DataAigis
Advisory service

Global data compliance training

Delivered to the people who actually touch the data — engineering, support, sales, legal and overseas teams, each told what their own job requires. We have run all-hands programmes of 300+ people for China-based companies operating abroad, in Chinese and English.

300+

attendees in a single all-hands programme

CN / EN

bilingual delivery, remote for overseas teams

Two trainers

compliance counsel plus a data security specialist

Read the statute aloud and people still will not know what to change about their own work

Engineering wants to know whether phone numbers can stay in logs and whether production data can seed a test database. Support wants to know what to do first when a deletion request arrives and how long they have. Sales wants to know whether a customer list can leave the country or be emailed to a colleague abroad. None of those have direct answers in the text of the law.

So we split by audience and draw cases from your own processes and the problems you have already had. Domestic teams are taught on site in Chinese, overseas teams online in English, and the two outlines differ — overseas staff need to know what to watch for in their daily work, while the domestic team needs to know what the company owes externally.

Three delivered curricula

Selected, trimmed or combined according to the jurisdictions you touch and how your teams are structured.

GDPR for China-based staff

Chinese · on site · 10 sessions

  1. 01GDPR requirements
  2. 02GDPR and our business
  3. 03Managing partner and third-party data
  4. 04Cookie and privacy notices
  5. 05Privacy obligations toward overseas staff
  6. 06Cross-border transfer and approval
  7. 07Sensitive data handling
  8. 08Code signing security requirements
  9. 09The DPO role
  10. 10Running and improving the data security programme

GDPR for overseas staff

English · online or on site · 17 sessions

  1. 01Scope of application
  2. 02General concepts
  3. 03Your data processing
  4. 04Fundamental principles
  5. 05Lawfulness of processing
  6. 06Consent
  7. 07Rights of data subjects
  8. 08Necessity of a DPO
  9. 09Cloud services
  10. 10Use of technological means
  11. 11CV reception
  12. 12Breaches and security measures
  13. 13International data transfers
  14. 14Infringements and penalties
  15. 15Good practices in the work environment

US EO 14117 / CISA

Chinese or English · 6 sessions

  1. 01EO 14117 today and where it is heading
  2. 02EO 14117 restricted and prohibited transfers: worked scenarios
  3. 03The direction of travel for restricted transactions
  4. 04CISA overview
  5. 05CISA zero trust architecture and the data lifecycle
  6. 06CISA cross-border transfer and breach handling

What each programme delivers

All four are written into the statement of work, not promised verbally.

Training deck

A complete deck covering the statutory provisions, worked cases and practical technique; split by role, versions retained.

Session notes

Key points written up afterwards so attendees can go back to them.

Q&A record

Every question from the floor recorded and turned into an FAQ — nobody has to ask it twice.

Follow-up support

Continued answers to questions attendees hit in practice after the session.

What happens before the session

  1. 01

    Business interviews

    Talk to the departments being trained: what data do they genuinely handle, and where do they get stuck.

  2. 02

    Content tailoring

    Set the depth and breadth from those interviews so the material matches the work.

  3. 03

    Trainer pairing

    Domestic sessions are taught jointly by a data security specialist and compliance counsel; overseas sessions add local senior counsel delivering in the attendees' own language.

  4. 04

    Q&A and follow-up

    A dedicated question slot afterwards, with anything left open feeding into follow-up support.

The training record is itself compliance evidence

Regulators and customer due diligence ask the same question: did you train people, who attended, and what were they told. Attendance, deck versions, Q&A records and assessment results are all retained — material that gets cited directly under GDPR accountability, ISO 27001 people controls, and in customer security questionnaires. So we file it from the first session as something that will later be shown to someone.

The curricula above come from delivered projects; actual content is adjusted to your business and the jurisdictions that apply. Training is not legal advice, and specific obligations are governed by the current text of the applicable law.

Talk through your training needs

Tell us which roles to cover, which jurisdictions apply, and whether an inspection or due-diligence review is coming. We will come back with a curriculum and a schedule.

Book a consultation