Catalogue
Become a certified legal engineer.
Two programmes that turn privacy and AI compliance into structure machines can read, verify, and act on.
- Expert-led
- Certification
- ISO/IEC + EU law
Introduction: Consent, in two views
See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.
Browse by programme
Role
EQF level
6 courses
Structured Consent
Modelling consent records, receipts, and notices to ISO/IEC TS 27560 and ISO/IEC 29184 — mapped to the GDPR.
Six courses. Turn consent into structure a machine can read, verify, and act on — and that you can defend afterwards.
Consent Records
- Browse by programme
- Structured Consent
- EQF level
- EQF 5
- Standard
- ISO/IEC TS 27560:2023 · GDPR Art. 7(1)
- Role
- Lawyer + AI expert
Produce a consent record that is standardised, machine-readable, and interoperable. You learn the duty that creates it — GDPR Art. 7(1), which requires the controller to be able to demonstrate consent — the four sections every record carries, the eight mandatory processing fields, and why events are appended and never overwritten. You finish able to read any 27560 record end to end.
Read moreShow less
Seven lessons · video on demand
Consent Receipts
- Browse by programme
- Structured Consent
- EQF level
- EQF 5
- Standard
- ISO/IEC TS 27560 §9
- Role
- Lawyer + AI expert
Give the individual their own copy of the consent. Under §9.2 the receipt reuses the record's fields at the same requirement levels — it is not a lesser summary. You learn what the header carries, why the GDPR names no explicit duty to issue a receipt, and why Art. 15 and Art. 20 are the nearest hooks.
Read moreShow less
Seven lessons · video on demand
Consent Notices
- Browse by programme
- Structured Consent
- EQF level
- EQF 5
- Standard
- ISO/IEC 29184:2020 §5
- Role
- Lawyer
The notice is what makes consent informed. ISO/IEC 29184 §5 sets when it must reach the individual (§5.2), the sixteen content elements it must convey (§5.3), and the controls that let consent be withdrawn or renewed (§5.4–5.5). You learn to read a notice against the clause that governs it, and to spot a provision failure before a regulator does.
Read moreShow less
Seven lessons · video on demand
Privacy Notices
- Browse by programme
- Structured Consent
- EQF level
- EQF 5
- Standard
- ISO/IEC 29184:2020 §5
- Role
- Lawyer
The organisation-wide document — what most people still call the privacy policy. You apply the same standard at scale: provision judged per collection route, content judged per section and per processing activity, and the Art. 13 / Art. 14 split on where the data came from. Including the discipline of recording "does not apply", with a justification, control by control.
Read moreShow less
Seven lessons · video on demand
Privacy Notice Design
- Browse by programme
- Structured Consent
- EQF level
- EQF 6
- Standard
- Design craft · builds on 03 & 04
- Role
- AI expert
The policy does not fail because of the law. It fails because of layout, length, and sequencing — and that is a design outcome, which means it can be redesigned. You learn real progressive disclosure, the move from document to dashboard where the reader can act as well as read, symmetry that survives an audit, and comprehension you can evidence under GDPR Art. 25(1).
Read moreShow less
Seven lessons · video on demand
Consent & Notice Studio
- Browse by programme
- Structured Consent
- EQF level
- EQF 6
- Standard
- Capstone · builds on 01–05
- Role
- AI expert
No new theory. One client brief, four processing activities, three builds: the consent notice and its UI, then the record and receipt, then the privacy notice and the dashboard over it. You assemble the §5.1 audit file as you go, and you defend it. The credential is attested by oral examination on your portfolio — not by a score.
Read moreShow less
Seven lessons · studio format
4 courses
GDPR & AI Act Operations
Operational compliance — records of processing, impact assessments, breach handling and AI governance, mapped to the GDPR and the EU AI Act.
Four operational courses for data protection officers, compliance teams and AI leads — to build, maintain and defend the documentation the law requires.
Records of Processing Activities
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 5
- Standard
- GDPR Art. 30
- Role
- Lawyer
Build and maintain records of processing activities for controllers and processors. The course covers the minimum content, how to scope a processing activity, integration with system inventories and processor registers, and how the record actually operates as a governance tool — not just as an audit artefact.
Read moreShow less
Seven lessons · video on demand
Data Protection Impact Assessment
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 6
- Standard
- GDPR Art. 35
- Role
- Lawyer
When a DPIA is mandatory, how to assess necessity and proportionality, which mitigations reduce residual risk, and when prior consultation with the supervisory authority is required (Article 36). Built on the EDPB criteria and national lists of processing operations that require a DPIA.
Read moreShow less
Seven lessons · video on demand
Personal Data Breach
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 6
- Standard
- GDPR Art. 33–34
- Role
- Lawyer
From detection to documentation: how a breach is detected, assessed for risk, notified to the supervisory authority within 72 hours, and — where the risk to individuals is high — communicated to the data subjects. Covers the internal breach protocol, the controller-processor interface, and the templates that make the process runnable under pressure.
Read moreShow less
Seven lessons · video on demand
AI Act Compliance
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 7
- Standard
- Regulation (EU) 2024/1689
- Role
- Lawyer + AI expert
Classification of AI systems by risk, with a focus on high-risk systems under Annex III. The course covers provider obligations (quality management, technical documentation, conformity assessment, CE marking, registration) and deployer obligations (instructions for use, human oversight, logging, fundamental rights impact assessment where required), and the interface with the GDPR.
Read moreShow less
Seven lessons · video on demand
Certification — two tiers
Per course
Pass a course's exam to earn its credential — e.g. Structured Consent — Consent Records (ISO/IEC TS 27560). The exam isn't a formality: you're handed real artefacts and asked to read them.
Capstone
Pass every course in a programme to earn its capstone title — e.g. Certified Legal Engineer — Structured Consent.
Exams and certificates are issued and verified on KROG, each with a unique ID and a public verification page.
Jurisdiction editions (roadmap)
The catalogue ships first mapped to EU law (GDPR and AI Act). Editions mapping the same artefacts onto other countries' laws follow — so the courses, and their certifications, extend jurisdiction by jurisdiction. The full list of covered countries will be published shortly.
Why this catalogue
The PDF privacy policy and the opaque consent log are on their way out. Auditors, regulators, partners and the systems we integrate with increasingly expect consent, privacy and AI-governance information to be structured, portable and verifiable — not buried in prose. ISO/IEC has published the standards; the EU has enacted the rules. This catalogue shows you how to put them to work.
- Built directly on international standards (ISO/IEC TS 27560:2023, ISO/IEC 29184:2020) and EU regulation (GDPR, AI Act) — not one vendor's house style — and mapped onto the law's actual requirements.
- Machine-readable and interoperable by design — documentation that automates, audits and ports across systems, and that agents can read, verify and act on.
- Practical throughout, from a free introduction to capstone courses where you produce the real thing and certify.
Register your interest
The full schedule, pricing, and the jurisdiction-edition list land soon. Register now for updates on launch, pricing and registration.
Subscribe to KROG Courses
