Continuing Education Information Sheet
2023 Year in Review: The State and Impact of the GDPR
- Provider
- Legal Cyber Academy · Lexeprint Inc.
13413 Granger Ave, Orlando, FL 32827
info@lawandforensics.com · https://www.lexeprint.com - Delivery method
- On-demand, self-study (online, recorded)
- Instructional time
- 1h 3m
- Assessment
- Graded multiple-choice exam · pass mark 70%
- Administered online, unproctored, with identity verified only to the level of a confirmed email address. Each sitting draws 10questions at random from the course’s pool, is timed, and is fixed for that sitting; correct answers are never disclosed. The pass mark is provider-set and is not supported by published reliability statistics or a standard-setting panel.
Equivalent credit hours
1.0 on a 60-minute basis (most CLE / general CE) · 1.2 on a 50-minute basis (NASBA CPE). Rounded down to the nearest tenth of an hour; your board may round differently.
Learning objectives
- Explain the GDPR's scope and exceptions
- Describe the 2023 shift toward centralized enforcement
- Identify the criteria for GDPR penalties
- Review landmark 2023 fines and best practices
Audience & prerequisites
Intended audience: Attorneys advising clients with business in the E.U. on data privacy compliance.
Level: intermediate
Prerequisites: None
Faculty
Daniel B. Garrie, Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard
Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare
Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.
K Royal, Global Chief Privacy Officer and Deputy General Counsel, Crawford & Company
Crawford & Company
K Royal is Global Chief Privacy Officer and Deputy General Counsel at Crawford & Company, where she is tasked with developing and implementing the company's privacy policies, designed to protect both client and company data. She has more than 25 years of experience in the legal and health-related fields. She holds a J.D. from the Sandra Day O'Connor College of Law at Arizona State University and a Ph.D., and is certified as a Fellow of Information Privacy (FIP), in Privacy Management (CIPM) and in US and EU privacy law (CIPP/US, CIPP/E), plus Certified Data Privacy Solutions Engineer (CDPSE) through ISACA. She co-hosts the Serious Privacy podcast. At Legal Cyber Academy she teaches on the New York DFS cybersecurity regulations and the GDPR.
Jarno Vanto, Partner, King & Spalding LLP
King & Spalding
Jarno Vanto is a partner in King & Spalding's Data, Privacy and Security practice in New York. He counsels multinational clients on privacy and cybersecurity regulatory compliance and investigations, AI governance, international transfers of personal data, and complex cross-border technology and data transactions, including data and software licensing, under regimes such as the EU General Data Protection Regulation, the California Consumer Privacy Act and the EU AI Act. He holds an LL.M. from New York University School of Law and a master of laws from the University of Turku, is admitted in New York, and holds the CIPP/US and CIPP/E certifications. He has been named to the 2026 Lawdragon 500 Leading Global Cyber Lawyers and to Cybersecurity Docket's Incident Response Elite. At Legal Cyber Academy, Jarno Vanto teaches on the state and impact of the GDPR.
Noshin Khan, Ethics and Compliance, NMC Healthcare
OneTrust
Noshin Khan works in ethics and compliance at NMC Healthcare in Abu Dhabi. She was previously Senior Compliance Counsel in the Ethics Center of Excellence at OneTrust, where her work focused on European and Middle Eastern regulation, including the European Whistleblower Protection Directive, the EU Artificial Intelligence Act, the Corporate Sustainability Due Diligence Directive, and France's Sapin II and duty of vigilance law. Before OneTrust she was a global compliance manager at Forensic Risk Alliance. She holds the CCEP-I and LPEC certifications, the CIPP/E, CIPM and FIP credentials from the IAPP, and a certificate in the ethics of AI from the London School of Economics and Political Science. At Legal Cyber Academy she teaches on the state and impact of the GDPR.
Timed agenda
| # | Topic | Minutes |
|---|---|---|
| 1 | Overview of the General Data Protection Regulation (GDPR) | 63 |
| 2 | How 2023 was Significant for the GDPR | — |
| 3 | GDPR Fines in 2023 | — |
| 4 | Key Takeaways and What Lies Ahead | — |
| Total instructional time | 63 |
Self-submission by credit type
Legal Cyber Academy is not an accredited provider; the notes below explain how a learner may self-submitthis activity where their board permits. The pathways shown reflect this course’s subject matter. Always confirm your board’s current rules.
CLE (attorneys)up to 1.0 hr (60-min basis)
Many U.S. jurisdictions let an attorney apply for CLE credit for a non-accredited program (often called individual attorney or self-application). Use this certificate plus the course Information Sheet as your supporting documentation. Your state bar or CLE board decides whether credit is granted, how much, and any self-study cap.
CE / CPD (privacy, insurance, IT)up to 1.0 hr (60-min basis)
Where your professional body recognizes self-reported or self-directed learning (CPD) — for example many privacy (CIPP/CIPM) and security certifications — record this activity using the certificate and Information Sheet. Confirm your program's self-reporting rules and any documentation it requires.
Legal Cyber Academy is not an accredited continuing-education provider, and its courses are not pre-approved for CLE, CE, CME, or CPE credit. Each course provides a graded assessment, a verifiable Certificate of Completion, and a Continuing Education Information Sheet documenting instructional time, learning objectives, faculty, and a timed agenda — the records most licensing bodies require when a learner applies for self-submitted or self-study credit. Whether credit is granted, and how much, is determined solely by your licensing board. Confirm your board's rules before claiming credit. Verify certificates at https://www.legalcyberacademy.com/certificate/ <code>.