Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Privacy & Compliance
Training

Prepare your team for the privacy and AI governance obligations auditors actually check.

48 interactive exercises across 4 courses on AI basics, GDPR, the EU AI Act, and OWASP privacy risks. Free to play, no sign-up required.

1

AI Basics for Everyone

4 exercises

2

GDPR Compliance

18 exercises

Personal Data Essentials

Recognize personal data before you handle it.

  • GDPRArt. 4
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Principles and Legal Bases

Pick the lawful basis before the work starts.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Everyday Privacy Duties

The three reflexes that keep a small problem small.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Employee Data Collection

Send the staff form twice: once wrong, once lawfully.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Marketing Consent Management

Segment a marketing list by the consent each contact gave.

  • GDPRArt. 7
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Data Breach Response

Report a misdirected-email breach inside the 72-hour clock.

  • GDPRArt. 33
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Privacy by Design Review

Evaluate a product feature through a privacy-first lens.

  • GDPRArt. 25
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Legitimate DSAR Processing

Process a data subject access request end to end.

  • GDPRArt. 15
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

PII Document Redaction

Redact personal data from a report before it goes to auditors.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Fraudulent DSAR Detection

Spot fake data access requests used for social engineering.

  • GDPRArt. 12
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Third-Party Data Processor Vetting

Find the gaps in a vendor's DPA before signing.

  • GDPRArt. 28
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Security Incident Response

Spot a live breach in the SOC and escalate it to the DPO.

  • GDPRArt. 32
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Cross-Border Data Transfers

Navigate transfer mechanisms for data leaving the EEA.

  • GDPRArt. 44
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Data Protection Impact Assessment

Run a DPIA for a high-risk data processing activity.

  • GDPRArt. 35
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Data Mapping and Records of Processing

Review a healthcare provider's Article 30 processing register.

  • GDPRArt. 30
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Cookie Consent Management

Fix a cookie banner a regulator has already flagged.

  • GDPRArt. 7
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Data Retention Compliance

Decide what to delete, retain, hold, or anonymize.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Breach Response Tabletop

Take the privacy seat on a live ransomware bridge.

  • GDPRArt. 33
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →
3

EU AI Act Compliance

16 exercises

AI Literacy Essentials

Earn the AI literacy required by Article 4 before touching company AI tools.

  • EU AI ActArt. 4
Play Exercise →

AI Risk Classification

Sort real AI deployments into the four EU AI Act risk tiers.

  • EU AI ActArt. 6
Play Exercise →

Prohibited AI Practices

Stop banned AI deployments before they go live.

  • EU AI ActArt. 5
Play Exercise →

High-Risk AI: Deployer Obligations

Block a high-risk AI launch with compliance gaps in any of seven areas.

  • EU AI ActArt. 8
Play Exercise →

Provider vs. Deployer: Who's Responsible?

A compliant vendor product does not make your deployment compliant.

  • EU AI ActArt. 16
Play Exercise →

AI Transparency and Disclosure

Label AI chatbots and synthetic media correctly under Article 50.

  • EU AI ActArt. 50
Play Exercise →

Meaningful Human Oversight

Override an AI loan recommendation when the evidence does not match.

  • EU AI ActArt. 14
Play Exercise →

AI Data Governance

Block AI training that uses a leaky, biased, or oversharing dataset.

  • GDPRArt. 5
  • EU AI ActArt. 10
Play Exercise →

AI and Data Protection

Run a healthcare AI through both EU AI Act and GDPR at once.

  • GDPRArt. 22
  • EU AI ActArt. 26
Play Exercise →

Bias and Discrimination in AI

Investigate proxy variables hiding inside a resume-screening model.

  • EU AI ActArt. 10
Play Exercise →

Fundamental Rights Impact Assessment

Run a FRIA before a social housing AI ever assigns a benefit decision.

  • GDPRArt. 35
  • EU AI ActArt. 27
Play Exercise →

AI Incident Reporting

Report a discriminatory AI rejection pattern under Article 73.

  • EU AI ActArt. 73
  • CIS 17
  • NIST CSFRS.MA
Play Exercise →

AI Governance in Your Organization

Build an AI registry and shut down shadow AI in your company.

  • EU AI ActArt. 4
Play Exercise →

General-Purpose AI Model Obligations

Map GPAI provider and downstream deployer duties for systemic-risk models.

  • EU AI ActArt. 53
Play Exercise →

Using AI Tools Responsibly at Work

Make compliant AI choices through a normal working day.

  • EU AI ActArt. 4
  • CIS 14.4
Play Exercise →

EU AI Act Penalties and Enforcement

Map the three-tier penalty structure to real enforcement scenarios.

  • EU AI ActArt. 99
Play Exercise →
4

OWASP Top 10 Privacy Risks

10 exercises

Soon

Privacy Breach Through Application Vulnerabilities

An error message and one URL id are enough to read other people's records.

Play Exercise →
Soon

Internal Data Leakage to Unauthorized Parties

Customer records reach an outside vendor because a share link was too broad.

Play Exercise →
Soon

Handling a Personal Data Breach

The clock starts at detection, not when you understand the leak.

Play Exercise →
Soon

Consent Dark Patterns and Bundled Permissions

One checkbox for five purposes is not consent to any of them.

Play Exercise →
Soon

Opaque Privacy Policies and Hidden Data Practices

The policy discloses everything and explains nothing.

Play Exercise →
Soon

Personal Data Deletion Failures

The account is gone. The backup, the analytics profile, and the CRM are not.

Play Exercise →
Soon

Outdated and Inaccurate Personal Data

A stale record stops being untidy once it decides someone's credit.

Play Exercise →
Soon

Session Hijacking Through Missing Expiration

The last person to use this workstation is still logged in.

Play Exercise →
Soon

Blocked Data Subject Access Requests

One person's data, one month, and no system that agrees who they are.

Play Exercise →
Soon

Excessive Personal Data Collection

Every field you collect just in case is a field you have to protect.

Play Exercise →

Frequently asked questions

What does the AI Basics for Everyone course cover?

AI Basics for Everyone is an EU AI Act course for every employee, not only the teams that build or buy AI. It starts with What Counts as AI, which teaches the legal definition of an AI system and the difference between provider and deployer.

Labeling AI and Deepfakes covers when AI content needs a label. Using AI Within the Law covers data protection, copyright and employment law, and When AI Use Goes Wrong shows what misuse costs the company and the employee.

What does GDPR Article 7 require for marketing consent?

GDPR Article 7 requires that consent be freely given, specific, informed, and unambiguous. Organizations must use clear affirmative action like unticked checkboxes, keep records proving when and how consent was obtained, and make withdrawal as easy as opting in.

Pre-ticked boxes, bundled consent, and vague privacy policies do not meet the standard. Regulators have imposed over EUR 400M in fines related to consent violations.

What is the GDPR 72-hour breach notification rule?

Under GDPR Article 33, organizations must notify their supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals.

The notification must include the nature of the breach, approximate number of affected individuals, likely consequences, and measures taken. British Airways was fined GBP 20M for the security failures behind its 2018 breach.

What is privacy by design under GDPR?

Privacy by design, codified in GDPR Article 25, requires organizations to integrate data protection into the design of systems and processes from the start, not bolt it on afterward. This includes data minimization, purpose limitation, and privacy-protective default settings.

The concept originated with Ann Cavoukian's seven foundational principles in the 1990s and became a legal obligation when the GDPR took effect in 2018.

What is a DSAR under GDPR?

A Data Subject Access Request (DSAR) is a right under GDPR Article 15 allowing any individual to request a copy of the personal data an organization holds about them.

Organizations must respond within 30 days, provide the data in an accessible format, and include information about processing purposes, retention periods, and third-party recipients. Requests can arrive through any channel, including email, web forms, or verbal communication.

What does GDPR Article 28 require for data processors?

Article 28 requires a written contract, called a Data Processing Agreement (DPA), between the controller and every processor handling personal data. The DPA must specify the processing purpose, data types, duration, and security measures.

Processors can only engage sub-processors with prior written authorization from the controller. The processor must assist with DSARs, breach notification, and data deletion, and submit to audits by the controller.

What is the OWASP Top 10 Privacy Risks?

The OWASP Top 10 Privacy Risks is an industry framework that identifies the ten most common ways organizations mishandle personal data.

It covers web application vulnerabilities that leak PII, operator-sided data leakage, insufficient breach response, bundled consent, non-transparent policies, failed data deletion, poor data quality, missing session expiration, blocked data subject access, and excessive data collection. The framework helps organizations assess and mitigate privacy risks beyond regulatory compliance.

How does the OWASP Privacy Risks list relate to GDPR?

The OWASP Top 10 Privacy Risks overlaps significantly with GDPR requirements. For example, OWASP P3 (Insufficient Data Breach Response) maps to GDPR Article 33 breach notification, P4 (Consent on Everything) maps to Article 7 consent requirements, P6 (Insufficient Deletion) maps to Article 17 right to erasure, and P9 (Inability to Access Data) maps to Article 15 data subject access rights.

Training on both frameworks gives teams a complete picture of privacy obligations.

What does the EU AI Act require for workforce training?

Article 4 of the EU AI Act requires providers and deployers to take measures to support the development of AI literacy of their staff, the wording since the 2026 Digital Omnibus. The duty has applied since February 2, 2025, and scales with each role and the systems staff use. In practice that means staff understand how AI generates outputs, its limitations including hallucinations, and the data privacy implications of using AI tools.

Articles 14 and 26 add competency requirements for human oversight of high-risk AI systems from December 2, 2027, and Article 50 requires transparency disclosure for AI chatbots and AI-generated content. Failure to train staff on these requirements creates direct exposure to enforcement actions.

How do GDPR and the EU AI Act interact?

The two frameworks are independent but overlapping. When an AI system processes personal data, both apply simultaneously. GDPR Article 22 grants individuals the right not to be subject to automated decisions with legal effects, and that right attaches regardless of how the EU AI Act classifies the system.

For high-risk AI systems processing personal data, organizations may need both a GDPR Data Protection Impact Assessment (DPIA) under Article 35 and a Fundamental Rights Impact Assessment (FRIA) under Article 27 of the EU AI Act. One does not replace the other.

What are the three penalty tiers under the EU AI Act?

Tier 1 covers Article 5 prohibited AI practices and reaches 35 million euros or 7% of global annual turnover, whichever is higher. Tier 2 covers most operator obligations, including those for high-risk AI, and reaches 15 million euros or 3%; GPAI model providers face the same ceiling under Article 101. Tier 3 covers supplying incorrect, incomplete, or misleading information to authorities and reaches 7.5 million euros or 1%.

Beyond fines, national market surveillance authorities can suspend non-compliant systems, require market withdrawal, publicly disclose violations, and mandate corrective measures. The fines fall on organizations, not individual employees, though staff who knowingly mislead an authority can face disciplinary action and penalties under national law.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.