Delivered to the people who actually touch the data — engineering, support, sales, legal and overseas teams, each told what their own job requires. We have run all-hands programmes of 300+ people for China-based companies operating abroad, in Chinese and English.
300+
attendees in a single all-hands programme
CN / EN
bilingual delivery, remote for overseas teams
Two trainers
compliance counsel plus a data security specialist
Engineering wants to know whether phone numbers can stay in logs and whether production data can seed a test database. Support wants to know what to do first when a deletion request arrives and how long they have. Sales wants to know whether a customer list can leave the country or be emailed to a colleague abroad. None of those have direct answers in the text of the law.
So we split by audience and draw cases from your own processes and the problems you have already had. Domestic teams are taught on site in Chinese, overseas teams online in English, and the two outlines differ — overseas staff need to know what to watch for in their daily work, while the domestic team needs to know what the company owes externally.
Selected, trimmed or combined according to the jurisdictions you touch and how your teams are structured.
GDPR for China-based staff
Chinese · on site · 10 sessions
GDPR for overseas staff
English · online or on site · 17 sessions
US EO 14117 / CISA
Chinese or English · 6 sessions
All four are written into the statement of work, not promised verbally.
A complete deck covering the statutory provisions, worked cases and practical technique; split by role, versions retained.
Key points written up afterwards so attendees can go back to them.
Every question from the floor recorded and turned into an FAQ — nobody has to ask it twice.
Continued answers to questions attendees hit in practice after the session.
01
Talk to the departments being trained: what data do they genuinely handle, and where do they get stuck.
02
Set the depth and breadth from those interviews so the material matches the work.
03
Domestic sessions are taught jointly by a data security specialist and compliance counsel; overseas sessions add local senior counsel delivering in the attendees' own language.
04
A dedicated question slot afterwards, with anything left open feeding into follow-up support.
Regulators and customer due diligence ask the same question: did you train people, who attended, and what were they told. Attendance, deck versions, Q&A records and assessment results are all retained — material that gets cited directly under GDPR accountability, ISO 27001 people controls, and in customer security questionnaires. So we file it from the first session as something that will later be shown to someone.
The curricula above come from delivered projects; actual content is adjusted to your business and the jurisdictions that apply. Training is not legal advice, and specific obligations are governed by the current text of the applicable law.
Tell us which roles to cover, which jurisdictions apply, and whether an inspection or due-diligence review is coming. We will come back with a curriculum and a schedule.
Book a consultation