KROG Legal Engineering Academy · BeLEx
Consent you can prove.
Six courses that turn a legal duty into a specification a machine can execute and a regulator can check — taught in consent, because ISO/IEC has already published the standards.
- 6 courses · 7 lessons each
- Video on demand + oral examination
- EQF 5–6 · no coding required
- €595 · founding cohort €449 with code FOUNDING (first 20 seats)
Why consent has to be built right
Consent is the one legal basis the individual controls — and the one the organisation must be able to prove. If the proof fails, the processing that rests on it fails too.
The EU has chosen a format.
In May 2026 the European Commission called for tenders for a Data Altruism Consent Management System under the Data Governance Act — open-source software through which people give, withdraw and manage consent, interoperable with EU digital infrastructure. The tender specifications require consent receipts that follow ISO/IEC TS 27560:2023. When the Commission builds its reference implementation on a standard, that standard becomes the measure others are held to.
No proof, no consent.
GDPR Art. 7(1) puts the burden on the controller: where processing rests on consent, the controller must be able to demonstrate it — who consented, to what, when, on which notice, and whether it has since been withdrawn. A consent that cannot be demonstrated cannot be relied on. The processing then has no legal basis under Art. 6(1), and every activity resting on it is unlawful. Documentation is a condition of validity, not paperwork after the fact.
Consent is how data is exchanged for value.
Much data sharing rests on a simple bargain: the individual shares data and gets something back. Media subscribers consent to personalised recommendations and content; retailers build product recommendations and direct marketing on consented first-party data. That value lasts only as long as the consent holds — and can be shown to hold.
Consent has to travel between systems.
Today consent sits in silos. Public bodies and health services each run their own consent solutions, many designed years before ISO/IEC TS 27560 was published in 2023, each with its own data model. When one system cannot read another's consent status, someone checks it by hand — or the data sharing stops. A shared vocabulary and one JSON consent record that any system can parse, verify and act on removes the bottleneck.
Coverage · published in full
We publish what the catalogue does not cover yet
Every criterion in GDPR-CARPA is mapped to the course that teaches it — and the 28 of 30 subjects we have not written yet are named, not hidden.
- criteria mapped
- 70
- subjects available now
- 2 of 30
- subjects coming soon
- 4
- subjects planned
- 24
Introduction: Consent, in two views
See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.
What you'll be able to do
By the end you can take a legal requirement and produce a specification that a machine can execute and a regulator can check.
Turn a duty into a data structure. GDPR Art. 7(1) becomes four sections, eight mandatory processing fields, and events that are appended and never overwritten.
Read a standard the way an engineer reads a spec. Requirement levels, clause by clause, and what changes when a field is mandatory in both record and receipt.
Map a clause to its legal basis — and defend the mapping. ISO/IEC 29184 §5.3 against Art. 13 and Art. 14, including recording “does not apply” with a justification.
Design the interface, not just the document. Progressive disclosure, document to dashboard, and comprehension you can evidence under Art. 25(1).
Build the audit file as you go, and stand behind it. One client brief, four processing activities, three builds — and an oral defence.
You leave with artefacts you can show, not a certificate of attendance.
Who it's for
For you
Lawyers and privacy professionals who want to work in structure rather than prose. The work that used to train a junior lawyer is now done by an LLM in seconds; what it cannot do is decide what the law requires and state it precisely enough for a system to execute and an auditor to check. That is legal engineering, and legal-AI companies are hiring for it. Also for engineers and designers building consent into products.
For your organisation
DPOs and compliance leads who need consent documentation that survives an audit and ports between systems. Train the people who build and defend it.
Contact us for team pricing — hello@signatu.comBrowse by programme
Role
EQF level
6 courses
Structured Consent
Modelling consent records, receipts, and notices to ISO/IEC TS 27560 and ISO/IEC 29184 — mapped to the GDPR.
Six courses. Turn consent into structure a machine can read, verify, and act on — and that you can defend afterwards.
Buy the programme — €595 →Consent Records
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC TS 27560:2023 · GDPR Art. 7(1)
- Role
- Lawyer + AI expert
- CARPA
- CARPA II-a-3
You leave able to read any ISO/IEC TS 27560 record end to end and say whether it proves consent.
Produce a consent record that is standardised, machine-readable, and interoperable. You learn the duty that creates it — GDPR Art. 7(1), which requires the controller to be able to demonstrate consent — the four sections every record carries, the eight mandatory processing fields, and why events are appended and never overwritten. You finish able to read any 27560 record end to end.
Read moreShow less
Seven lessons · video on demand
Consent Receipts
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC TS 27560 §9
- Role
- Lawyer + AI expert
- CARPA
- CARPA II-a-3
You leave able to issue a receipt that carries the record's fields at the same requirement levels.
Give the individual their own copy of the consent. Under §9.2 the receipt reuses the record's fields at the same requirement levels — it is not a lesser summary. You learn what the header carries, why the GDPR names no explicit duty to issue a receipt, and why Art. 15 and Art. 20 are the nearest hooks.
Read moreShow less
Seven lessons · video on demand
Consent Notices
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC 29184:2020 §5
- Role
- Lawyer
- CARPA
- CARPA II-a-13 – II-a-15
You leave able to test a consent notice against ISO/IEC 29184 §5 and spot a provision failure before a regulator does.
The notice is what makes consent informed. ISO/IEC 29184 §5 sets when it must reach the individual (§5.2), the sixteen content elements it must convey (§5.3), and the controls that let consent be withdrawn or renewed (§5.4–5.5). You learn to read a notice against the clause that governs it, and to spot a provision failure before a regulator does.
Read moreShow less
Seven lessons · video on demand
Privacy Notices
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC 29184:2020 §5
- Role
- Lawyer
- CARPA
- CARPA II-a-13 – II-a-15
You leave able to audit an organisation-wide privacy notice per collection route and per processing activity.
The organisation-wide document — what most people still call the privacy policy. You apply the same standard at scale: provision judged per collection route, content judged per section and per processing activity, and the Art. 13 / Art. 14 split on where the data came from. Including the discipline of recording "does not apply", with a justification, control by control.
Read moreShow less
Seven lessons · video on demand
Privacy Notice Design
- Programme
- Structured Consent
- EQF
- EQF 6
- Standard
- Design craft · builds on 03 & 04
- Role
- AI expert
- CARPA
- CARPA II-a-13 – II-a-15
You leave able to redesign a notice so comprehension can be evidenced under GDPR Art. 25(1).
The policy does not fail because of the law. It fails because of layout, length, and sequencing — and that is a design outcome, which means it can be redesigned. You learn real progressive disclosure, the move from document to dashboard where the reader can act as well as read, symmetry that survives an audit, and comprehension you can evidence under GDPR Art. 25(1).
Read moreShow less
Seven lessons · video on demand
Consent & Notice Studio
- Programme
- Structured Consent
- EQF
- EQF 6
- Standard
- Capstone · builds on 01–05
- Role
- AI expert
- CARPA
- CARPA II-a-3 · II-a-13 – II-a-15
You leave with a notice, record, receipt, privacy notice and §5.1 audit file you have defended orally.
No new theory. One client brief, four processing activities, three builds: the consent notice and its UI, then the record and receipt, then the privacy notice and the dashboard over it. You assemble the §5.1 audit file as you go, and you defend it. The credential is attested by oral examination on your portfolio — not by a score.
Read moreShow less
Seven lessons · studio format
Who teaches it
Georg Philip Krog has spent more than a decade building legal ontologies, rule logic and consent infrastructure. His paper on implementing ISO/IEC TS 27560:2023 consent records and receipts for the GDPR and the Data Governance Act received the best paper award at the Annual Privacy Forum 2024.
Photo and link to KROG profile to follow.
Certification
Included in the purchase:
- Portfolio assessment: a consent record, a consent receipt, a consent notice and a privacy notice, each assessed against the standard it is built to.
- A 60-minute oral examination over video. You defend your artefacts; the credential is attested on your portfolio, not on a score.
- On a pass: a verified credential on your KROG profile, a badge and a diploma, each with a unique ID and a public verification page.
Pass all six to earn the capstone title BeLEx Certified Legal Engineer — Structured Consent. The examination is booked on KROG after purchase.
From learning to proof
01 · Learn
Courses 1–4 model consent and notice information to ISO/IEC TS 27560 and ISO/IEC 29184 and map it to the GDPR; course 5 is the design craft on top; course 6 is the capstone studio.
02 · Produce
The consent notice and the UI it appears in, the consent record and receipt, the privacy notice and the dashboard over it — plus the §5.1 audit file you assemble during the capstone.
03 · Assess
Each course ends in its own exam: you are handed real artefacts and asked to read them. The capstone is attested by oral examination on your portfolio — not by a score.
04 · Prove
Per course: that course's credential, e.g. Structured Consent — Consent Records (ISO/IEC TS 27560), at the EQF level the course states (5–6). All six: the capstone title BeLEx Certified Legal Engineer — Structured Consent. Each with a unique ID and a public verification page on KROG.
BeLEx · Catalogue · Certification track
The CARPA criteria index
GDPR-CARPA is the only GDPR certification criteria set a European supervisory authority has adopted under GDPR Art. 42. This index maps every criterion onto the course that teaches it — including the ones we have not written yet.
- criteria
- 70 criteria
- subjects
- 30 subjects
- available now
- 2 available now
- coming soon
- 4 coming soon
- planned
- 24 planned
Why we publish the gaps
A catalogue that only lists what it sells tells you nothing about what it leaves out. Every one of the 30 subjects below is shown with the course that covers it and how far that coverage goes — and the ones still unwritten are marked as such rather than quietly omitted. When a course ships, one field moves and every row citing it updates.
Legend
- Available now
- Buyable today.
- Coming soon
- Published as a course, in build — register to be notified.
- Planned
- Scoped and sequenced, not yet written.
- in depth
- A course or programme that produces the artefact and its evidence.
- one lesson
- Covered inside a coverage course: the criterion, its evidence, and how it is tested.
SECTION I Accountability and governance
controllers and processors · 18 criteria
- 1.1
The target of evaluation
The system and interface inventory, and a data-flow diagram down to manual steps, transformations and printouts.
- I-0
Coming soon
Records of Processing Activities
one lesson
partly — the ToE inventory sits beside the register
Notify me → - 1.2
Policies and procedures
Management's accountability measures, the ten topics a policy set must cover, and the review that revalidates even the unchanged ones.
- I-1
- I-2
- I-3
Planned
Governance
one lesson
new course 01
- 1.3
The record of processing activities
Content for controller and for processor, then the management review that certifies completeness and accuracy.
- I-4
- I-5
- I-6
- I-7
Coming soon
- 1.4
Facilitating data subjects' rights
The accessible contact point, identification and minimisation, one month with a reasoned extension to three, refusals that carry the complaint route.
- I-8
- I-9
Planned
Governance
one lesson
new course 01
- 1.5
The data protection officer
Designation and publication, the competence floor and its training substitutes, protected position, and the three-year audit plan.
- I-10
- I-11
- I-12
- I-13
Planned
Governance
one lesson
new course 01
- 1.6
Data breaches
The documented method for deciding whether an event qualifies, the register, notification content, and the processor's duty inside 72 hours.
- I-14
- I-15
Coming soon
- 1.7
Awareness and competencies
Competence defined per processing activity, annual training for staff and externals, documented participation, written commitments.
- I-16
- I-17
Planned
Governance
one lesson
new course 01
SECTION II-a Lawfulness, transparency and rights
controllers · 18 criteria
- 2.1
Identifying and reviewing a legal basis
Necessity against the purpose, the conditions the law attaches, and the annual re-test of the basis itself.
- II-a-1
- II-a-2
Planned
Lawfulness, transparency and rights
one lesson
new course 02
- 2.2
The five bases other than consent
Contract, legal obligation, vital interest, public interest, legitimate interest — each with the assessment CARPA names.
- II-a-4
- II-a-5
- II-a-6
- II-a-7
- II-a-8
Planned
Lawfulness, transparency and rights
one lesson
new course 02
- 2.3
Consent
Freely given, specific, informed, unambiguous; explicit where required; the record kept unaltered; withdrawal as easy as giving.
- II-a-3
Available now
Structured Consent
in depth
Structured Consent 01–02 · 06 Studio · ISO/IEC TS 27560
Buy the course bundle → - 2.4
Special categories
The prohibition first, then the ten Article 9(2) routes one at a time, each with its own assessment and safeguards.
- II-a-9
Planned
Lawfulness, transparency and rights
one lesson
new course 02
- 2.5
Objection, restriction, automated decisions
When each right arises, the compelling-grounds analysis, restriction without deletion, and qualified human intervention.
- II-a-10
- II-a-11
- II-a-12
Planned
Lawfulness, transparency and rights
one lesson
new course 02
- 2.6
Transparency
The direct-collection list, the indirect list with its exceptions, and keeping information current as processing changes.
- II-a-13
- II-a-14
- II-a-15
Available now
- 2.7
Access, portability and transfers
The structured retrieval process, the rights-of-others assessment, format choice, and the transfer-mechanism analysis with annual revalidation.
- II-a-16
- II-a-17
- II-a-18
Planned
Lawfulness, transparency and rights
one lesson
new course 02
SECTION II-b–f Data quality, storage and security
controllers · 21 criteria
- 3.1
Purpose limitation and minimisation
Purpose quality, compatibility of further processing, and the field-by-field necessity record.
- II-b-1
- II-b-2
- II-c-1
- II-c-2
Planned
Data quality, storage and security
one lesson
new course 03
- 3.2
Accuracy and rectification
Source reliability assessed by method, annual verification of data held, and rectification propagated to every recipient.
- II-d-1
- II-d-2
- II-d-3
Planned
Data quality, storage and security
one lesson
new course 03
- 3.3
Storage limitation and erasure
Retention derived from law or a documented assessment; deletion and anonymisation tested annually, backups and logs included.
- II-e-1
- II-e-2
- II-e-3
Planned
Data quality, storage and security
one lesson
new course 03
- 3.4
Security: risk analysis and treatment
The named organisational and technical checklist, impact and probability on rights and freedoms, and accepted risks documented.
- II-f-1
- II-f-2
- II-f-3
Planned
Data quality, storage and security
one lesson
new course 03
- 3.5
Audit and follow-up
The independent annual audit, the three-year audit plan and its documented method, and the correction cycle.
- II-f-4
- II-f-5
Planned
Data quality, storage and security
one lesson
new course 03
- 3.6
DPIA and prior consultation
The documented decision either way, the four required contents, the view of data subjects, and consultation on residual high risk.
- II-f-6
- II-f-7
Coming soon
- 3.7
Outsourcing
Sufficiency assessed before and during, the nine contract stipulations, joint procedures, and annual independent monitoring.
- II-f-8
- II-f-9
- II-f-10
- II-f-11
Planned
Data quality, storage and security
one lesson
new course 03
SECTION III The processor's obligations
processors · 13 criteria
- 4.1
The contract and documented instructions
What the contract must set out, the annual review testing instructions against actual processing, and processing under law without instruction.
- III-1
- III-2
- III-3
- III-4
Planned
The processor's obligations
one lesson
new course 04
- 4.2
Security
The controller's risk analysis and treatment, but with method and accepted risks validated by the contractual partner.
- III-5
- III-6
- III-7
Planned
The processor's obligations
one lesson
new course 04
- 4.3
Audit and follow-up
The independent audit, the partner's agreed involvement, and reports to both managements.
- III-8
- III-9
Planned
The processor's obligations
one lesson
new course 04
- 4.4
Subcontracting
Proving the sub-processor offers the same guarantees, prior written authorisation, and a chain contract with identical obligations.
- III-10
- III-11
Planned
The processor's obligations
one lesson
new course 04
- 4.5
Transfers and the end of service
The transfer-mechanism analysis validated before processing starts, and return or deletion at the end, copies included.
- III-12
- III-13
Planned
The processor's obligations
one lesson
new course 04
THE MECHANISM How certification is examined
the audit itself — no criteria numbers · 0 criteria
- 5.1
Eligibility and the target of evaluation
The exclusions, the maturity self-assessment, and a meaningful ToE described across its four levels: legal context, business function, applications, infrastructure.
- n/a
Planned
The certification mechanism
one lesson
new course 05 · first to publish
- 5.2
ISAE 3000 and what the auditor tests
A type 2 reasonable-assurance report over a past period of six to twelve months: design and implementation, then operating effectiveness.
- n/a
Planned
The certification mechanism
one lesson
new course 05
- 5.3
Nonconformities and the decision
Major against minor, and their asymmetry: a major finding in Section I rejects the application; in Sections II or III it removes one activity from scope.
- n/a
Planned
The certification mechanism
one lesson
new course 05
- 5.4
The certificate
Validity tied to the audited period, renewal at each anniversary to a three-year maximum, changes to report, scope reduction, withdrawal, and the seal.
- n/a
Planned
The certification mechanism
one lesson
new course 05
BEYOND THE CRITERIA What CARPA does not reach
taught anyway — not counted in the thirty · 0 criteria · not counted
- —
AI Act conformity
Risk classification, provider and deployer obligations, technical documentation, and the interface with the GDPR. CARPA excludes AI Act conformity entirely — and excludes most Article 10 data from certification.
- n/a
Coming soon
- —
Machine-readable documentation
Records, receipts and notices to ISO/IEC TS 27560 and ISO/IEC 29184, and registers a machine can validate. CARPA asks for documentation; it does not ask for it to be structured.
- n/a
Available now
KROG does not certify entities.
A GDPR-CARPA certificate is issued by an accredited certification body under CNPD supervision, and only entities established in Luxembourg are eligible. These courses prepare the people who build and defend the documentation the criteria require. Outside Luxembourg they are accountability training held to the only GDPR criteria a European authority has actually adopted — which is a stronger reference point than the Regulation alone, not a weaker one.
The criteria are versioned, and they do not cover everything.
The mechanism is at v2.0 (July 2023) and the CNPD keeps the criteria under review, so every course card and every certificate we issue carries the criteria version it was written and earned under. CARPA does not certify the security of processing, and it excludes most Article 10 data — so it is a floor for accountability, not a substitute for it.
GDPR-CARPA criteria v2.0 · July 2023 · CNPD, Luxembourg
Jurisdiction editions (roadmap)
The catalogue ships first mapped to EU law (GDPR and AI Act). Editions mapping the same artefacts onto other countries' laws follow — so the courses, and their certifications, extend jurisdiction by jurisdiction. The full list of covered countries will be published shortly.
Why this catalogue
The PDF privacy policy and the opaque consent log are on their way out. Auditors, regulators, partners and the systems we integrate with increasingly expect consent, privacy and AI-governance information to be structured, portable and verifiable — not buried in prose. ISO/IEC has published the standards; the EU has enacted the rules. This catalogue shows you how to put them to work.
- Built directly on international standards (ISO/IEC TS 27560:2023, ISO/IEC 29184:2020) and EU regulation (GDPR, AI Act) — not one vendor's house style — and mapped onto the law's actual requirements.
- Machine-readable and interoperable by design — documentation that automates, audits and ports across systems, and that agents can read, verify and act on.
- Practical throughout, from a free introduction to capstone courses where you produce the real thing and certify.
Email newsletter
Get notified when new courses, modules and updates are published. No spam — course announcements only.
What is delivered, and what is only specified
The courses above are delivered and examined by KROG. CWA 18398 separately specifies 37 educational profiles, one per AI role, with learning outcomes and summative assessments. KROG does not deliver those. They are published as specifications so a reader can see the standard itself.
See the specified educational profiles