DPO SchoolDPO School
Back to E-Learning
Audio + documentationAlso on the members-only podcast channelTechnology and law as of 24 September 2026

Privacy in Tech

An audio course on privacy engineering and privacy-enhancing technology for technology professionals, with a guide, a one-page map and a self-check for each of its five parts, and a glossary. Written as a companion to our classroom course. Study material, not legal advice.

Listen while driving or commuting: subscribers of the podcast's paid tier get every episode in their podcast app.

5 parts, 18 episodes, 3 h 48 min of audio. Each part also has a guide, a one-page map and a self-check, and the course has a glossary.

Premium Content

Subscribe to unlock this course and all premium privacy training content.

Part I

What are we protecting, and from what?

Covers: What privacy means to an engineer, principles, the data life cycle, privacy harms, risk models and frameworks, values in design.

  • Episode 1. What privacy means to an engineer

    What privacy means, the principles behind it, and how privacy sits beside security and data governance.

    14:08
  • Episode 2. The life of a piece of data

    Personal data from collection to destruction, with the rule, the main risk and a real case at each stage.

    9:21
  • Episode 3. What goes wrong, and how likely it is

    Naming privacy problems, weighing risk, and bringing people's values into design.

    15:50
  • Part I guide (PDF)
  • Part I one-page map (PDF)
  • Part I self-check (PDF)

Part II

Who does the privacy work, and with what paperwork?

Covers: Roles, turning law into requirements, standards, policies and inventories, contracts, privacy and data protection impact assessments, data flows, threat modelling, incidents.

  • Episode 1. The technologist in the privacy team

    The people who do the privacy work, how law is turned into requirements, and the standards they work to.

    14:06
  • Episode 2. Policies, inventories, contracts and assessments

    The documents needed before a contract is signed: notice and policy, inventory and classification, contracts, and the impact assessment.

    12:16
  • Episode 3. Mapping systems, modelling threats, handling incidents

    Mapping systems and data flows, data crossing borders, modelling threats, handling incidents, and measuring the programme.

    15:25
  • Part II guide (PDF)
  • Part II one-page map (PDF)
  • Part II self-check (PDF)

Part III

How do we build privacy in?

Covers: Privacy by design principles, the engineering objectives, requirements, design strategies and patterns, usable notices and controls, dark patterns, testing and monitoring.

  • Episode 1. Principles and objectives

    The seven principles of privacy by design, how they became a legal duty and a standard, and the three engineering objectives.

    10:11
  • Episode 2. From requirement to design

    How a privacy goal becomes a testable requirement, and a requirement becomes a design through strategies, tactics and patterns.

    11:14
  • Episode 3. Interfaces people can use

    Notices, consent and privacy controls that people can use, and the dark patterns the rules now address.

    14:54
  • Episode 4. Testing and watching the live system

    Testing a design before launch, and watching the live system every day after it.

    9:31
  • Part III guide (PDF)
  • Part III one-page map (PDF)
  • Part III self-check (PDF)

Part IV

Which tools protect the data?

Covers: Encryption and post-quantum migration, identity and authentication, access control and security, de-identification and the law on pseudonymised and anonymous data, privacy-enhancing technologies.

  • Episode 1. Encryption and its limits

    How encryption, keys and certificates protect data in transit, at rest and in use, and the move to post-quantum cryptography.

    13:01
  • Episode 2. Who are you? Identity, authentication and access

    How little identity a task needs: passwords and passkeys, federation and credentials, age checks, and access control.

    12:48
  • Episode 3. Removing the person: de-identification

    What identifies a person, the techniques that weaken the link, and the law on pseudonymised and anonymous data.

    13:40
  • Episode 4. Using data without seeing it

    Privacy-enhancing technologies, from differential privacy to computing on hidden data, what each protects and how to choose one.

    12:07
  • Part IV guide (PDF)
  • Part IV one-page map (PDF)
  • Part IV self-check (PDF)

Part V

What does new technology change?

Covers: Online tracking and ad tech, location, cameras and connected devices, machine learning and its privacy attacks, generative AI, retrieval and agents, the rules for AI.

  • Episode 1. Being followed online

    What the network can see, cookies and fingerprinting, the browsers' answers, and consent and privacy signals.

    14:33
  • Episode 2. Sensors everywhere

    Location, cameras, microphones and drones, and connected devices, cars and cities.

    9:59
  • Episode 3. Machine learning and its privacy attacks

    Where personal data sits in machine learning, how models give it away, and the limits of unlearning.

    9:19
  • Episode 4. Assistants, agents and the law catching up

    Assistants and agents, the rules for AI, harms that are not leaks, and the close of the series.

    15:26
  • Part V guide (PDF)
  • Part V one-page map (PDF)
  • Part V self-check (PDF)

Glossary

The terms used across the course, each tagged with the part where it is explained.

  • Glossary (PDF)