Connect accountable roles, risk priorities, humanitarian consequences, essential services, and escalation authority.
TCAA professional pathway
AI, data protection, and digital security for NGOs.
A seven-part pathway for protecting people, information, services, and organizational trust through practical governance, safer digital habits, incident decisions, recovery, and tested resilience.

Course modules
Move from governance to trusted recovery.
Trace purpose, affected people, data, systems, partners, retention, dependencies, and confidentiality, integrity, and availability risks.
Review data use, retention, access, assurance, subprocessors, continuity, rights support, configuration, change, and exit.
Apply named accounts, MFA, least privilege, separation of duties, secure collaboration, phishing response, and joiner-mover-leaver controls.
Build safer document and AI workflows that account for indirect identifiers, generated outputs, logs, temporary copies, and authorized holds.
Report quickly, contain without destroying evidence, assess harm, support authorized notification decisions, restore trusted operations, and learn.
Test account takeover, exposed-link, and unauthorized-AI-upload scenarios and present a ninety-day improvement decision.
Practical outcomes
Participants should leave with safer habits and reusable controls.
Assessment preview
See the certificate-track task without exposing the private key.
A public outline of the assessment areas, evidence expectations, and certificate boundary. It does not include the admin answer key or scoring decisions.
A practical data-safety workflow task using fictional or redacted examples only. Real sensitive data must never be submitted in public previews or unsafe tools.
Public starter materials
Twelve practical resources for safer daily work.
The pathway is grounded in the official EU General Data Protection Regulation, EDPB Opinion 28/2024 on AI models, NIST Cybersecurity Framework 2.0, OCHA humanitarian cyber-threat guidance, and the ICRC Handbook on Data Protection in Humanitarian Action. It is professional education, not legal advice, a compliance audit, penetration testing, or security certification.
Protection boundary
This course supports safer practice, not legal certification.
The course supports proportionate governance and safer practice. It cannot determine whether a real breach is legally notifiable, replace incident-response specialists, certify GDPR compliance, or prove technical security. Automated paid certificate release remains inactive until enrollment, payment, private access, reviewed assignment, certificate issue, public verification, correction, revocation, learner support, and admin controls are tested together.
Delivery options
Useful for individuals, local organizations, and project teams.
Related learning
Connect data protection with field systems and responsible AI policy.
Build the policy, risk, and approval rules that should sit behind AI-supported work.
Use practical field-data workflows before moving data into reports, analysis, or learning products.
