Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Privacy & Compliance
Training

Prepare your team for the privacy and AI governance obligations auditors actually check.

44 interactive exercises across 3 courses on GDPR, the EU AI Act, and OWASP privacy risks. Free to play, no sign-up required.

1

GDPR Compliance

18 exercises

Personal Data Essentials

Recognize personal data before you handle it.

  • GDPRArt. 4
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Principles and Legal Bases

Pick the lawful basis before the work starts.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Everyday Privacy Duties

The three reflexes that keep a small problem small.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Employee Data Collection

Send the staff form twice: once wrong, once lawfully.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Marketing Consent Management

Build compliant opt-in flows that regulators accept.

  • GDPRArt. 7
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Breach Response

Triage a breach and meet the 72-hour notification clock.

  • GDPRArt. 33
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Privacy by Design Review

Evaluate a product feature through a privacy-first lens.

  • GDPRArt. 25
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Legitimate DSAR Processing

Process a data subject access request end to end.

  • GDPRArt. 15
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

PII Document Redaction

Redact personal data from documents before disclosure.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Fraudulent DSAR Detection

Spot fake data access requests used for social engineering.

  • GDPRArt. 12
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Third-Party Data Processor Vetting

Evaluate a vendor's data processing controls before signing.

  • GDPRArt. 28
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Security Incident Response

Coordinate security and privacy teams during a live breach.

  • GDPRArt. 32
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Cross-Border Data Transfers

Navigate transfer mechanisms for data leaving the EEA.

  • GDPRArt. 44
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Protection Impact Assessment

Run a DPIA for a high-risk data processing activity.

  • GDPRArt. 35
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Mapping and Records of Processing

Build an Article 30 processing register from scratch.

  • GDPRArt. 30
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Cookie Consent Management

Fix a cookie banner a regulator has already flagged.

  • GDPRArt. 7
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Retention Compliance

Decide what to delete, retain, hold, or anonymize.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Breach Response Tabletop

Take the privacy seat on a live ransomware bridge.

  • GDPRArt. 33
  • CIS 3
  • NIST CSFPR.DS
Play Exercise
2

EU AI Act Compliance

16 exercises

AI Literacy Essentials

Earn the AI literacy required by Article 4 before touching company AI tools.

  • EU AI ActArt. 4
Play Exercise

AI Risk Classification

Sort real AI deployments into the four EU AI Act risk tiers.

  • EU AI ActArt. 6
Play Exercise

Prohibited AI Practices

Stop banned AI deployments before they go live.

  • EU AI ActArt. 5
Play Exercise

High-Risk AI: Deployer Obligations

Block a high-risk AI launch with compliance gaps in any of seven areas.

  • EU AI ActArt. 8
Play Exercise

Provider vs. Deployer: Who's Responsible?

A compliant vendor product does not make your deployment compliant.

  • EU AI ActArt. 16
Play Exercise

AI Transparency and Disclosure

Label AI chatbots and synthetic media correctly under Article 50.

  • EU AI ActArt. 50
Play Exercise

Meaningful Human Oversight

Override an AI loan recommendation when the evidence does not match.

  • EU AI ActArt. 14
Play Exercise

AI Data Governance

Block AI training that uses a leaky, biased, or oversharing dataset.

  • GDPRArt. 5
  • EU AI ActArt. 10
Play Exercise

AI and Data Protection

Run a healthcare AI through both EU AI Act and GDPR at once.

  • GDPRArt. 22
  • EU AI ActArt. 26
Play Exercise

Bias and Discrimination in AI

Investigate proxy variables hiding inside a resume-screening model.

  • EU AI ActArt. 10
Play Exercise

Fundamental Rights Impact Assessment

Run a FRIA before a social housing AI ever assigns a benefit decision.

  • GDPRArt. 35
  • EU AI ActArt. 27
Play Exercise

AI Incident Reporting

Report a discriminatory AI rejection pattern under Article 62.

  • EU AI ActArt. 62
  • CIS 17
  • NIST CSFRS.MA
Play Exercise

AI Governance in Your Organization

Build an AI registry and shut down shadow AI in your company.

  • EU AI ActArt. 4
Play Exercise

General-Purpose AI Model Obligations

Map GPAI provider and downstream deployer duties for systemic-risk models.

  • EU AI ActArt. 53
Play Exercise

Using AI Tools Responsibly at Work

Make compliant AI choices through a normal working day.

  • EU AI ActArt. 4
  • CIS 14.4
Play Exercise

EU AI Act Penalties and Enforcement

Map the three-tier penalty structure to real enforcement scenarios.

  • EU AI ActArt. 99
Play Exercise
3

OWASP Top 10 Privacy Risks

10 exercises

Soon

Privacy Breach Through Application Vulnerabilities

An error message and one URL id are enough to read other people's records.

Play Exercise
Soon

Internal Data Leakage to Unauthorized Parties

Customer records reach an outside vendor because a share link was too broad.

Play Exercise
Soon

Handling a Personal Data Breach

The clock starts at detection, not when you understand the leak.

Play Exercise
Soon

Consent Dark Patterns and Bundled Permissions

One checkbox for five purposes is not consent to any of them.

Play Exercise
Soon

Opaque Privacy Policies and Hidden Data Practices

The policy discloses everything and explains nothing.

Play Exercise
Soon

Personal Data Deletion Failures

The account is gone. The backup, the analytics profile, and the CRM are not.

Play Exercise
Soon

Outdated and Inaccurate Personal Data

A stale record stops being untidy once it decides someone's credit.

Play Exercise
Soon

Session Hijacking Through Missing Expiration

The last person to use this workstation is still logged in.

Play Exercise
Soon

Blocked Data Subject Access Requests

One person's data, one month, and no system that agrees who they are.

Play Exercise
Soon

Excessive Personal Data Collection

Every field you collect just in case is a field you have to protect.

Play Exercise

Frequently asked questions

What does GDPR Article 7 require for marketing consent?

GDPR Article 7 requires that consent be freely given, specific, informed, and unambiguous. Organizations must use clear affirmative action like unticked checkboxes, keep records proving when and how consent was obtained, and make withdrawal as easy as opting in.

Pre-ticked boxes, bundled consent, and vague privacy policies do not meet the standard. Regulators have imposed over EUR 400M in fines related to consent violations.

What is the GDPR 72-hour breach notification rule?

Under GDPR Article 33, organizations must notify their supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals.

The notification must include the nature of the breach, approximate number of affected individuals, likely consequences, and measures taken. British Airways was fined GBP 20M partly for delayed and inadequate breach response.

What is privacy by design under GDPR?

Privacy by design, codified in GDPR Article 25, requires organizations to integrate data protection into the design of systems and processes from the start, not bolt it on afterward. This includes data minimization, purpose limitation, and privacy-protective default settings.

The concept originated with Ann Cavoukian's seven foundational principles in the 1990s and became a legal obligation when the GDPR took effect in 2018.

What is a DSAR under GDPR?

A Data Subject Access Request (DSAR) is a right under GDPR Article 15 allowing any individual to request a copy of the personal data an organization holds about them.

Organizations must respond within 30 days, provide the data in an accessible format, and include information about processing purposes, retention periods, and third-party recipients. Requests can arrive through any channel, including email, web forms, or verbal communication.

What does GDPR Article 28 require for data processors?

Article 28 requires a written contract, called a Data Processing Agreement (DPA), between the controller and every processor handling personal data. The DPA must specify the processing purpose, data types, duration, and security measures.

Processors can only engage sub-processors with prior written authorization from the controller. The processor must assist with DSARs, breach notification, and data deletion, and submit to audits by the controller.

What is the OWASP Top 10 Privacy Risks?

The OWASP Top 10 Privacy Risks is an industry framework that identifies the ten most common ways organizations mishandle personal data.

It covers web application vulnerabilities that leak PII, operator-sided data leakage, insufficient breach response, bundled consent, non-transparent policies, failed data deletion, poor data quality, missing session expiration, blocked data subject access, and excessive data collection. The framework helps organizations assess and mitigate privacy risks beyond regulatory compliance.

How does the OWASP Privacy Risks list relate to GDPR?

The OWASP Top 10 Privacy Risks overlaps significantly with GDPR requirements. For example, OWASP P3 (Insufficient Data Breach Response) maps to GDPR Article 33 breach notification, P4 (Consent on Everything) maps to Article 7 consent requirements, P6 (Insufficient Deletion) maps to Article 17 right to erasure, and P9 (Inability to Access Data) maps to Article 15 data subject access rights.

Training on both frameworks gives teams a complete picture of privacy obligations.

What does the EU AI Act require for workforce training?

Article 4 of the EU AI Act mandates that every employee who interacts with AI systems must have sufficient AI literacy. The requirement became enforceable on February 2, 2025, and applies regardless of role or department. Organizations must ensure staff understand how AI generates outputs, its limitations including hallucinations, and the data privacy implications of using AI tools.

Articles 14 and 26 add competency requirements for human oversight of high-risk AI systems, and Article 50 requires transparency disclosure for AI chatbots and AI-generated content. Failure to train staff on these requirements creates direct exposure to enforcement actions.

How do GDPR and the EU AI Act interact?

The two frameworks are independent but overlapping. When an AI system processes personal data, both apply simultaneously. GDPR Article 22 grants individuals the right not to be subject to automated decisions with legal effects, and that right attaches regardless of how the EU AI Act classifies the system.

For high-risk AI systems processing personal data, organizations may need both a GDPR Data Protection Impact Assessment (DPIA) under Article 35 and a Fundamental Rights Impact Assessment (FRIA) under Article 27 of the EU AI Act. One does not replace the other.

What are the three penalty tiers under the EU AI Act?

Tier 1 covers Article 5 prohibited AI practices and reaches 35 million euros or 7% of global annual turnover, whichever is higher. Tier 2 covers high-risk AI obligations and GPAI provider obligations and reaches 15 million euros or 3%. Tier 3 covers supplying incorrect, incomplete, or misleading information to authorities and reaches 7.5 million euros or 1.5%.

Beyond fines, national market surveillance authorities can suspend non-compliant systems, require market withdrawal, publicly disclose violations, and mandate corrective measures. Individual employees can face personal liability for knowingly enabling non-compliance or obstructing investigations.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.