Catalogue
Become a certified legal engineer.
Two programmes that turn privacy and AI compliance into structure machines can read, verify, and act on.
- Expert-led
- Certification
- ISO/IEC + EU law
Introduction: Consent, in two views
See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.
Browse by programme
Role
EQF level
4 courses
GDPR & AI Act Operations
Operational compliance — records of processing, impact assessments, breach handling and AI governance, mapped to the GDPR and the EU AI Act.
Four operational courses for data protection officers, compliance teams and AI leads — to build, maintain and defend the documentation the law requires.
Records of Processing Activities
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 5
- Standard
- GDPR Art. 30
- Role
- Lawyer
Build and maintain records of processing activities for controllers and processors. The course covers the minimum content, how to scope a processing activity, integration with system inventories and processor registers, and how the record actually operates as a governance tool — not just as an audit artefact.
Read moreShow less
Seven lessons · video on demand
Data Protection Impact Assessment
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 6
- Standard
- GDPR Art. 35
- Role
- Lawyer
When a DPIA is mandatory, how to assess necessity and proportionality, which mitigations reduce residual risk, and when prior consultation with the supervisory authority is required (Article 36). Built on the EDPB criteria and national lists of processing operations that require a DPIA.
Read moreShow less
Seven lessons · video on demand
Personal Data Breach
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 6
- Standard
- GDPR Art. 33–34
- Role
- Lawyer
From detection to documentation: how a breach is detected, assessed for risk, notified to the supervisory authority within 72 hours, and — where the risk to individuals is high — communicated to the data subjects. Covers the internal breach protocol, the controller-processor interface, and the templates that make the process runnable under pressure.
Read moreShow less
Seven lessons · video on demand
AI Act Compliance
- Browse by programme
- GDPR & AI Act Operations
- EQF level
- EQF 7
- Standard
- Regulation (EU) 2024/1689
- Role
- Lawyer + AI expert
Classification of AI systems by risk, with a focus on high-risk systems under Annex III. The course covers provider obligations (quality management, technical documentation, conformity assessment, CE marking, registration) and deployer obligations (instructions for use, human oversight, logging, fundamental rights impact assessment where required), and the interface with the GDPR.
Read moreShow less
Seven lessons · video on demand
Certification — two tiers
Per course
Pass a course's exam to earn its credential — e.g. Structured Consent — Consent Records (ISO/IEC TS 27560). The exam isn't a formality: you're handed real artefacts and asked to read them.
Capstone
Pass every course in a programme to earn its capstone title — e.g. Certified Legal Engineer — Structured Consent.
Exams and certificates are issued and verified on KROG, each with a unique ID and a public verification page.
Jurisdiction editions (roadmap)
The catalogue ships first mapped to EU law (GDPR and AI Act). Editions mapping the same artefacts onto other countries' laws follow — so the courses, and their certifications, extend jurisdiction by jurisdiction. The full list of covered countries will be published shortly.
Why this catalogue
The PDF privacy policy and the opaque consent log are on their way out. Auditors, regulators, partners and the systems we integrate with increasingly expect consent, privacy and AI-governance information to be structured, portable and verifiable — not buried in prose. ISO/IEC has published the standards; the EU has enacted the rules. This catalogue shows you how to put them to work.
- Built directly on international standards (ISO/IEC TS 27560:2023, ISO/IEC 29184:2020) and EU regulation (GDPR, AI Act) — not one vendor's house style — and mapped onto the law's actual requirements.
- Machine-readable and interoperable by design — documentation that automates, audits and ports across systems, and that agents can read, verify and act on.
- Practical throughout, from a free introduction to capstone courses where you produce the real thing and certify.
Register your interest
The full schedule, pricing, and the jurisdiction-edition list land soon. Register now for updates on launch, pricing and registration.
Subscribe to KROG Courses
