbaum, Harms Dimensions by Calo, FAIR, NIST/NICE, FIPPs, OECD principles; threat modelling with LINDDUN and MITRE PANOPTIC
  • Data ethics and privacy: distinguishing between lawful and ethical processing, societal and ethical questions, minimising bias and discrimination in automated decisions

Collection, Use, Disclosure and Deletion of Data

  • Collection: data subject control and consent through clear privacy notices, settings, dashboards and consent management; automatic collection; data from publicly available sources
  • Implementing appropriate retention and destruction of personal data
  • Use: data minimisation, separation of processing activities, risks of aggregation, privacy-enhancing techniques such as anonymisation, pseudonymisation and differential privacy, secondary use and profiling
  • Disclosure: mitigating risks from exposure and accessibility, protection against data falsification, data exposure, breach of confidentiality, extortion and appropriation; defence in depth with identity and access management and authentication

Privacy Risk Management

  • Intrusion and decisional interference: mitigating risks from behavioural advertising, profiling, cyberbullying and social engineering, avoiding dark patterns
  • Software security: identifying and fixing privacy vulnerabilities, intrusion detection and prevention, risks in change management for patches and upgrades, identifying vendor breaches
  • Tracking and surveillance: e-commerce with cookies, chatbots and payments, audio and video surveillance, wearables and IoT, biometrics, location tracking, internet monitoring and web tracking
  • Technologies in the workplace: artificial intelligence, machine learning and deep learning; communication technologies such as video conferencing, messaging, mobile devices, social media and gaming platforms
  • Monitoring and managing risks: privacy audits and IT control reviews, key risk indicators and key performance indicators, data protection impact assessments

Privacy by Design

  • Applying the seven foundational principles of Privacy by Design, defining privacy objectives and communicating them within the organisation
  • Aligning high-level specifications and detailed specifications with the principles of Privacy by Design
  • Assessing privacy risks in the user experience: the influence of UX decisions on user behaviour, usability testing for privacy features, value sensitive design

Privacy Engineering and Privacy Governance

  • Applying the NIST Privacy Engineering Objectives: predictability, manageability and disassociability
  • Considering enterprise architecture, data flow diagrams and data lineage tools, and cross-border data transfers
  • Managing privacy risks throughout the development lifecycle
  • Cataloguing data assets, building a data inventory and record of processing activities, reviewing code for privacy gaps, monitoring runtime behaviour
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/11/16, 2027/02/15, 2027/05/31, 2027/08/16, flexibel, auf Anfrage

Software developers, information security professionals, data architects, privacy engineers, and network and cloud engineers involved in developing products and services, as well as anyone pursuing the CIPT certification.

Basic knowledge of IT systems, software development or information security is required. Prior knowledge of privacy law is helpful but not a prerequisite.

After the course you will be able to:

  • identify the role of privacy technologists in the organisation and translate legal requirements into technical solutions
  • apply privacy risk models and threat modelling frameworks such as LINDDUN
  • mitigate privacy risks in the collection, use, disclosure and deletion of personal data using techniques such as data minimisation, pseudonymisation and differential privacy
  • identify and assess the risks of tracking, surveillance, biometrics and AI
  • implement Privacy by Design and a privacy-friendly user experience in projects
  • embed Privacy Engineering in the development lifecycle and monitor privacy controls

CHF3'370 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation