Jason Edwards

Certified: The IAPP CIPM Audio Course

Certified: The IAPP CIPM Audio Course is an audio-first study and skill-building program for privacy professionals, security and compliance practitioners, product leaders, and busy managers who need a practical path into privacy program management. It’s designed for people who want to understand how a privacy program actually runs, not just memorize terms. If you’re stepping into a privacy role, supporting a privacy office, or translating privacy requirements into real-world operations, this course is built for you. You’ll get a clear, structured approach that assumes you have a full schedule...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 22, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 49 — Conduct M&A privacy due diligence to surface shared-data risks early 22.02.2026

This episode explains how to conduct privacy due diligence during mergers and acquisitions, because CIPM exam questions often test whether you can identify privacy risk in business transactions before systems and data are combined. You will learn how to assess target-company data practices, including what personal data is collected, which jurisdictions apply, how consent and notices are handled, a...

Episode 48 — Set enforceable limits on data use, reuse, minimization, and retention 22.02.2026

This episode focuses on setting enforceable limits on data use, reuse, minimization, and retention, because CIPM expects you to convert privacy principles into controls that survive real operational pressure. You will learn how to define permitted uses in a way that aligns with notice commitments and purpose limitation, how to prevent “reuse creep” where teams repurpose data for new initiatives wi...

Episode 47 — Determine data location and cross-border flows with operational accuracy 22.02.2026

This episode teaches how to determine data location and cross-border flows with operational accuracy, because CIPM exam scenarios often depend on whether you can identify where data is stored, replicated, accessed, and transferred, not just where the company is headquartered. You will learn how data location is shaped by architecture decisions such as multi-region cloud deployments, failover and d...

Episode 46 — Assess technical risks across infrastructure, cloud, endpoints, and storage layers 22.02.2026

This episode explains how to assess technical risks across infrastructure, cloud services, endpoints, and storage layers, because CIPM expects privacy program managers to understand where technical weaknesses create privacy impact, even if they are not hands-on engineers. You will learn how privacy risk shows up in access control failures, misconfigurations, weak logging, insecure APIs, exposed st...

Episode 45 — Identify physical and environmental risks impacting privacy and confidentiality 22.02.2026

This episode covers physical and environmental risks that can impact privacy and confidentiality, because CIPM questions often include scenarios where strong policies fail due to weak physical controls and poor operational discipline. You will learn how physical security intersects with privacy outcomes through risks like unauthorized facility access, shoulder surfing, exposed paper records, insec...

Episode 44 — Draft and negotiate privacy clauses that reduce risk and strengthen accountability 22.02.2026

This episode explains how to draft and negotiate privacy clauses that reduce risk while remaining implementable, because the CIPM exam expects you to connect contract language to program controls, monitoring, and enforcement. You will learn the purpose of key clause categories, including processing instructions, confidentiality, access controls, sub-processor governance, cross-border transfer safe...

Episode 43 — Build vendor due diligence questions that expose real privacy control maturity 22.02.2026

This episode focuses on building due diligence questions that reveal true privacy control maturity, because CIPM exam items often hinge on whether you can gather the right evidence to make defensible vendor decisions. You will learn how to move beyond generic questionnaires by asking targeted questions tied to data handling realities, such as how the vendor limits internal access, how it segregate...

Episode 42 — Evaluate third parties by service type, access level, and processing activities 22.02.2026

This episode teaches how to evaluate third parties using a structured approach based on service type, access level, and what processing activities they actually perform, because CIPM expects you to tailor due diligence and controls to risk rather than using a one-size-fits-all checklist. You will learn to separate vendors who only receive limited identifiers from those with broad system access, an...

Episode 41 — Assess outsourcing risks: processing obligations, contracts, and transfer constraints 22.02.2026

This episode explains how to assess outsourcing risk when personal data is processed by external providers, because CIPM exam questions often test whether you can translate high-level obligations into vendor controls that hold up in real operations. You will learn how outsourcing changes the risk surface through expanded access, additional processing purposes, and new transfer pathways, and how to...

Episode 40 — Perform gap analysis against laws, regulations, and accepted standards 22.02.2026

This episode covers how to perform a gap analysis that produces clear, actionable remediation, because the CIPM exam expects you to compare current program state to applicable requirements and prioritize improvements. You will learn how to define the baseline for comparison, whether it is a legal obligation set, regulatory guidance, internal policy standards, or industry frameworks, and how to map...

Episode 39 — Measure policy compliance using tests, attestations, and control validation methods 22.02.2026

This episode explains how to measure privacy policy compliance using methods that stand up to scrutiny, because CIPM questions often test whether you can verify controls rather than simply assert that policies exist. You will learn how to choose validation methods such as automated tests, manual reviews, sampling, attestations, configuration checks, and evidence-based walkthroughs, and how to alig...

Episode 38 — Record data elements, purpose, access, systems, and retention for accountability 22.02.2026

This episode focuses on recording the specific data elements a program manages, why they are processed, who can access them, where they live, and how long they are retained, because CIPM expects you to demonstrate accountability with structured, audit-ready documentation. You will learn how to define data elements and categories consistently, connect each to a purpose and processing activity, and...

Episode 37 — Map data flows to understand processing, sharing, storage, and transfer points 22.02.2026

This episode teaches how to map data flows so you can see how personal data moves through collection, processing, storage, sharing, and transfer, because CIPM questions often require you to reason about risk and controls across the full journey. You will learn the core elements of a data flow map, including actors, systems, interfaces, data elements, purposes, and transfer points, and how to repre...

Episode 36 — Document data holdings using inventories that support real operational decisions 22.02.2026

This episode explains how to build and maintain a data inventory that supports real decisions, because the CIPM exam tests whether you understand inventories as foundational to rights handling, incident response, retention enforcement, and vendor oversight. You will learn what a useful inventory captures, including systems of record, key data categories, sensitivity, purposes, owners, access patte...

Episode 35 — Monitor legal change across jurisdictions and translate it into program updates 22.02.2026

This episode covers how to monitor legal and regulatory change and convert it into practical program updates, because CIPM expects you to manage privacy programs in a shifting environment without creating constant chaos. You will learn how to set up a repeatable change-management process that identifies relevant changes, assesses impact on current processing and controls, and prioritizes updates b...

Episode 34 — Plan for audits: scope, evidence, sampling, and corrective action workflows 22.02.2026

This episode explains how to plan for privacy audits in a way that reduces disruption and improves outcomes, because CIPM questions frequently test audit readiness, evidence quality, and follow-through on findings. You will learn how to define audit scope based on risk, program objectives, and regulatory or contractual requirements, and how to prepare evidence that demonstrates both design and ope...

Episode 33 — Design dashboards and reporting that make privacy metrics actionable for leaders 22.02.2026

This episode teaches how to turn privacy metrics into dashboards and reports that drive decisions, because the CIPM exam expects you to communicate program status in a way that prompts governance actions and resource choices. You will learn how to match reporting formats to audiences, such as executives who need trends and risk signals, operational managers who need backlogs and bottlenecks, and c...

Episode 32 — Define privacy metrics for oversight, governance, and operational decision-making 22.02.2026

This episode focuses on building privacy metrics that leaders can use to govern and improve the program, because CIPM questions often ask which measurements best reflect program health and control performance. You will learn to distinguish activity metrics from outcome metrics, and to define indicators that connect to risks such as unmanaged sharing, delayed rights fulfillment, weak vendor oversig...

Episode 31 — Build privacy training and awareness programs across employees and contractors 22.02.2026

This episode explains how to design and run privacy training and awareness that actually changes behavior, because the CIPM exam tests whether you understand training as an operational control with measurable outcomes. You will learn how to segment training by role, risk exposure, and access to personal data, and how to set learning objectives that map to real tasks like handling rights requests,...

Episode 30 — Define breach response roles by function, with internal and external accountability 22.02.2026

This episode focuses on defining breach response roles by function, because CIPM expects you to coordinate privacy, security, legal, communications, and business leadership under time pressure while maintaining defensible accountability. You will learn how to assign responsibilities for detection and triage, containment and eradication, evidence preservation, legal assessment, notification decisio...

Episode 29 — Define privacy roles across IT, HR, Legal, Security, and product teams 22.02.2026

This episode explains how to define privacy roles across core functions so accountability is clear and work does not stall, because CIPM is fundamentally about program management across the organization. You will learn how privacy responsibilities typically distribute across IT operations, HR and employee-data owners, Legal counsel, Security teams, Procurement, and product and engineering groups,...

Episode 28 — Govern external sharing: processors, controllers, recipients, and onward transfers 22.02.2026

This episode covers how to govern external sharing using clear role definitions and contractual controls, because CIPM questions regularly test whether you can classify parties correctly and apply the right oversight. You will review what it means operationally to share data with processors, other controllers, and various recipients, and how onward transfers and sub-processors can expand risk beyo...

Episode 27 — Govern internal sharing and disclosure with clear controls and approvals 22.02.2026

This episode explains how to govern internal sharing and disclosure so personal data moves only as needed and with appropriate safeguards, because CIPM expects you to manage internal flows as carefully as external transfers. You will define internal disclosure in operational terms, then learn how to apply purpose limitation, minimization, role-based access, and need-to-know principles to common sc...

Episode 26 — Execute defensible disposal and deletion processes across systems and vendors 22.02.2026

This episode focuses on making disposal and deletion defensible across modern architectures, because CIPM questions often test whether you understand the difference between policy intent and technical reality. You will learn what “deletion” means in practice across production databases, backups, logs, analytics platforms, and SaaS vendors, and how to document what was deleted, when, and under what...

Episode 25 — Establish retention rules that align legal duties, risk, and business value 22.02.2026

This episode explains how to establish retention rules that balance legal requirements, privacy risk, and legitimate business value, because CIPM expects you to manage retention as a control with measurable outcomes. You will learn how to define retention in terms of purpose, category, jurisdictional drivers, and operational constraints, and how to align retention schedules with records management...

Listen to the Certified: The IAPP CIPM Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.