KROG Legal Engineering Academy · BeLEx
Consent you can prove.
Six courses that turn a legal duty into a specification a machine can execute and a regulator can check — taught in consent, because ISO/IEC has already published the standards.
- 6 courses · 7 lessons each
- Video on demand + oral examination
- EQF 5–6 · no coding required
- €595 · founding cohort €449 with code FOUNDING (first 20 seats)
Why consent has to be built right
Consent is the one legal basis the individual controls — and the one the organisation must be able to prove. If the proof fails, the processing that rests on it fails too.
The EU has chosen a format.
In May 2026 the European Commission called for tenders for a Data Altruism Consent Management System under the Data Governance Act — open-source software through which people give, withdraw and manage consent, interoperable with EU digital infrastructure. The tender specifications require consent receipts that follow ISO/IEC TS 27560:2023. When the Commission builds its reference implementation on a standard, that standard becomes the measure others are held to.
No proof, no consent.
GDPR Art. 7(1) puts the burden on the controller: where processing rests on consent, the controller must be able to demonstrate it — who consented, to what, when, on which notice, and whether it has since been withdrawn. A consent that cannot be demonstrated cannot be relied on. The processing then has no legal basis under Art. 6(1), and every activity resting on it is unlawful. Documentation is a condition of validity, not paperwork after the fact.
Consent is how data is exchanged for value.
Much data sharing rests on a simple bargain: the individual shares data and gets something back. Media subscribers consent to personalised recommendations and content; retailers build product recommendations and direct marketing on consented first-party data. That value lasts only as long as the consent holds — and can be shown to hold.
Consent has to travel between systems.
Today consent sits in silos. Public bodies and health services each run their own consent solutions, many designed years before ISO/IEC TS 27560 was published in 2023, each with its own data model. When one system cannot read another's consent status, someone checks it by hand — or the data sharing stops. A shared vocabulary and one JSON consent record that any system can parse, verify and act on removes the bottleneck.
Coverage · published in full
We publish what the catalogue does not cover yet
Every criterion in GDPR-CARPA is mapped to the course that teaches it — and the 28 of 30 subjects we have not written yet are named, not hidden.
- criteria mapped
- 70
- subjects available now
- 2 of 30
- subjects coming soon
- 4
- subjects planned
- 24
Booking, fees, and your credential
Introduction: Consent, in two views
See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.
What you'll be able to do
By the end you can take a legal requirement and produce a specification that a machine can execute and a regulator can check.
Turn a duty into a data structure. GDPR Art. 7(1) becomes four sections, eight mandatory processing fields, and events that are appended and never overwritten.
Read a standard the way an engineer reads a spec. Requirement levels, clause by clause, and what changes when a field is mandatory in both record and receipt.
Map a clause to its legal basis — and defend the mapping. ISO/IEC 29184 §5.3 against Art. 13 and Art. 14, including recording “does not apply” with a justification.
Design the interface, not just the document. Progressive disclosure, document to dashboard, and comprehension you can evidence under Art. 25(1).
Build the audit file as you go, and stand behind it. One client brief, four processing activities, three builds — and an oral defence.
You leave with artefacts you can show, not a certificate of attendance.
Who it's for
For you
Lawyers and privacy professionals who want to work in structure rather than prose. The work that used to train a junior lawyer is now done by an LLM in seconds; what it cannot do is decide what the law requires and state it precisely enough for a system to execute and an auditor to check. That is legal engineering, and legal-AI companies are hiring for it. Also for engineers and designers building consent into products.
For your organisation
DPOs and compliance leads who need consent documentation that survives an audit and ports between systems. Train the people who build and defend it.
Contact us for team pricing — hello@signatu.comBrowse by programme
Role
EQF level
6 courses
Structured Consent
Modelling consent records, receipts, and notices to ISO/IEC TS 27560 and ISO/IEC 29184 — mapped to the GDPR.
Six courses. Turn consent into structure a machine can read, verify, and act on — and that you can defend afterwards.
Buy the programme — €595 →Consent Records
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC TS 27560:2023 · GDPR Art. 7(1)
- Role
- Lawyer + AI expert
- CARPA
- CARPA II-a-3
You leave able to read any ISO/IEC TS 27560 record end to end and say whether it proves consent.
Produce a consent record that is standardised, machine-readable, and interoperable. You learn the duty that creates it — GDPR Art. 7(1), which requires the controller to be able to demonstrate consent — the four sections every record carries, the eight mandatory processing fields, and why events are appended and never overwritten. You finish able to read any 27560 record end to end.
Read moreShow less
Seven lessons · video on demand
Consent Receipts
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC TS 27560 §9
- Role
- Lawyer + AI expert
- CARPA
- CARPA II-a-3
You leave able to issue a receipt that carries the record's fields at the same requirement levels.
Give the individual their own copy of the consent. Under §9.2 the receipt reuses the record's fields at the same requirement levels — it is not a lesser summary. You learn what the header carries, why the GDPR names no explicit duty to issue a receipt, and why Art. 15 and Art. 20 are the nearest hooks.
Read moreShow less
Seven lessons · video on demand
Consent Notices
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC 29184:2020 §5
- Role
- Lawyer
- CARPA
- CARPA II-a-13 – II-a-15
You leave able to test a consent notice against ISO/IEC 29184 §5 and spot a provision failure before a regulator does.
The notice is what makes consent informed. ISO/IEC 29184 §5 sets when it must reach the individual (§5.2), the sixteen content elements it must convey (§5.3), and the controls that let consent be withdrawn or renewed (§5.4–5.5). You learn to read a notice against the clause that governs it, and to spot a provision failure before a regulator does.
Read moreShow less
Seven lessons · video on demand
Privacy Notices
- Programme
- Structured Consent
- EQF
- EQF 5
- Standard
- ISO/IEC 29184:2020 §5
- Role
- Lawyer
- CARPA
- CARPA II-a-13 – II-a-15
You leave able to audit an organisation-wide privacy notice per collection route and per processing activity.
The organisation-wide document — what most people still call the privacy policy. You apply the same standard at scale: provision judged per collection route, content judged per section and per processing activity, and the Art. 13 / Art. 14 split on where the data came from. Including the discipline of recording "does not apply", with a justification, control by control.
Read moreShow less
Seven lessons · video on demand
Privacy Notice Design
- Programme
- Structured Consent
- EQF
- EQF 6
- Standard
- Design craft · builds on 03 & 04
- Role
- AI expert
- CARPA
- CARPA II-a-13 – II-a-15
You leave able to redesign a notice so comprehension can be evidenced under GDPR Art. 25(1).
The policy does not fail because of the law. It fails because of layout, length, and sequencing — and that is a design outcome, which means it can be redesigned. You learn real progressive disclosure, the move from document to dashboard where the reader can act as well as read, symmetry that survives an audit, and comprehension you can evidence under GDPR Art. 25(1).
Read moreShow less
Seven lessons · video on demand
Consent & Notice Studio
- Programme
- Structured Consent
- EQF
- EQF 6
- Standard
- Capstone · builds on 01–05
- Role
- AI expert
- CARPA
- CARPA II-a-3 · II-a-13 – II-a-15
You leave with a notice, record, receipt, privacy notice and §5.1 audit file you have defended orally.
No new theory. One client brief, four processing activities, three builds: the consent notice and its UI, then the record and receipt, then the privacy notice and the dashboard over it. You assemble the §5.1 audit file as you go, and you defend it. The credential is attested by oral examination on your portfolio — not by a score.
Read moreShow less
Seven lessons · studio format
Who teaches it
Georg Philip Krog has spent more than a decade building legal ontologies, rule logic and consent infrastructure. His paper on implementing ISO/IEC TS 27560:2023 consent records and receipts for the GDPR and the Data Governance Act received the best paper award at the Annual Privacy Forum 2024.
Photo and link to KROG profile to follow.
Certification
Included in the purchase:
- Portfolio assessment: a consent record, a consent receipt, a consent notice and a privacy notice, each assessed against the standard it is built to.
- A 60-minute oral examination over video. You defend your artefacts; the credential is attested on your portfolio, not on a score.
- On a pass: a verified credential on your KROG profile, a badge and a diploma, each with a unique ID and a public verification page.
Pass all six to earn the capstone title BeLEx Certified Legal Engineer — Structured Consent. The examination is booked on KROG after purchase.
From learning to proof
01 · Learn
Courses 1–4 model consent and notice information to ISO/IEC TS 27560 and ISO/IEC 29184 and map it to the GDPR; course 5 is the design craft on top; course 6 is the capstone studio.
02 · Produce
The consent notice and the UI it appears in, the consent record and receipt, the privacy notice and the dashboard over it — plus the §5.1 audit file you assemble during the capstone.
03 · Assess
Each course ends in its own exam: you are handed real artefacts and asked to read them. The capstone is attested by oral examination on your portfolio — not by a score.
04 · Prove
Per course: that course's credential, e.g. Structured Consent — Consent Records (ISO/IEC TS 27560), at the EQF level the course states (5–6). All six: the capstone title BeLEx Certified Legal Engineer — Structured Consent. Each with a unique ID and a public verification page on KROG.
Jurisdiction editions (roadmap)
The catalogue ships first mapped to EU law (GDPR and AI Act). Editions mapping the same artefacts onto other countries' laws follow — so the courses, and their certifications, extend jurisdiction by jurisdiction. The full list of covered countries will be published shortly.
Why this catalogue
The PDF privacy policy and the opaque consent log are on their way out. Auditors, regulators, partners and the systems we integrate with increasingly expect consent, privacy and AI-governance information to be structured, portable and verifiable — not buried in prose. ISO/IEC has published the standards; the EU has enacted the rules. This catalogue shows you how to put them to work.
- Built directly on international standards (ISO/IEC TS 27560:2023, ISO/IEC 29184:2020) and EU regulation (GDPR, AI Act) — not one vendor's house style — and mapped onto the law's actual requirements.
- Machine-readable and interoperable by design — documentation that automates, audits and ports across systems, and that agents can read, verify and act on.
- Practical throughout, from a free introduction to capstone courses where you produce the real thing and certify.
Email newsletter
Get notified when new courses, modules and updates are published. No spam — course announcements only.
What is delivered, and what is only specified
The courses above are delivered and examined by KROG. CWA 18398 separately specifies 37 educational profiles, one per AI role, with learning outcomes and summative assessments. KROG does not deliver those. They are published as specifications so a reader can see the standard itself.
See the specified educational profiles