Booking options
€660 - €1,080

€660 - €1,080
Live Online
21 CPD Units | 21 Hours
HRDA Subsidised
The EIMF Live Online Learning Experience
Participants will receive access to the recorded sessions of the course.
EIMF subject-matter experts deliver engaging and interactive courses across a broad spectrum of areas, that can be enjoyed in the comfort of your own chosen environment. Read more
Course Overview
With the ever increasing explosion of information flooding the internet, every company needs to plan how to manage and protect privacy of persons and their data. Not without a reason, many new laws within the EU, as well as in the USA and many other regions, are formed in order to regulate both privacy and data protection.
The European Commission has published the EU General Data Protection Regulation (GDPR), meaning that from the 25th of May 2018 on, all organizations concerned must comply with specific rules. This professional certification builds on the subjects covered by the Foundation exam by focusing on the development and implementation of policies and procedures in order to comply with existing and new legislation, application of privacy and data protection guidelines and best practices, and by establishing a data privacy information management system (PIMS).
The new standard in the ISO/IEC 27000 series: ISO/IEC 27701:2019 Security Techniques – Extension to ISO/IEC 27001 and ISO/IEC 27002 for Privacy Information Management – Requirements and Guidelines is useful for organizations that want to show compliance with the GDPR. The content of the new ISO standard helps fulfil the GDPR obligations to organizations regarding the processing of personal data.
EXIN Privacy and Data Protection Professional course is an advanced-level certification that validates a professional’s knowledge and understanding of the European privacy (data protection) legislation. The exam looks at the international relevance of these regulations and tests the individual’s ability to apply this knowledge and understanding in everyday professional practice.
Training Objectives
By the end of the programme, participants will be able to:
Understand the basic Definitions of the GDPR
Comprehend the needs for businesses and organisations defined in the GDPR
Define what are personal data according to the GDPR
Acknowledge the importance of compliance with the GDPR
Understand the basic principles of GDPR compliance
Training Outline
Data Protection Policies
Purpose of the Data Protection and Privacy Policies within an Organization
Data Protection by Design and by Default
Managing and Organizing Data Protection
Privacy Information Management System (PIMS)
Roles of the Controller, Processor and Data Protection Officer (DPO)
Roles of the Controller and Processor
Role and Responsibilities of a DPO
Data Protection Impact Assessment (DPIA)
Criteria for a DPIA
Steps of a DPIA
Data Breaches, Notification and Incident Response
GDPR Requirements with Regard to Personal Data Breaches
Requirements for Notification
The course sessions will include:
Practical questions and examples
Practical exercises and discussions
Practice tests that are like the Certification Exam
Who Should Attend
EXIN Privacy & Data Protection Professional Certification is ideal for: Data Protection Officers (DPOs), Privacy Officers, Legal / Compliance Officers, Security Officers, Business Continuity Managers, Data Controllers, Data Protection Auditors (internal and external) and HR managers.
As this is an advanced-level certification, it is advisable to have passed EXIN Privacy and Data Protection Foundation or have attended other similar type of courses or certifications before taking this exam.
CPD Recognition
This programme may be approved for up to 21 CPD units in GDPR. Eligibility criteria and CPD Units are verified directly by your association, regulator or other bodies which you hold membership.
Course Bundle
Register to both the EXIN Foundation and Professional Certificate training courses at EIMF and enjoy a special discount.
Certification and Exam
The exam fee is included in the total course price. If you choose to take the exam at our exam centre you will need to inform us, so we can make necessary arrangements.
EIMF, as an EXIN Accredited Training Provider and Exam Centre, is offering preparation courses and examinations to become a Privacy & Data Protection Professional.
EXIN Anywhere | EXIN Anywhere lets you take the exam for your certification online. This means taking your exam at a time and location convenient to you. So this can be at home, in a meeting room at the office or in any other secluded space where else you feel comfortable. The only conditions are that you have an internet connection, a laptop that meets the requirements and that there is no one else in the room with you. Learn more
Examination type: Multiple-choice questions
Number of questions: 40
Pass mark: 65% (26/40)
Open book
Notes: No
Training mandatory: Yes
Electronic equipment/aides permitted: No
Exam duration: 120 minutes
Exam fee is subject to change at any time at EXIN’s discretion and without prior notice. Accordingly, EIMF will charge candidates based on the applicable fees in effect at the time of registration.”
Any discount applies only to the course fee.
The Rules and Regulations for EXIN’s examinations apply to this exam.
Download Exam Syllabus here
Course and exam fees are subject to change at any time at EXIN’s discretion and without prior notice. Accordingly, EIMF will charge candidates based on the applicable fees in effect at the time of registration
Certified EXIN Data Protection Officer (DPO) Career Path Option
1. EXIN Privacy & Data Protection Foundation (mandatory)
2. EXIN Information Security Foundation based on ISO/IEC 27001*
3. EXIN Privacy & Data Protection Professional (mandatory)
* EXIN Information Security Foundation: This can be from an external party. If you currently hold the Certification of Information Privacy Professional (CIPP) from IAPP or the ISO/IEC 27001:2022 Foundation certification from PECB you can fast-track your path to becoming an EXIN Data Protection Officer. These certifications can replace the EXIN Privacy & Data Protection Foundation certificate. For information click here.
For more information please click the following links: ΕΧΙΝ Data Protection Officer | EXIN DPO Career Path
In-house Training
For groups within the same organisation, this course may be customized to meet any specific needs and delivered in-house.

Olympios Christofi
Olympios Christofi is a Founding Partner at Christofi, Meraklis & Associates LLC and an experienced trainer, specializing in GDPR and Cyprus Employment Law. A member of the Cyprus Bar Association since 2016, Olympios also serves as President of the Cyprus Bar Association Labour Law Committee and holds multiple accreditations, including as an HRDA Approved Trainer, Accredited Mediator and EXIN Privacy and Data Protection Practitioner. Olympios is a PHD candidate in the field of Employment Law and GDPR issues.
The invoice is issued on the day the course starts.
Payments can be made by bank transfer, cheque, or credit card.
Certificates are issued within 7–10 days after the course has been completed, provided that the invoice has been paid.
Once your certificate has been issued, you will receive an automated email from Cademy notifying you that it is available.
Click the Get Your Certificate button in the email to download your certificate.
You can also access it from your Cademy account:
To access the course materials, such as presentations and recordings:
The Human Resource Development Authority (HRDA) of Cyprus is a semi-government governmental organisation that supports the development of workforce skills through training and development initiatives. Eligible training programmes approved by the HRDA may qualify for a subsidy, reducing the participation cost for eligible organisations and individuals, subject to the HRDA's terms and conditions.
The HRDA subsidy is available to:
To receive the subsidy, eligible persons must attend at least 75% of the course.
ERMIS is the online platform of the Human Resource Development Authority (HRDA) of Cyprus, used for managing training programme registrations, participant details, subsidy applications, and attendance records. All participants attending HRDA-approved courses must have an ERMIS profile and use the platform’s attendance register to check in and check out during each course session. https://ermis.anad.org.cy/
To attend an HRDA-approved course, you must:
See the FAQs below for detailed instructions.
Yes. ALL participants attending HRDA-approved courses must have an ERMIS profile, whether applying for the subsidy or not.
You can create or access your ERMIS profile here: https://ermis.anad.org.cy/
After booking your course through the EIMF website, you must also register through ERMIS, provided that the required profile(s) have already been created.
You must register through your personal ERMIS profile.
For example: If your organisation includes multiple companies, make sure each participant is registered under the correct company profile.
Around one week before the course starts (or immediately after booking if you register less than one week before the course), we will email you the HRDA course details and instructions on how to complete your ERMIS registration.
When registering for the course through ERMIS, you must upload both of the following documents obtained from the Public Employment Service:
You must update your ERMIS profile:
When submitting your request, you must upload one of the following:
Yes. All participants must log onto the ERMIS system and check onto the attendance register when they join a course session and check out when they leave a course session, as HRDA records attendance.
To receive the subsidy, eligible persons must attend at least 75% of the course. Check-ins and check-outs reflect actual attendance.