Jason Edwards

Certified: The ISACA CDPSE Audio Course

Welcome to Certified: The ISACA CDPSE Audio Course. I’m going to guide you through the ideas and skills that sit behind the Certified Data Privacy Solutions Engineer credential, in a way that’s clear, exam-aligned, and grounded in how privacy actually works inside organizations. You can expect focused episodes that build your understanding step by step, from privacy governance and data life cycle thinking to privacy by design practices that hold up under real delivery pressure. We’ll keep the language straightforward, define terms in context, and connect each topic to the kinds of decisions yo...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 21 — Build a data inventory you can trust and keep it current (Domain 2C-1 Data Inventory) 14.02.2026

This episode explains how to create and maintain a data inventory that is accurate enough to drive real engineering decisions, because CDPSE questions often assume you can trace data across systems and prove where it lives. You’ll define the minimum inventory fields that matter for privacy work, including data categories, identifiers, purposes, lawful basis signals, owners, storage locations, rete...

Episode 20 — Produce evidence and artifacts that prove privacy controls actually work (Domain 2B-2 Evidence and Artifacts) 14.02.2026

This episode focuses on evidence and artifacts, teaching you what it means to prove privacy controls work in practice, not just on paper, which is a major CDPSE differentiator. You’ll define strong evidence characteristics such as completeness, timeliness, traceability, and independence, then connect them to common artifacts like data inventories, system logs, access reviews, retention enforcement...

Episode 19 — Use privacy frameworks to structure controls, evidence, and governance decisions (Domain 2B-1 Privacy Frameworks) 14.02.2026

This episode shows how privacy frameworks help you structure controls and evidence so privacy engineering is consistent across products and audits, not dependent on individual judgment. You’ll learn how frameworks provide common language for principles, requirements, and control categories, and how they support mapping from obligations to implementation choices and monitoring. We’ll cover practica...

Episode 18 — Choose risk responses that balance privacy, delivery, and business reality (Domain 2A-5 Risk Response) 14.02.2026

This episode explains privacy risk response options and how to choose among them when business delivery, user experience, and legal obligations all compete, which is exactly how CDPSE scenarios are framed. You’ll cover risk treatment strategies such as mitigate, avoid, transfer, and accept, and you’ll learn what “good” acceptance looks like: explicit ownership, documented rationale, compensating c...

Episode 17 — Identify privacy threats and vulnerabilities before they become operational failures (Domain 2A-4 Threats and Vulnerabilities) 14.02.2026

This episode teaches you to identify privacy threats and vulnerabilities using the same disciplined thinking used in security, but with privacy-specific harm pathways and control intent. You’ll define threats such as unauthorized access, over-collection, secondary use, re-identification, inference, and uncontrolled sharing, and you’ll connect them to vulnerabilities like weak access controls, exce...

Episode 16 — Make privacy training and awareness stick in real teams and workflows (Domain 2A-3 Privacy Training and Awareness) 14.02.2026

This episode explains how privacy training and awareness becomes effective only when it changes everyday behavior in product, engineering, support, and operations, which is a common CDPSE theme when questions test “what will reduce risk most.” You’ll learn how to tailor training by role so it covers the decisions each team actually makes, such as collecting only necessary fields, handling data sub...

Episode 15 — Perform privacy-focused assessments like PIAs with practical scope and outputs (Domain 2A-2 Privacy-Focused Assessment) 14.02.2026

This episode focuses on privacy-focused assessments, including PIA-style approaches, as practical tools that produce actionable outputs rather than paperwork. You’ll learn how to scope an assessment based on data types, processing purposes, populations impacted, and system boundaries, and how to identify where a shallow scope creates blind spots that later become findings. We’ll define what strong...

Episode 14 — Build a privacy risk management process that stays consistent and repeatable (Domain 2A-1 Risk Management Process and Policies) 14.02.2026

This episode shows how to build a privacy risk management process that is consistent across teams, repeatable across projects, and measurable over time, which is exactly the kind of operational maturity CDPSE questions look for. You’ll define privacy risk in terms of likelihood, impact, and harm pathways, then learn how policies, standards, and decision criteria keep risk scoring from turning into...

Episode 13 — Spaced Retrieval Review: Rapid recall for Domain 1 governance and operations essentials (Domain 1A-1 to 1B-4) 14.02.2026

This review episode strengthens fast recall across Domain 1 by connecting definitions, responsibilities, and operational processes into a single decision framework you can apply under exam timing pressure. You’ll revisit how to recognize personal information, apply privacy principles, and translate legal requirements into concrete controls, then immediately tie those ideas to governance roles, ven...

Episode 12 — Deliver data subject rights, requests, and notification with speed and correctness (Domain 1B-4 Data Subject Rights, Requests, and Notification) 14.02.2026

This episode covers the practical mechanics of fulfilling data subject rights, requests, and notifications in a way that is accurate, timely, and consistent across systems, which is a frequent focus in CDPSE scenarios. You’ll define common request types such as access, deletion, correction, portability, and objection, and you’ll learn how identity verification, scope confirmation, and data discove...

Episode 11 — Run privacy incident management with clear triggers, evidence, and remediation flow (Domain 1B-3 Incident Management) 14.02.2026

This episode explains privacy incident management as an operational process with defined triggers, repeatable handling steps, and evidence that supports both remediation and accountability. You’ll learn how to distinguish a privacy incident from a general security event, how to set severity criteria based on the type of personal information involved, and how to preserve decision quality when facts...

Episode 10 — Engineer vendor and supply chain privacy controls that hold up under pressure (Domain 1B-2 Vendor and Supply Chain Management) 14.02.2026

This episode teaches vendor and supply chain privacy management from an engineering perspective, focusing on the controls and evidence CDPSE expects you to evaluate under real-world constraints. You’ll cover how to scope vendor access, define data handling requirements, and translate privacy obligations into contracts, SLAs, technical controls, and ongoing monitoring that actually detects drift. W...

Episode 9 — Define privacy roles, culture, and responsibilities so accountability is real (Domain 1B-1 Organizational Culture, Structure, and Responsibilities) 14.02.2026

This episode breaks down organizational roles and responsibilities that support effective privacy engineering, and it shows how CDPSE tests accountability through governance structure and operating rhythm. You’ll define what “ownership” means for data, systems, controls, and decisions, and how to make responsibilities auditable through RACI-style clarity, escalation paths, and decision logs. We’ll...

Episode 8 — Build privacy documentation that survives audits, incidents, and organizational change (Domain 1A-4 Privacy Documentation) 14.02.2026

This episode explains the privacy documentation CDPSE expects you to recognize, evaluate, and improve, emphasizing durability under audit scrutiny and during real incidents. You’ll cover the purpose and structure of artifacts like data inventories, dataflow documentation, PIAs, policies and standards, DPIA-style outputs, records of processing activities, retention schedules, and incident records,...

Episode 7 — Handle cross-border and sector rules without losing control of privacy obligations (Domain 1A-3 Privacy Laws and Regulations) 14.02.2026

This episode focuses on cross-border data movement and sector-specific rules, teaching you how to keep privacy obligations coherent when data, vendors, and users span multiple legal regimes. You’ll learn how to identify which rule set applies based on data subject location, establishment, processing purpose, and industry context, and how to avoid the common mistake of treating geography as the onl...

Episode 6 — Interpret privacy laws and regulations as concrete, testable engineering requirements (Domain 1A-3 Privacy Laws and Regulations) 14.02.2026

This episode shows how to translate legal and regulatory obligations into specific, testable requirements that engineers and auditors can verify, which is a central CDPSE skill. You’ll practice turning broad obligations into measurable controls, such as defining retention rules, access controls, disclosure conditions, and response timelines, along with the evidence artifacts that prove compliance....

Episode 5 — Apply privacy principles like Privacy by Design, consent, and transparency end-to-end (Domain 1A-2 Privacy Principles) 14.02.2026

This episode covers core privacy principles and how to apply them as engineering requirements across collection, use, sharing, storage, and deletion, which is how CDPSE expects you to think. You’ll clarify Privacy by Design as proactive control selection and lifecycle integration, not a policy slogan, and you’ll connect consent and transparency to concrete mechanisms like notices, preference cente...

Episode 4 — Recognize personal information precisely across systems, contexts, and data types 14.02.2026

This episode teaches you to identify personal information accurately, even when it is fragmented across systems, transformed through analytics, or combined with other data in ways that re-create identifiability. You’ll define direct identifiers, indirect identifiers, sensitive categories, and contextual signals that make data personal in one setting but not another, which is a common CDPSE exam tr...

Episode 3 — Exam Acronyms: High-Yield Audio Reference for Fast CDPSE Recall 14.02.2026

This episode gives you a high-yield acronym reference designed for CDPSE-style questions where time pressure and similar-looking options can cause avoidable mistakes. You’ll focus on acronyms that change the meaning of an answer, such as assessment types, data governance artifacts, security and privacy controls, and common operational processes used to demonstrate compliance and accountability. We...

Episode 2 — Build a spoken 30-day CDPSE study plan that tracks every tested objective 14.02.2026

This episode builds a 30-day, audio-friendly study plan that aligns directly to what CDPSE tests, with a clear sequence that mirrors how privacy engineering happens in real organizations. You’ll organize your time around domain dependencies, starting with governance terms and roles, then moving into risk methods and assessments, then the data life cycle, and finally the technology controls that ma...

Episode 1 — Decode what the CDPSE exam actually tests across real privacy engineering work 14.02.2026

This episode explains how CDPSE maps privacy engineering work into four exam domains so you can study with a job-relevant mental model instead of memorizing isolated facts. You’ll learn what “governance,” “privacy risk management,” “data life cycle,” and “privacy by design” mean in exam language, and how questions often blend them in a single scenario such as a new product launch, a vendor integra...

Listen to the Certified: The ISACA CDPSE Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.