Learn Data Governance with Phoebe

From data practitioner to Data Protection Officer

Two tracks, one running company. The 8-session DPO track equips DA, DE, DS, and AI practitioners to run as a Data Protection Officer; the 4-session executive track gives C-level leaders and boards the working ideas in plain language. Singapore PDPA as the home law, GDPR as the international mirror, all taught on Himalaya - from messy day one to a board-ready program.

8DPO sessions
4exec sessions
2rulebooks: PDPA + GDPR
11PDPA obligations

The DPO track πŸ›‘οΈ Β· for practitioners Β· 8 x 45 min

For DA, DE, DS, and AI practitioners - the full body of knowledge to run as a Data Protection Officer, hands-on, session by session.

🧭 Session 1 · start here

Data governance and the DPO

What governance actually is, the DAMA wheel, and why Singapore law makes the DPO role mandatory for every organisation.

β–Ά Start hereFoundations
βš–οΈ Session 2 Β· building up

The law you enforce

The 11 PDPA obligations and the DNC registers, mirrored against GDPR's 7 principles, 6 lawful bases, and 8 rights.

PDPA + GDPR
πŸ—ΊοΈ Session 3 Β· building up

Know your data

Build the Record of Processing, classify by sensitivity, and stand up the catalog, glossary, and lineage that give a DPO sight.

Inventory + RoPA
πŸ“£ Session 4 Β· getting real

Consent, purpose & marketing (DNC)

Fix consent and purpose, and run the DNC register check before a marketing blast to eight million consumers.

Consent + DNC
πŸ›‘οΈ Session 5 Β· getting real

Protection & breach response

Reasonable security arrangements, then a full breach tabletop against the PDPC clock: assess, notify, remediate.

Breach runbook
♻️ Session 6 Β· getting real

Data lifecycle

Accuracy, retention and disposal, cross-border transfer safeguards, and answering access, correction, and rights requests.

Retention + transfer
πŸ—οΈ Session 7 Β· advanced

The operating model + maturity

Policies, decision rights, owners, stewards, and a council - then score the whole program on a maturity model.

DAMA + DCAM
πŸŽ“ Session 8 Β· advanced

Capstone: stand up the program

Run a DPIA on the AI copilot, prove accountability, and assemble everything into a first-90-days plan and board report.

DPIA + first 90 days
start here - foundations building up - the law & the data getting real - the live duties advanced - the program

The executive track πŸ‘” Β· for C-level, boards & curious leaders Β· 4 x 30-45 min

No tech required. The working ideas in plain language - what data governance costs to ignore, the rules in one page, the questions that expose your real risk, and the investment case. Also a friendly on-ramp for LinkedIn readers.

Choose your path πŸ—ΊοΈ

Practitioners start at Session 1; executives start at Exec session 1. The full journey makes a DPO; the fast-tracks fit a specific gap.

πŸ‘” Executive journey (no tech) E1β†’ E2β†’ E3β†’ E4β†’ curious? DPO session 1
πŸ›‘οΈ Full DPO journey 1β†’ 2β†’ 3β†’ 4β†’ 5β†’ 6β†’ 7β†’ 8
βš–οΈ Compliance-first (the law & the duties) 1β†’ 2β†’ 4β†’ 5β†’ 6
πŸ—οΈ Governance-builder (structure & maturity) 1β†’ 3β†’ 7β†’ 8
One company, both tracks. Every session governs Himalaya - a Singapore-based B2B2C SaaS platform with 1,200 business clients and 8 million end consumers, growing data-first and governance-last. Practitioners take the DPO's chair and build the program session by session; executives take the CEO's chair and learn what to ask, fund, and expect.
Honest about scope. This track teaches the working body of knowledge - the DAMA governance function, the PDPA obligations and DNC, the GDPR mirror, and the DCAM maturity concept. Certification exams (IAPP CIPP/E, CIPM, CIPT and the PDPC's own courses), member-only frameworks, and legal advice stay with their official sources. The PDPA Data Portability Obligation is taught as enacted but not yet in force.

The knowledge map 🧠

The DPO track at a glance - hover a session to spotlight its concepts, click any node to jump in.