KROG

KROG Legal Engineering Academy · BeLEx

Consent you can prove.

Six courses that turn a legal duty into a specification a machine can execute and a regulator can check — taught in consent, because ISO/IEC has already published the standards.

  • 6 courses · 7 lessons each
  • Video on demand + oral examination
  • EQF 5–6 · no coding required
  • €595 · founding cohort €449 with code FOUNDING (first 20 seats)

Why consent has to be built right

Consent is the one legal basis the individual controls — and the one the organisation must be able to prove. If the proof fails, the processing that rests on it fails too.

The EU has chosen a format.

In May 2026 the European Commission called for tenders for a Data Altruism Consent Management System under the Data Governance Act — open-source software through which people give, withdraw and manage consent, interoperable with EU digital infrastructure. The tender specifications require consent receipts that follow ISO/IEC TS 27560:2023. When the Commission builds its reference implementation on a standard, that standard becomes the measure others are held to.

No proof, no consent.

GDPR Art. 7(1) puts the burden on the controller: where processing rests on consent, the controller must be able to demonstrate it — who consented, to what, when, on which notice, and whether it has since been withdrawn. A consent that cannot be demonstrated cannot be relied on. The processing then has no legal basis under Art. 6(1), and every activity resting on it is unlawful. Documentation is a condition of validity, not paperwork after the fact.

Consent is how data is exchanged for value.

Much data sharing rests on a simple bargain: the individual shares data and gets something back. Media subscribers consent to personalised recommendations and content; retailers build product recommendations and direct marketing on consented first-party data. That value lasts only as long as the consent holds — and can be shown to hold.

Consent has to travel between systems.

Today consent sits in silos. Public bodies and health services each run their own consent solutions, many designed years before ISO/IEC TS 27560 was published in 2023, each with its own data model. When one system cannot read another's consent status, someone checks it by hand — or the data sharing stops. A shared vocabulary and one JSON consent record that any system can parse, verify and act on removes the bottleneck.

Coverage · published in full

We publish what the catalogue does not cover yet

Every criterion in GDPR-CARPA is mapped to the course that teaches it — and the 28 of 30 subjects we have not written yet are named, not hidden.

criteria mapped
70
subjects available now
2 of 30
subjects coming soon
4
subjects planned
24
See the criteria index →
Start hereFree · Structured Consent

See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.

What you'll be able to do

By the end you can take a legal requirement and produce a specification that a machine can execute and a regulator can check.

  • Turn a duty into a data structure. GDPR Art. 7(1) becomes four sections, eight mandatory processing fields, and events that are appended and never overwritten.

  • Read a standard the way an engineer reads a spec. Requirement levels, clause by clause, and what changes when a field is mandatory in both record and receipt.

  • Map a clause to its legal basis — and defend the mapping. ISO/IEC 29184 §5.3 against Art. 13 and Art. 14, including recording “does not apply” with a justification.

  • Design the interface, not just the document. Progressive disclosure, document to dashboard, and comprehension you can evidence under Art. 25(1).

  • Build the audit file as you go, and stand behind it. One client brief, four processing activities, three builds — and an oral defence.

You leave with artefacts you can show, not a certificate of attendance.

Who it's for

For you

Lawyers and privacy professionals who want to work in structure rather than prose. The work that used to train a junior lawyer is now done by an LLM in seconds; what it cannot do is decide what the law requires and state it precisely enough for a system to execute and an auditor to check. That is legal engineering, and legal-AI companies are hiring for it. Also for engineers and designers building consent into products.

For your organisation

DPOs and compliance leads who need consent documentation that survives an audit and ports between systems. Train the people who build and defend it.

Contact us for team pricing — hello@signatu.com

Browse by programme

Role

EQF level

Who teaches it

Georg Philip Krog has spent more than a decade building legal ontologies, rule logic and consent infrastructure. His paper on implementing ISO/IEC TS 27560:2023 consent records and receipts for the GDPR and the Data Governance Act received the best paper award at the Annual Privacy Forum 2024.

Photo and link to KROG profile to follow.

Certification

Included in the purchase:

  • Portfolio assessment: a consent record, a consent receipt, a consent notice and a privacy notice, each assessed against the standard it is built to.
  • A 60-minute oral examination over video. You defend your artefacts; the credential is attested on your portfolio, not on a score.
  • On a pass: a verified credential on your KROG profile, a badge and a diploma, each with a unique ID and a public verification page.

Pass all six to earn the capstone title BeLEx Certified Legal Engineer — Structured Consent. The examination is booked on KROG after purchase.

  1. 01 · Learn

    Courses 1–4 model consent and notice information to ISO/IEC TS 27560 and ISO/IEC 29184 and map it to the GDPR; course 5 is the design craft on top; course 6 is the capstone studio.

  2. 02 · Produce

    The consent notice and the UI it appears in, the consent record and receipt, the privacy notice and the dashboard over it — plus the §5.1 audit file you assemble during the capstone.

  3. 03 · Assess

    Each course ends in its own exam: you are handed real artefacts and asked to read them. The capstone is attested by oral examination on your portfolio — not by a score.

  4. 04 · Prove

    Per course: that course's credential, e.g. Structured Consent — Consent Records (ISO/IEC TS 27560), at the EQF level the course states (5–6). All six: the capstone title BeLEx Certified Legal Engineer — Structured Consent. Each with a unique ID and a public verification page on KROG.

BeLEx · Catalogue · Certification track

The CARPA criteria index

GDPR-CARPA is the only GDPR certification criteria set a European supervisory authority has adopted under GDPR Art. 42. This index maps every criterion onto the course that teaches it — including the ones we have not written yet.

criteria
70 criteria
subjects
30 subjects
available now
2 available now
coming soon
4 coming soon
planned
24 planned

Why we publish the gaps

A catalogue that only lists what it sells tells you nothing about what it leaves out. Every one of the 30 subjects below is shown with the course that covers it and how far that coverage goes — and the ones still unwritten are marked as such rather than quietly omitted. When a course ships, one field moves and every row citing it updates.

Legend

Available now
Buyable today.
Coming soon
Published as a course, in build — register to be notified.
Planned
Scoped and sequenced, not yet written.
in depth
A course or programme that produces the artefact and its evidence.
one lesson
Covered inside a coverage course: the criterion, its evidence, and how it is tested.

SECTION I Accountability and governance

controllers and processors · 18 criteria

  • 1.1

    The target of evaluation

    The system and interface inventory, and a data-flow diagram down to manual steps, transformations and printouts.

    • I-0

    Coming soon

    Records of Processing Activities

    one lesson

    partly — the ToE inventory sits beside the register

    Notify me →
  • 1.2

    Policies and procedures

    Management's accountability measures, the ten topics a policy set must cover, and the review that revalidates even the unchanged ones.

    • I-1
    • I-2
    • I-3

    Planned

    Governance

    one lesson

    new course 01

  • 1.3

    The record of processing activities

    Content for controller and for processor, then the management review that certifies completeness and accuracy.

    • I-4
    • I-5
    • I-6
    • I-7

    Coming soon

    Records of Processing Activities

    in depth

    three courses · eighteen modules · in build

    Notify me →
  • 1.4

    Facilitating data subjects' rights

    The accessible contact point, identification and minimisation, one month with a reasoned extension to three, refusals that carry the complaint route.

    • I-8
    • I-9

    Planned

    Governance

    one lesson

    new course 01

  • 1.5

    The data protection officer

    Designation and publication, the competence floor and its training substitutes, protected position, and the three-year audit plan.

    • I-10
    • I-11
    • I-12
    • I-13

    Planned

    Governance

    one lesson

    new course 01

  • 1.6

    Data breaches

    The documented method for deciding whether an event qualifies, the register, notification content, and the processor's duty inside 72 hours.

    • I-14
    • I-15

    Coming soon

    Personal Data Breach

    in depth

    seven lessons · GDPR Art. 33–34

    Notify me →
  • 1.7

    Awareness and competencies

    Competence defined per processing activity, annual training for staff and externals, documented participation, written commitments.

    • I-16
    • I-17

    Planned

    Governance

    one lesson

    new course 01

SECTION II-a Lawfulness, transparency and rights

controllers · 18 criteria

  • 2.1

    Identifying and reviewing a legal basis

    Necessity against the purpose, the conditions the law attaches, and the annual re-test of the basis itself.

    • II-a-1
    • II-a-2

    Planned

    Lawfulness, transparency and rights

    one lesson

    new course 02

  • 2.2

    The five bases other than consent

    Contract, legal obligation, vital interest, public interest, legitimate interest — each with the assessment CARPA names.

    • II-a-4
    • II-a-5
    • II-a-6
    • II-a-7
    • II-a-8

    Planned

    Lawfulness, transparency and rights

    one lesson

    new course 02

  • 2.3

    Consent

    Freely given, specific, informed, unambiguous; explicit where required; the record kept unaltered; withdrawal as easy as giving.

    • II-a-3

    Available now

    Structured Consent

    in depth

    Structured Consent 01–02 · 06 Studio · ISO/IEC TS 27560

    Buy the course bundle →
  • 2.4

    Special categories

    The prohibition first, then the ten Article 9(2) routes one at a time, each with its own assessment and safeguards.

    • II-a-9

    Planned

    Lawfulness, transparency and rights

    one lesson

    new course 02

  • 2.5

    Objection, restriction, automated decisions

    When each right arises, the compelling-grounds analysis, restriction without deletion, and qualified human intervention.

    • II-a-10
    • II-a-11
    • II-a-12

    Planned

    Lawfulness, transparency and rights

    one lesson

    new course 02

  • 2.6

    Transparency

    The direct-collection list, the indirect list with its exceptions, and keeping information current as processing changes.

    • II-a-13
    • II-a-14
    • II-a-15

    Available now

    Structured Consent

    in depth

    Structured Consent 03–05 · ISO/IEC 29184

    Buy the course bundle →
  • 2.7

    Access, portability and transfers

    The structured retrieval process, the rights-of-others assessment, format choice, and the transfer-mechanism analysis with annual revalidation.

    • II-a-16
    • II-a-17
    • II-a-18

    Planned

    Lawfulness, transparency and rights

    one lesson

    new course 02

SECTION II-b–f Data quality, storage and security

controllers · 21 criteria

  • 3.1

    Purpose limitation and minimisation

    Purpose quality, compatibility of further processing, and the field-by-field necessity record.

    • II-b-1
    • II-b-2
    • II-c-1
    • II-c-2

    Planned

    Data quality, storage and security

    one lesson

    new course 03

  • 3.2

    Accuracy and rectification

    Source reliability assessed by method, annual verification of data held, and rectification propagated to every recipient.

    • II-d-1
    • II-d-2
    • II-d-3

    Planned

    Data quality, storage and security

    one lesson

    new course 03

  • 3.3

    Storage limitation and erasure

    Retention derived from law or a documented assessment; deletion and anonymisation tested annually, backups and logs included.

    • II-e-1
    • II-e-2
    • II-e-3

    Planned

    Data quality, storage and security

    one lesson

    new course 03

  • 3.4

    Security: risk analysis and treatment

    The named organisational and technical checklist, impact and probability on rights and freedoms, and accepted risks documented.

    • II-f-1
    • II-f-2
    • II-f-3

    Planned

    Data quality, storage and security

    one lesson

    new course 03

  • 3.5

    Audit and follow-up

    The independent annual audit, the three-year audit plan and its documented method, and the correction cycle.

    • II-f-4
    • II-f-5

    Planned

    Data quality, storage and security

    one lesson

    new course 03

  • 3.6

    DPIA and prior consultation

    The documented decision either way, the four required contents, the view of data subjects, and consultation on residual high risk.

    • II-f-6
    • II-f-7

    Coming soon

    Data Protection Impact Assessment

    in depth

    seven lessons · GDPR Art. 35–36

    Notify me →
  • 3.7

    Outsourcing

    Sufficiency assessed before and during, the nine contract stipulations, joint procedures, and annual independent monitoring.

    • II-f-8
    • II-f-9
    • II-f-10
    • II-f-11

    Planned

    Data quality, storage and security

    one lesson

    new course 03

SECTION III The processor's obligations

processors · 13 criteria

  • 4.1

    The contract and documented instructions

    What the contract must set out, the annual review testing instructions against actual processing, and processing under law without instruction.

    • III-1
    • III-2
    • III-3
    • III-4

    Planned

    The processor's obligations

    one lesson

    new course 04

  • 4.2

    Security

    The controller's risk analysis and treatment, but with method and accepted risks validated by the contractual partner.

    • III-5
    • III-6
    • III-7

    Planned

    The processor's obligations

    one lesson

    new course 04

  • 4.3

    Audit and follow-up

    The independent audit, the partner's agreed involvement, and reports to both managements.

    • III-8
    • III-9

    Planned

    The processor's obligations

    one lesson

    new course 04

  • 4.4

    Subcontracting

    Proving the sub-processor offers the same guarantees, prior written authorisation, and a chain contract with identical obligations.

    • III-10
    • III-11

    Planned

    The processor's obligations

    one lesson

    new course 04

  • 4.5

    Transfers and the end of service

    The transfer-mechanism analysis validated before processing starts, and return or deletion at the end, copies included.

    • III-12
    • III-13

    Planned

    The processor's obligations

    one lesson

    new course 04

THE MECHANISM How certification is examined

the audit itself — no criteria numbers · 0 criteria

  • 5.1

    Eligibility and the target of evaluation

    The exclusions, the maturity self-assessment, and a meaningful ToE described across its four levels: legal context, business function, applications, infrastructure.

    • n/a

    Planned

    The certification mechanism

    one lesson

    new course 05 · first to publish

  • 5.2

    ISAE 3000 and what the auditor tests

    A type 2 reasonable-assurance report over a past period of six to twelve months: design and implementation, then operating effectiveness.

    • n/a

    Planned

    The certification mechanism

    one lesson

    new course 05

  • 5.3

    Nonconformities and the decision

    Major against minor, and their asymmetry: a major finding in Section I rejects the application; in Sections II or III it removes one activity from scope.

    • n/a

    Planned

    The certification mechanism

    one lesson

    new course 05

  • 5.4

    The certificate

    Validity tied to the audited period, renewal at each anniversary to a three-year maximum, changes to report, scope reduction, withdrawal, and the seal.

    • n/a

    Planned

    The certification mechanism

    one lesson

    new course 05

BEYOND THE CRITERIA What CARPA does not reach

taught anyway — not counted in the thirty · 0 criteria · not counted

  • —

    AI Act conformity

    Risk classification, provider and deployer obligations, technical documentation, and the interface with the GDPR. CARPA excludes AI Act conformity entirely — and excludes most Article 10 data from certification.

    • n/a

    Coming soon

    AI Act Compliance

    in depth

    EQF 7 · Regulation (EU) 2024/1689

    Notify me →
  • —

    Machine-readable documentation

    Records, receipts and notices to ISO/IEC TS 27560 and ISO/IEC 29184, and registers a machine can validate. CARPA asks for documentation; it does not ask for it to be structured.

    • n/a

    Available now

    Structured Consent

    in depth

    the catalogue's own thesis

    Buy the course bundle →

KROG does not certify entities.

A GDPR-CARPA certificate is issued by an accredited certification body under CNPD supervision, and only entities established in Luxembourg are eligible. These courses prepare the people who build and defend the documentation the criteria require. Outside Luxembourg they are accountability training held to the only GDPR criteria a European authority has actually adopted — which is a stronger reference point than the Regulation alone, not a weaker one.

The criteria are versioned, and they do not cover everything.

The mechanism is at v2.0 (July 2023) and the CNPD keeps the criteria under review, so every course card and every certificate we issue carries the criteria version it was written and earned under. CARPA does not certify the security of processing, and it excludes most Article 10 data — so it is a floor for accountability, not a substitute for it.

GDPR-CARPA criteria v2.0 · July 2023 · CNPD, Luxembourg

Jurisdiction editions (roadmap)

The catalogue ships first mapped to EU law (GDPR and AI Act). Editions mapping the same artefacts onto other countries' laws follow — so the courses, and their certifications, extend jurisdiction by jurisdiction. The full list of covered countries will be published shortly.

Why this catalogue

The PDF privacy policy and the opaque consent log are on their way out. Auditors, regulators, partners and the systems we integrate with increasingly expect consent, privacy and AI-governance information to be structured, portable and verifiable — not buried in prose. ISO/IEC has published the standards; the EU has enacted the rules. This catalogue shows you how to put them to work.

  • Built directly on international standards (ISO/IEC TS 27560:2023, ISO/IEC 29184:2020) and EU regulation (GDPR, AI Act) — not one vendor's house style — and mapped onto the law's actual requirements.
  • Machine-readable and interoperable by design — documentation that automates, audits and ports across systems, and that agents can read, verify and act on.
  • Practical throughout, from a free introduction to capstone courses where you produce the real thing and certify.

Email newsletter

Get notified when new courses, modules and updates are published. No spam — course announcements only.

Double opt-in: we store your address only to send this list, and you can unsubscribe at any time.

What is delivered, and what is only specified

The courses above are delivered and examined by KROG. CWA 18398 separately specifies 37 educational profiles, one per AI role, with learning outcomes and summative assessments. KROG does not deliver those. They are published as specifications so a reader can see the standard itself.

See the specified educational profiles

The human harness for the AI age: expert judgment, converted into verifiable infrastructure — profiles, credentials, rules, and models trained by the people who hold them.

One network, from learning to proving.

We start with law and AI governance — the same model reaches every profession where competence must be proven.