KROG

KROG Legal Engineering Academy · BeLEx

Consent you can prove.

Six courses that turn a legal duty into a specification a machine can execute and a regulator can check — taught in consent, because ISO/IEC has already published the standards.

  • 6 courses · 7 lessons each
  • Video on demand + oral examination
  • EQF 5–6 · no coding required
  • €595 · founding cohort €449 with code FOUNDING (first 20 seats)

Why consent has to be built right

Consent is the one legal basis the individual controls — and the one the organisation must be able to prove. If the proof fails, the processing that rests on it fails too.

The EU has chosen a format.

In May 2026 the European Commission called for tenders for a Data Altruism Consent Management System under the Data Governance Act — open-source software through which people give, withdraw and manage consent, interoperable with EU digital infrastructure. The tender specifications require consent receipts that follow ISO/IEC TS 27560:2023. When the Commission builds its reference implementation on a standard, that standard becomes the measure others are held to.

No proof, no consent.

GDPR Art. 7(1) puts the burden on the controller: where processing rests on consent, the controller must be able to demonstrate it — who consented, to what, when, on which notice, and whether it has since been withdrawn. A consent that cannot be demonstrated cannot be relied on. The processing then has no legal basis under Art. 6(1), and every activity resting on it is unlawful. Documentation is a condition of validity, not paperwork after the fact.

Consent is how data is exchanged for value.

Much data sharing rests on a simple bargain: the individual shares data and gets something back. Media subscribers consent to personalised recommendations and content; retailers build product recommendations and direct marketing on consented first-party data. That value lasts only as long as the consent holds — and can be shown to hold.

Consent has to travel between systems.

Today consent sits in silos. Public bodies and health services each run their own consent solutions, many designed years before ISO/IEC TS 27560 was published in 2023, each with its own data model. When one system cannot read another's consent status, someone checks it by hand — or the data sharing stops. A shared vocabulary and one JSON consent record that any system can parse, verify and act on removes the bottleneck.

Coverage · published in full

We publish what the catalogue does not cover yet

Every criterion in GDPR-CARPA is mapped to the course that teaches it — and the 28 of 30 subjects we have not written yet are named, not hidden.

criteria mapped
70
subjects available now
2 of 30
subjects coming soon
4
subjects planned
24
See the criteria index →
Video · 2 min

Booking, fees, and your credential

How the certification exam is booked and held — and what a pass gives you: a verified credential on your profile, a badge, and a diploma.
Start hereFree · Structured Consent

See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.

What you'll be able to do

By the end you can take a legal requirement and produce a specification that a machine can execute and a regulator can check.

  • Turn a duty into a data structure. GDPR Art. 7(1) becomes four sections, eight mandatory processing fields, and events that are appended and never overwritten.

  • Read a standard the way an engineer reads a spec. Requirement levels, clause by clause, and what changes when a field is mandatory in both record and receipt.

  • Map a clause to its legal basis — and defend the mapping. ISO/IEC 29184 §5.3 against Art. 13 and Art. 14, including recording “does not apply” with a justification.

  • Design the interface, not just the document. Progressive disclosure, document to dashboard, and comprehension you can evidence under Art. 25(1).

  • Build the audit file as you go, and stand behind it. One client brief, four processing activities, three builds — and an oral defence.

You leave with artefacts you can show, not a certificate of attendance.

Who it's for

For you

Lawyers and privacy professionals who want to work in structure rather than prose. The work that used to train a junior lawyer is now done by an LLM in seconds; what it cannot do is decide what the law requires and state it precisely enough for a system to execute and an auditor to check. That is legal engineering, and legal-AI companies are hiring for it. Also for engineers and designers building consent into products.

For your organisation

DPOs and compliance leads who need consent documentation that survives an audit and ports between systems. Train the people who build and defend it.

Contact us for team pricing — hello@signatu.com

Browse by programme

Role

EQF level

Who teaches it

Georg Philip Krog has spent more than a decade building legal ontologies, rule logic and consent infrastructure. His paper on implementing ISO/IEC TS 27560:2023 consent records and receipts for the GDPR and the Data Governance Act received the best paper award at the Annual Privacy Forum 2024.

Photo and link to KROG profile to follow.

Certification

Included in the purchase:

  • Portfolio assessment: a consent record, a consent receipt, a consent notice and a privacy notice, each assessed against the standard it is built to.
  • A 60-minute oral examination over video. You defend your artefacts; the credential is attested on your portfolio, not on a score.
  • On a pass: a verified credential on your KROG profile, a badge and a diploma, each with a unique ID and a public verification page.

Pass all six to earn the capstone title BeLEx Certified Legal Engineer — Structured Consent. The examination is booked on KROG after purchase.

  1. 01 · Learn

    Courses 1–4 model consent and notice information to ISO/IEC TS 27560 and ISO/IEC 29184 and map it to the GDPR; course 5 is the design craft on top; course 6 is the capstone studio.

  2. 02 · Produce

    The consent notice and the UI it appears in, the consent record and receipt, the privacy notice and the dashboard over it — plus the §5.1 audit file you assemble during the capstone.

  3. 03 · Assess

    Each course ends in its own exam: you are handed real artefacts and asked to read them. The capstone is attested by oral examination on your portfolio — not by a score.

  4. 04 · Prove

    Per course: that course's credential, e.g. Structured Consent — Consent Records (ISO/IEC TS 27560), at the EQF level the course states (5–6). All six: the capstone title BeLEx Certified Legal Engineer — Structured Consent. Each with a unique ID and a public verification page on KROG.

Jurisdiction editions (roadmap)

The catalogue ships first mapped to EU law (GDPR and AI Act). Editions mapping the same artefacts onto other countries' laws follow — so the courses, and their certifications, extend jurisdiction by jurisdiction. The full list of covered countries will be published shortly.

Why this catalogue

The PDF privacy policy and the opaque consent log are on their way out. Auditors, regulators, partners and the systems we integrate with increasingly expect consent, privacy and AI-governance information to be structured, portable and verifiable — not buried in prose. ISO/IEC has published the standards; the EU has enacted the rules. This catalogue shows you how to put them to work.

  • Built directly on international standards (ISO/IEC TS 27560:2023, ISO/IEC 29184:2020) and EU regulation (GDPR, AI Act) — not one vendor's house style — and mapped onto the law's actual requirements.
  • Machine-readable and interoperable by design — documentation that automates, audits and ports across systems, and that agents can read, verify and act on.
  • Practical throughout, from a free introduction to capstone courses where you produce the real thing and certify.

Email newsletter

Get notified when new courses, modules and updates are published. No spam — course announcements only.

Double opt-in: we store your address only to send this list, and you can unsubscribe at any time.

What is delivered, and what is only specified

The courses above are delivered and examined by KROG. CWA 18398 separately specifies 37 educational profiles, one per AI role, with learning outcomes and summative assessments. KROG does not deliver those. They are published as specifications so a reader can see the standard itself.

See the specified educational profiles

The human harness for the AI age: expert judgment, converted into verifiable infrastructure — profiles, credentials, rules, and models trained by the people who hold them.

One network, from learning to proving.

We start with law and AI governance — the same model reaches every profession where competence must be proven.