Jason Edwards

Certified: The ISACA CDPSE Audio Course

Welcome to Certified: The ISACA CDPSE Audio Course. I’m going to guide you through the ideas and skills that sit behind the Certified Data Privacy Solutions Engineer credential, in a way that’s clear, exam-aligned, and grounded in how privacy actually works inside organizations. You can expect focused episodes that build your understanding step by step, from privacy governance and data life cycle thinking to privacy by design practices that hold up under real delivery pressure. We’ll keep the language straightforward, define terms in context, and connect each topic to the kinds of decisions yo...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 46 — Choose privacy enhancing technologies that match threats, data, and architecture (Domain 4C-4 Privacy Enhancing Technologies) 14.02.2026

This episode introduces privacy enhancing technologies as a toolbox that must be matched to a specific threat model, dataset, and system architecture, because “use a PET” is never a complete answer on CDPSE. You’ll learn what PETs are trying to achieve, such as limiting exposure during computation, reducing identifiability, or enabling analysis with reduced disclosure, and how to evaluate tradeoff...

Episode 45 — Apply anonymization and pseudonymization with honest limits and verification (Domain 4C-3 Anonymization and Pseudonymization) 14.02.2026

 This episode explains anonymization and pseudonymization in the way CDPSE expects: as risk-reduction techniques with strict limits, not magic labels that eliminate obligations. You’ll learn the functional difference between truly anonymized data and data that is merely pseudonymized, masked, or tokenized, and you’ll see why identifiability depends on context, auxiliary data, and re-identification...

Episode 44 — Govern tracking technologies and cookie management with clear, enforceable rules (Domain 4C-2 Tracking Technologies) 14.02.2026

This episode covers tracking technologies and cookie management as a governance-and-implementation problem that spans websites, mobile apps, SDKs, and third-party tags. You’ll learn how tracking creates privacy risk through cross-context linkage, hidden data sharing, and secondary use, and how CDPSE scenarios often test whether you can control tracking beyond marketing intent statements. We’ll def...

Episode 43 — Implement consent tagging that travels with data and survives system boundaries (Domain 4C-1 Consent Tagging) 14.02.2026

This episode explains consent tagging as a practical mechanism for making consent enforceable across pipelines, services, and vendors, rather than treating consent as a one-time UI event. You’ll learn how to represent consent states in data models, how to tie tags to purpose and processing context, and how to ensure downstream systems can read and enforce those tags consistently, even when data is...

Episode 42 — Build monitoring and logging that supports privacy without creating new exposure (Domain 4B-6 Monitoring and Logging) 14.02.2026

This episode teaches how to design monitoring and logging so it improves detection, troubleshooting, and auditability without quietly increasing privacy risk through over-collection and long retention. You’ll learn how to decide what events to collect, what fields to exclude or redact, and how to enforce consistent practices across services so personal information does not leak into telemetry by d...

Episode 41 — Use encryption and hashing correctly so privacy goals match cryptographic reality (Domain 4B-5 Encryption and Hashing) 14.02.2026

This episode clarifies how encryption and hashing support privacy goals, and it corrects the common misunderstanding that “hashed” automatically means “anonymous” or “safe.” You’ll distinguish encryption at rest, encryption in transit, and application-level encryption, and you’ll learn what each protects against and what it does not protect against, especially when insiders, misconfigured keys, or...

Episode 40 — Select transport protocols that protect privacy across modern and legacy paths (Domain 4B-4 Communication and Transport Protocols) 14.02.2026

This episode focuses on communication and transport protocols as privacy safeguards, because the protocol choices and configurations determine whether data can be intercepted, altered, misrouted, or exposed through weak defaults. You’ll learn how to evaluate protocols in terms of confidentiality, integrity, authentication, and downgrade risk, and how to recognize when “encrypted somewhere” is not...

Episode 39 — Maintain patching and hardening discipline that protects privacy at scale (Domain 4B-3 Patch Management and Hardening) 14.02.2026

This episode explains patch management and hardening as privacy protection at scale, because unpatched systems and weak baselines often lead to the kinds of unauthorized access and data exposure events that drive regulatory reporting and loss of trust. You’ll learn how to connect vulnerability management to privacy risk by considering what data the system touches, how reachable it is, and what lat...

Episode 38 — Implement identity and access management that enforces least privilege for privacy (Domain 4B-2 Identity and Access Management) 14.02.2026

This episode teaches IAM as one of the strongest privacy controls available, because access decisions determine who can view, export, modify, or share personal information in both normal operations and high-pressure events. You’ll learn to apply least privilege in practical terms, including role design, entitlement review, privileged access workflows, service account governance, and separation of...

Episode 37 — Operationalize asset management so data assets and owners are never ambiguous (Domain 4B-1 Asset Management) 14.02.2026

This episode explains asset management as a foundational privacy enabler, because you cannot protect or govern what you cannot confidently identify, classify, and assign to an accountable owner. You’ll learn how to treat systems, datasets, pipelines, and integrations as assets with defined owners, purpose statements, data categories, and lifecycle expectations, and how to keep this accurate throug...

Episode 36 — Engineer APIs and cloud-native services to prevent silent privacy failure modes (Domain 4A-5 APIs and Cloud-Native Services) 14.02.2026

This episode focuses on APIs and cloud-native services as places where privacy failures can happen silently, such as over-broad responses, weak authorization checks, unintended data propagation through events, and uncontrolled downstream consumers. You’ll learn how to evaluate API design for privacy outcomes, including data minimization in payloads, field-level authorization, consistent handling o...

Episode 35 — Embed privacy into the secure development life cycle without slowing delivery (Domain 4A-4 Secure Development Life Cycle) 14.02.2026

This episode explains how to integrate privacy into the SDLC so it becomes a predictable part of delivery rather than a last-minute blocker, which is a common CDPSE scenario theme. You’ll learn where privacy fits into requirements, design, build, test, deploy, and operate, with concrete examples like collecting only necessary fields, handling consent states, enforcing retention rules, and preventi...

Episode 34 — Design connectivity choices that reduce privacy risk across networks and services (Domain 4A-3 Connectivity) 14.02.2026

This episode teaches connectivity as a privacy risk multiplier, because the way systems connect often determines whether data is exposed, intercepted, misrouted, or broadly accessible by default. You’ll learn to evaluate connectivity patterns such as VPN access, private links, service meshes, direct internet exposure, and third-party network paths, and you’ll connect each to privacy outcomes like...

Episode 33 — Secure devices and endpoints so personal information exposure stays contained (Domain 4A-2 Devices and Endpoints) 14.02.2026

This episode covers endpoint and device security as a privacy control surface, emphasizing how laptops, mobile devices, kiosks, and managed endpoints can become the fastest route to personal information exposure even when servers are well protected. You’ll learn to connect endpoint risks to privacy-specific harms, such as local caching of sensitive data, unapproved sync tools, screenshots and expo...

Episode 32 — Choose infrastructure and platform approaches for privacy across legacy and cloud (Domain 4A-1 Infrastructure and Platform Technology) 14.02.2026

This episode explains how infrastructure and platform choices influence privacy outcomes, and how CDPSE questions often test whether you can connect architecture decisions to exposure, control effectiveness, and evidence quality. You’ll compare common patterns across legacy data centers, hybrid environments, and cloud platforms, focusing on where personal information resides, how it moves, and whi...

Episode 31 — Spaced Retrieval Review: Data life cycle management from collection to destruction (Domain 3A-1 to 3B-4) 14.02.2026

This review episode locks in rapid recall for Domain 3 by walking the data life cycle as a single continuous control story, from the moment data is collected to the point it is destroyed or irreversibly de-identified. You’ll rehearse how collection decisions shape downstream risk, how processing and storage create new exposure through copies and transformations, and how sharing and access patterns...

Episode 30 — Spaced Retrieval Review: Data inventory, flows, classification, minimization, and retention (Domain 2C-1 to 2C-9) 14.02.2026

This review episode strengthens rapid recall across the Domain 2C data management objectives by linking them into an end-to-end control story you can apply to exam scenarios. You’ll rehearse how inventory and dataflow accuracy enables everything else, then connect classification to safeguard selection, and connect minimization, purpose limitation, and consent to the decisions that control collecti...

Episode 29 — Protect privacy in monitoring, logging, and observability without losing visibility (Domain 2C-9 Monitoring and Logging) 14.02.2026

This episode addresses a common real-world conflict: monitoring and logging are essential for reliability and security, but they can also become a privacy liability through over-collection and long retention. You’ll learn how to evaluate logs for personal information, how to limit what is captured, and how to protect what must be collected with access controls, segregation, redaction, and retentio...

Episode 28 — Manage privacy in third-party data sharing with clear boundaries and controls (Domain 2C-8 Data Sharing and Third Parties) 14.02.2026

This episode teaches you how to control privacy risk when data is shared with third parties, emphasizing boundaries, contractual constraints, and technical enforcement that can be verified. You’ll define common sharing patterns such as processors, joint activities, and partners, and you’ll learn how each pattern changes obligations around purpose, onward transfer, breach notification, and deletion...

Episode 27 — Apply purpose limitation so data use stays aligned with promises and approvals (Domain 2C-7 Purpose Limitation) 14.02.2026

This episode explains purpose limitation as a governance-and-technology pairing that prevents silent expansion of how data is used, which is a frequent source of privacy failures and exam scenarios. You’ll learn how to define purpose in operational terms, how to document it in inventories and processing records, and how to enforce it through access patterns, service boundaries, and approval gates....

Episode 26 — Build consent management that is measurable, reversible, and reliable (Domain 2C-6 Consent Management) 14.02.2026

This episode covers consent management as a system capability with clear states, audit trails, and enforcement points, not just a banner or checkbox. You’ll define valid consent characteristics, how consent differs from other legal bases, and how to represent consent decisions in data models so downstream services can honor them consistently. We’ll explore scenarios like marketing preferences, ana...

Episode 25 — Define retention and disposal that is enforceable across systems and vendors (Domain 2C-5 Retention and Disposal) 14.02.2026

This episode teaches retention and disposal as enforceable control systems rather than policy statements, because exam scenarios often reveal gaps between stated retention and actual technical behavior. You’ll learn how to design retention rules based on purpose and obligation, then connect them to implementation patterns like TTL enforcement, automated deletion jobs, archive controls, and deletio...

Episode 24 — Use data minimization to reduce exposure without breaking the business (Domain 2C-4 Data Minimization) 14.02.2026

This episode explains data minimization as an engineering and product discipline that reduces exposure by limiting collection, limiting use, and limiting retention to what is necessary for defined purposes. You’ll learn how to translate minimization into design choices, such as collecting fewer fields, reducing event granularity, shortening retention, avoiding sensitive enrichment, and splitting i...

Episode 23 — Classify data properly to drive the right privacy safeguards (Domain 2C-3 Data Classification) 14.02.2026

This episode focuses on data classification as a decision tool that drives safeguards, access rules, retention, and sharing controls, not as a label exercise. You’ll learn how privacy classification differs from security-only classification by emphasizing identifiability, sensitivity, context, and potential harm, including re-identification and inference risk. We’ll cover practical classification...

Episode 22 — Map data flows end-to-end so privacy risk is visible, not guessed (Domain 2C-2 Data Flow) 14.02.2026

This episode teaches you to map data flows with enough precision to answer exam scenarios about collection, sharing, storage, and deletion across complex architectures. You’ll define what a complete data flow includes, such as sources, collection mechanisms, transformations, destinations, access paths, sharing boundaries, and where controls and approvals apply. We’ll use scenarios like mobile apps...

Listen to the Certified: The ISACA CDPSE Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.