This course is an online course lasting 3 days. The exam will be online via remote proctor, completed after the course at a suitable time for you.

None of these dates work for you? Suggest another date & time


The BCS Foundation Certificate in Data Protection will explore the application of current data protection laws, including the EU-GDPR, the UK-GDPR (although not included within the exam) and the UK Data Protection Act 2018.  

The qualification demonstrates a level of practical competence and knowledge obtained by those responsible for dealing with data protection in an organisation.

NB: The syllabus is updated to October 2020, at a time when the UK had left the EU, but an agreement between the UK and EU on its withdrawal has not yet been agreed, and the implementation of the UK GDPR legislation has not yet come into effect. The version delivered by DPAS reflects the law as at October 2020, updates to legislation after this date will not come into effect in the exam under post July 2021.


What's Included:

In addition to the 3 days of interactive or onsite training & exam, we also give you access to added-value products and services that allow you to start or continue your work within Data Protection:

  • Lunch and refreshments every day (classroom courses only)

  • 12 month BCS associate membership

  • DPAS branded folder (sent prior to the course)

  • Trainer with over 20 years of experience in the industry

  • All course materials shared via Microsoft 

  • Our latest Data Protection Assurance Audit which you can use when you are back in the workplace to assess compliance and develop remediation plans. Within this tool is a great one-page reporting template for your board.

  • An innovative risk model which is designed for you to assess data protection risks in your organisation.

  • Access to all the latest legislation, regulations and Data Protection case studies from the UK and EU.

  • Information security audit tool based upon ISO27001 which you can use to measure 92 security controls you have in your organisation.

Course Format

The course takes 3 days to complete and will be held virtually.  

You will need access to Microsoft Teams and OneDrive throughout the course. All documents will be shared via OneDrive and sessions will be held via Teams.

The course will start at 9:00 am and finish at 4:30 pm.

The BCS exam is included within the cost of the course. The exam is currently available either in a classroom or online via remote proctor. 

The exam format is as follows:

60-minute closed book exam with 40 multiple choice questions. The pass mark is currently 65% (26/40). 


Course Content

The aim of the syllabus is so delegates gain knowledge of UK data protection law, including the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, along with an understanding of how they are applied in practice.

The BCS Foundation Certificate in Data Protection is designed for those who wish to acquire a sound knowledge in the key elements of the law and its practical application. 

Day 1

  • History of Data Protection

  • Principles of Data Protection & Applicable Terminology

  • Lawful bases for processing Personal Data


Day 2

  • Governance & Accountability

  • Interaction between Controller and Processor

  • Transfers of Personal Data to third countries


Day 3

  • Data Subject Rights

  • Independent Supervisory Authority

  • Breaches, Enforcement and Liability

  • Privacy & Electronic Communications Regulations 2003 (PECR)


Candidates will be able to demonstrate knowledge and understanding of key provisions of Data Protection legislation in the following areas:

  • An Introduction to the History of Data Protection in the U.K.

  • Principles of Data Protection and Applicable Terminology

  • Lawful bases for processing of Personal Data

  • Governance and Accountability of Data Protection within organisations

  • Controller and Processor obligations

  • Transfers of personal data to third countries or international organisations

  • Data Subject Rights

  • Independent Supervisory Authority (ICO)

  • Breaches, Enforcement and Liability

  • Privacy and Electronic Communications (EC Directive) Regulations (PECR) 2003

You can download the syllabus on the BCS website by clicking here:


Our course is great for

This qualification is primarily aimed at those who need to have an understanding of data protection, and the GDPR in particular, to do their job; or those whose effectiveness in their role would be enhanced by knowledge of the law in this area.

The Foundation Certificate will also provide a steppingstone for those who have, or who will have, some responsibility for data protection within an organisation and who intend in due course to gain the BCS Practitioner Certificate in Data Protection.

This qualification is likely to be of particular benefit to those working in the following areas:

  • Data Protection and Privacy

  • Information Governance, risk and compliance

  • Data Management

  • Project Management

  • Directors/Senior Managers with Data Protection responsibilities

  • Legal and procurement

  • Marketing and Sales professionals

  • Information Security and IT

  • Human Resources