Date and time:
– 19 November, 2026 / 10:00am -15:30pm (5 hours)
5 CPDS
Registration and Access
To register to this Course, click “Take this Course” above to pay online and register for this Course. After your registration, you will receive an email with information for the Live Online presentation of the Course.
If you are purchasing this Course on behalf of others, please be advised that you will need to create or use their personal profile before finalizing your payment.
If you wish to receive an invoice instead of paying online, please complete and submit the Registration Form.
Contact us at seminars@icpte.com or at 25755911 for any clarification or assistance for registration you might need.
Course Description and topics covered
The Course will cover the following topics:
- Does your Company comply with the GDPR requirements?
- Key Terms.
- The GDPR in summary.
- Comply with the GDPR Principles.
- When processing of personal data is unlawful.
- What does the Processing of Personal Data Involve?
- How to comply with GDPR specific requirements.
- Avoid being penalised for the infringement of GDPR provisions (Examples of fines imposed).
- Understand how to receive valid Consent and meet Data Subjects’ rights
- General provisions of Consent.
- Understand when a Consent is valid.
- Conditions for valid Consent.
- Conditions applicable to children’s Consent.
- Examples of obtaining valid Consent.
- Valid Consent – Summary.
- Understand how to meet Data Subjects rights.
- What rights do Data Subjects have?
- Restrictions on responding to Data Subjects’ rights requests.
- Key points regarding restrictions.
- Practical guidance on handling Data Subjects’ rights requests.
- Examples on handling Data Subjects’ rights requests.
- Respond to Data Subjects’ rights requests.
- Data Subjects Rights Request (DSRR) Procedure.
- What forms a company may develop and implement for handling Data Subjects’ rights requests.
- Learn how to comply with the Retention Period and how to develop a Data Protection Impact Assessment (DPIA)
- Develop and implement a Retention Period.
- What Retention Period means.
- How long should a Company retain personal data?
- What should a Company do with personal data that is no longer needed?
- Apply Retention Period in practice.
- What a “Personal Data Retention Policy” may include.
- Key points to consider when implementing Retention Period.
- Develop a Data Protection Impact Assessment (DPIA).
- What a DPIA is.
- What a DPIA shall at least include.
- When a DPIA shall be performed.
- Examples of processing activities subject to DPIA.
- Example of a DPIA structure.
- Key points to consider when performing a DPIA.
- Be prepared to manage a personal data breach and the various policies and procedures to keep internally
- Be prepared to manage a personal data breach.
- What a personal data breach is.
- Informing affected Data Subjects for a breach.
- Examples
- Notify the personal data breach to the Supervisory Authority.
- Examples
- Develop and implement a “Personal Data Breach Management Procedure”.
- What a “Personal Data Breach Management Procedure” may include.
- Policies, Procedures and Agreements to Develop and Implement.
Course Duration
This Course will be presented Online Live on 19 November 2026 at 10:00 – 15:30. The Course duration is 5 hours.
The Course is addressed to:
This course is addressed to all individuals who are involved in the processing of personal data in an organisation:
- Designated DPOs in Investment Firms, Investment Funds, ASPs, Trust Service Corporate Providers, Banks, Payment Service Providers, Law Firms, Accounting Firms, Auditors, insurance companies, hospitals, schools, hotels, real estate professionals, and in general DPOs of all organisations.
- Employees of Investment Firms, Investment Funds, ASPs, Trust Service Corporate Providers, Banks, Payment Service Providers, Law Firms, Accounting Firms, Auditors, insurance companies, hospitals, schools, hotels, real estate professionals, and in general of all organisations involved in the processing of personal data.
- Executive Directors, Non-executive directors, Senior Managers, Compliance Officers, Risk Managers, Product Managers, etc.
- Internal Auditors
- Consultants
- Lawyers
It is also suitable for professionals pursuing CPD for the renewal of CySEC Certificate (CySEC Basic or CySEC Advance Certificate or CySEC AML Certificate) or other relevant professional certificates in other jurisdictions.
Training Method
Live Online
At the end of the Course, participants take a Quiz. A Certificate of Completion shall be issued and sent to participants after the Course is completed.
Accreditation and CPD Recognition
The course can be accredited by regulators and other bodies for 5 CPD Units that require CPD training in financial and other regulation. The Course may be also approved for up to 5 CPD Units by institutions that approve general financial training, such as the CySEC, ICPAC, CBA and CISI.
Eligibility criteria and CPD Units are verified directly by your association or other bodies in which you hold membership.
Registration and Access
To register to this Course, click “Take this Course” above to pay online and register for this Course. After your registration, you will receive an email with information for the Live Online presentation of the Course.
If you are purchasing this Course on behalf of others, please be advised that you will need to create or use their personal profile before finalizing your payment.
If you wish to receive an invoice instead of paying online, please complete and submit the Registration Form or Contact us by email. Talk to us for our special Corporate Group rates.
Instructor
Experience
Andreas Nicolaides has more than 12-years experience in the financial Industry. He is the Operations Manager of G.P. GLOBAL LTD offering consulting services and training courses to Investment Firms, Administrative Service Providers and Funds focuses in Internal Audit, compliance & AML issues. He is a member of the Internal Audit team of G.P. GLOBAL LTD and is involved in numerous Internal Audits of Cyprus Investment Firms, Administrative Service Providers and Funds where he is engaged, among others, in the audit for compliance with the GDPR regulatory framework. He has completed a number of trainings on GDPR regulatory framework and assisted a number of Cyprus Investment Firms, Administrative Service Providers and Funds to comply with their GDPR legal obligations.
Education
Andreas Nicolaides holds a BA in Business Management from the Northumbria University (Newcastle – UK). Andreas also holds an Advance and Money Laundering certificate from the Cyprus Securities and Exchange Commission for the provision of investment services/activities.
See more Courses from Andreas Nicolaides

