KROG Legal Engineering Academy · BeLEx
Structured Consent
Modelling consent records, receipts, and notices to ISO/IEC TS 27560 and ISO/IEC 29184 — mapped to the GDPR.
Six courses. Turn consent into structure a machine can read, verify, and act on — and that you can defend afterwards.
- 6 courses · 7 lessons each
- Video on demand + oral examination
- EQF 5–6 · no coding required
Checkout on Gumroad · opens in a new tab.Purchase goes through Gumroad and gives access to the video lessons and exam booking. Questions go by email to hello@signatu.com.
Why consent has to be built right
Consent is the one legal basis the individual controls — and the one the organisation must be able to prove. If the proof fails, the processing that rests on it fails too.
The EU has chosen a format.
In May 2026 the European Commission called for tenders for a Data Altruism Consent Management System under the Data Governance Act — open-source software through which people give, withdraw and manage consent, interoperable with EU digital infrastructure. The tender specifications require consent receipts that follow ISO/IEC TS 27560:2023. When the Commission builds its reference implementation on a standard, that standard becomes the measure others are held to.
No proof, no consent.
GDPR Art. 7(1) puts the burden on the controller: where processing rests on consent, the controller must be able to demonstrate it — who consented, to what, when, on which notice, and whether it has since been withdrawn. A consent that cannot be demonstrated cannot be relied on. The processing then has no legal basis under Art. 6(1), and every activity resting on it is unlawful. Documentation is a condition of validity, not paperwork after the fact.
Consent is how data is exchanged for value.
Much data sharing rests on a simple bargain: the individual shares data and gets something back. Media subscribers consent to personalised recommendations and content; retailers build product recommendations and direct marketing on consented first-party data. That value lasts only as long as the consent holds — and can be shown to hold.
Consent has to travel between systems.
Today consent sits in silos. Public bodies and health services each run their own consent solutions, many designed years before ISO/IEC TS 27560 was published in 2023, each with its own data model. When one system cannot read another's consent status, someone checks it by hand — or the data sharing stops. A shared vocabulary and one JSON consent record that any system can parse, verify and act on removes the bottleneck.
Start here
Introduction: Consent, in two views
See consent from both sides of the table — the individual who gives it, and the organisation that must manage and document it. A short, plain-language foundation for the series.
The six courses
Courses 1–4 model consent and notice information to the standards and map it to the GDPR; 5 is the design craft on top; 6 is the capstone studio where you build it. Each course ends in its own exam.
01 · EQF 5 · CARPA II-a-3
Consent Records
ISO/IEC TS 27560:2023 · GDPR Art. 7(1)
You leave able to read any ISO/IEC TS 27560 record end to end and say whether it proves consent.
02 · EQF 5 · CARPA II-a-3
Consent Receipts
ISO/IEC TS 27560 §9
You leave able to issue a receipt that carries the record's fields at the same requirement levels.
03 · EQF 5 · CARPA II-a-13 – II-a-15
Consent Notices
ISO/IEC 29184:2020 §5
You leave able to test a consent notice against ISO/IEC 29184 §5 and spot a provision failure before a regulator does.
04 · EQF 5 · CARPA II-a-13 – II-a-15
Privacy Notices
ISO/IEC 29184:2020 §5
You leave able to audit an organisation-wide privacy notice per collection route and per processing activity.
05 · EQF 6 · CARPA II-a-13 – II-a-15
Privacy Notice Design
Design craft · builds on 03 & 04
You leave able to redesign a notice so comprehension can be evidenced under GDPR Art. 25(1).
06 · EQF 6 · CARPA II-a-3 · II-a-13 – II-a-15
Consent & Notice Studio
Capstone · builds on 01–05
You leave with a notice, record, receipt, privacy notice and §5.1 audit file you have defended orally.
What you'll be able to do
By the end you can take a legal requirement and produce a specification that a machine can execute and a regulator can check.
- Turn a duty into a data structure. GDPR Art. 7(1) becomes four sections, eight mandatory processing fields, and events that are appended and never overwritten.
- Read a standard the way an engineer reads a spec. Requirement levels, clause by clause, and what changes when a field is mandatory in both record and receipt.
- Map a clause to its legal basis — and defend the mapping. ISO/IEC 29184 §5.3 against Art. 13 and Art. 14, including recording “does not apply” with a justification.
- Design the interface, not just the document. Progressive disclosure, document to dashboard, and comprehension you can evidence under Art. 25(1).
- Build the audit file as you go, and stand behind it. One client brief, four processing activities, three builds — and an oral defence.
You leave with artefacts you can show, not a certificate of attendance.
Who it's for
For you
Lawyers and privacy professionals who want to work in structure rather than prose. The work that used to train a junior lawyer is now done by an LLM in seconds; what it cannot do is decide what the law requires and state it precisely enough for a system to execute and an auditor to check. That is legal engineering, and legal-AI companies are hiring for it. Also for engineers and designers building consent into products.
For your organisation
DPOs and compliance leads who need consent documentation that survives an audit and ports between systems. Train the people who build and defend it.
From learning to proof
01 · Learn
Courses 1–4 model consent and notice information to ISO/IEC TS 27560 and ISO/IEC 29184 and map it to the GDPR; course 5 is the design craft on top; course 6 is the capstone studio.
02 · Produce
The consent notice and the UI it appears in, the consent record and receipt, the privacy notice and the dashboard over it — plus the §5.1 audit file you assemble during the capstone.
03 · Assess
Each course ends in its own exam: you are handed real artefacts and asked to read them. The capstone is attested by oral examination on your portfolio — not by a score.
04 · Prove
Per course: that course's credential, e.g. Structured Consent — Consent Records (ISO/IEC TS 27560), at the EQF level the course states (5–6). All six: the capstone title BeLEx Certified Legal Engineer — Structured Consent. Each with a unique ID and a public verification page on KROG.
Access and assessment
Included in the purchase, according to the source:
- Portfolio assessment: a consent record, a consent receipt, a consent notice and a privacy notice, each assessed against the standard it is built to.
- A 60-minute oral examination over video. You defend your artefacts; the credential is attested on your portfolio, not on a score.
- On a pass: a verified credential on your KROG profile, a badge and a diploma, each with a unique ID and a public verification page.
Pass all six to earn the capstone title BeLEx Certified Legal Engineer — Structured Consent. The examination is booked on KROG after purchase.
Checkout takes place on Gumroad. Exam booking is handled separately after purchase. Ask us for the current terms before you enrol.
Who teaches it
Georg Philip Krog has spent more than a decade building legal ontologies, rule logic and consent infrastructure. His paper on implementing ISO/IEC TS 27560:2023 consent records and receipts for the GDPR and the Data Governance Act received the best paper award at the Annual Privacy Forum 2024.
Checkout on Gumroad · opens in a new tab.Purchase goes through Gumroad and gives access to the video lessons and exam booking. Questions go by email to hello@signatu.com.