Skip to content
Artwork for Certified: The IAPP CIPM Audio Course
TechnologyEducationCourses

Certified: The IAPP CIPM Audio Course

Jason Edwards

Certified: The IAPP CIPM Audio Course is an audio-first study and skill-building program for privacy professionals, security and compliance practitioners, product leaders, and busy managers who need a practical path into privacy program management. It’s designed for people who want to understand how a privacy program actually runs, not just memorize terms. If you’re stepping into a privacy role, supporting a privacy office, or translating privacy requirements into real-world operations, this course is built for you. You’ll get a clear, structured approach that assumes you have a full schedule and limited study time, while still respecting the depth of the CIPM body of knowledge.

Inside Certified: The IAPP CIPM Audio Course, you’ll learn how to design, operate, and improve a privacy program across the full lifecycle—governance, policies, training, incident response coordination, vendor oversight, metrics, and continuous improvement. The teaching style is straightforward and audio-friendly: short, focused lessons with plain-English explanations, concrete examples, and consistent reinforcement of the concepts that show up in real programs. Audio-first means you can learn during commutes, workouts, travel, or between meetings, without needing slides or worksheets. Each lesson is built to make the ideas stick, so you can apply them immediately at work and recognize them on exam day.

What sets Certified: The IAPP CIPM Audio Course apart is the emphasis on operational clarity. Instead of treating privacy as a pile of rules, we treat it like a management system with roles, decisions, and measurable outcomes. You’ll learn the “why” behind common program choices, the tradeoffs leaders face, and how to communicate privacy requirements in a way stakeholders can act on. Success here looks like two things: you can explain how a privacy program functions end to end, and you can make confident calls about what to do next when you’re handed a new requirement, a new vendor, or a new risk. That’s the difference between passing a test and running the work.

Play
  • 20 episodes
  • Avg 16 min
  • English
  • #74
    February 22 · 17 min

    Episode 74 — Reduce breach likelihood and impact by updating plans, controls, and training

    This episode ties incident outcomes back into program improvement by showing how to reduce breach likelihood and impact through updates to plans, controls, and training, because CIPM expects you to treat incidents as learning events that harden the organization over time. You will learn how to run structured lessons learned, identify root causes and contributing factors, and choose corrective actions that address both technical weaknesses and process failures, such as unclear escalation paths, incomplete data inventories, or inconsistent vendor oversight. We discuss how to update incident response plans and playbooks so they reflect what actually happened, how to improve controls like access governance, logging, retention enforcement, and secure deletion, and how to refresh training so the right teams change behavior where mistakes occurred. Practical examples include preventing repeat misdirected disclosures, closing gaps in DSAR tooling that created exposure, and tightening third-party controls after a vendor-driven incident. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #73
    February 22 · 17 min

    Episode 73 — Maintain an incident register that supports accountability and continuous improvement

    This episode explains how to maintain an incident register that supports accountability and continuous improvement, because CIPM questions often test whether you can track incidents as program inputs that drive measurable changes, not isolated events that disappear after the immediate crisis. You will learn what an effective incident register captures, including incident categorization, data types involved, affected populations, root cause, control failures, response timeline milestones, notification decisions, remediation tasks, and verification evidence. We cover how to use the register to identify trends such as repeated misconfigurations, recurring vendor issues, training gaps, or persistent access-control weaknesses, and how to translate those trends into prioritized improvement work with owners and deadlines. Practical examples show how incomplete registers create confusion during audits and lead to repeated mistakes, while well-run registers make leadership reporting cleaner and risk management more credible. Troubleshooting guidance includes keeping entries consistent, protecting sensitive details while still preserving useful evidence, and ensuring incidents are closed only when remediation is validated. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #72
    February 22 · 17 min

    Episode 72 — Communicate incident details to stakeholders under legal and business requirements

    This episode focuses on communicating incident details to stakeholders under both legal and business requirements, because the CIPM exam expects you to deliver accurate, timely, role-appropriate information while avoiding speculation and inconsistent messaging. You will learn how to identify key stakeholder groups—executive leadership, Legal, Security, IT operations, communications, customer support, regulators, and affected individuals—and how each group needs different levels of detail to make decisions and fulfill obligations. We discuss how to structure communications around confirmed facts, what is still unknown, the immediate actions taken, and the next decision points, including notification analysis, vendor coordination, and customer impact handling. Practical guidance covers maintaining a single source of truth, managing updates as facts evolve, and keeping communications aligned across internal teams so customer-facing statements match legal assessments and technical realities. Troubleshooting includes managing pressure to “say something now,” handling cross-border notification complexity, and documenting approvals and sign-offs to keep the response defensible. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #71
    February 22 · 19 min

    Episode 71 — Run incident handling steps: assessment, containment, remediation, and documentation

    This episode walks through the core incident handling steps from a privacy program perspective—assessment, containment, remediation, and documentation—because CIPM exam scenarios often test whether you can coordinate a disciplined response that protects individuals and produces defensible evidence. You will learn how to rapidly assess what happened, what data was involved, who may be affected, and which systems and vendors are in scope, then connect those facts to containment actions that limit further exposure without destroying evidence. We cover how remediation differs from containment, including fixing root causes, validating that controls now operate as intended, and tracking follow-up work so the incident truly closes. Practical examples include misdirected disclosures, compromised credentials, and vendor-caused exposures, with best practices for preserving logs, maintaining a clear timeline, and documenting decision points around notifications and risk acceptance. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #70
    February 22 · 15 min

    Episode 70 — Handle consent and preference changes: withdrawal, objection, and restriction operations

    This episode explains how to handle consent and preference changes operationally, including withdrawal, objection, and restriction, because CIPM exam questions often test whether you can turn user choices into enforceable system behavior across integrated tools and vendors. You will learn how consent differs from general preferences, how withdrawal and objection should be captured and honored consistently, and why restriction workflows require careful handling to pause certain processing while still allowing necessary operations like security logging or legal compliance. We discuss the technical and process implications of propagating preference updates across marketing systems, analytics pipelines, identity services, and third-party vendors, including the risks of latency, partial updates, and inconsistent identifiers. Practical examples include email marketing opt-outs that must apply across brands, in-app tracking toggles, and objections to profiling that require segmentation changes in data pipelines. Troubleshooting guidance focuses on verifying that choices are honored in practice, maintaining evidence, and preventing product changes from reintroducing processing after a user has opted out. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #69
    February 22 · 16 min

    Episode 69 — Build DSAR workflows that meet identity verification, deadlines, and recordkeeping

    This episode teaches how to build DSAR workflows that meet identity verification requirements, statutory deadlines, and recordkeeping expectations, because CIPM questions often focus on the operational details that determine whether responses are defensible. You will learn how to design identity verification that is proportionate to the sensitivity of the data and the risk of impersonation, and how to document verification outcomes without collecting unnecessary new personal data. We cover how to manage deadlines with queueing, escalation, and pause rules when clarification or verification is pending, and how to coordinate with system owners and vendors so data retrieval and deletion actions occur on time. Practical examples include high-volume consumer requests, employee requests that touch HR and security logs, and requests where exemptions require careful redaction and explanation. Troubleshooting guidance focuses on audit-ready recordkeeping, preventing “lost” requests in email, and avoiding inconsistent decision-making by using standardized criteria, templates, and review steps that reduce variability across cases. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #68
    February 22 · 17 min

    Episode 68 — Respond to rights requests with clear notices, processes, and accountable outcomes

    This episode explains how to respond to rights requests with clear notices, reliable processes, and accountable outcomes, because CIPM exam scenarios often test whether you can handle requests consistently while managing fraud risk and operational constraints. You will learn how the quality of your notices and intake communications affects the downstream workload, including setting expectations on identity verification, scope clarification, timelines, and delivery methods. We discuss how to operationalize request handling so it is repeatable across business units, including triage, assignment, evidence gathering, exemptions handling, and secure fulfillment, with clear ownership for each step. Practical examples include requests that span multiple products, requests submitted by authorized agents, and requests that involve conflicting obligations such as retention requirements or legal holds. Troubleshooting guidance focuses on common breakdowns like inconsistent responses across teams, lack of data location knowledge, and requests that exceed capacity, along with strategies like standard templates, workflow tools, and measurable service targets that drive continuous improvement. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #67
    February 22 · 16 min

    Episode 67 — Sustain program performance by managing change, exceptions, and technical drift

    This episode focuses on sustaining privacy program performance by managing change, exceptions, and technical drift, because CIPM expects you to keep controls effective as systems evolve and business pressure creates shortcuts. You will learn how to design change management that triggers privacy review when processing changes, how to maintain a controlled exception process with clear approvals and expiration dates, and how to detect drift when configurations, access rules, or data flows gradually diverge from documented standards. We cover practical examples such as new product features adding tracking events, vendors enabling new sub-processing functions, teams creating ad hoc exports for analytics, and retention jobs failing silently after system upgrades. Best practices include integrating privacy gates into existing delivery workflows, maintaining an exception register, and using monitoring to validate that controls still operate as designed. Troubleshooting guidance addresses resistance from teams that view governance as friction, and how to present change management as a way to prevent rework, incident response chaos, and audit failures. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #66
    February 22 · 15 min

    Episode 66 — Use transfer impact assessments to manage cross-border transfer risk and evidence

    This episode explains how to use transfer impact assessments to manage cross-border transfer risk and build defensible evidence, because CIPM exam questions often test whether you can evaluate transfers beyond simple “data is encrypted” claims. You will learn how to identify when a transfer impact assessment is needed, how to scope the transfer pathway across entities and vendors, and how to document the nature of the data, the purposes of processing, the transfer mechanisms, and the safeguards that reduce exposure. We discuss practical evidence gathering, including vendor transparency, data location and access patterns, sub-processor relationships, and technical measures like encryption and access logging, along with organizational measures like incident notification requirements and challenge processes for government access requests. Real-world scenarios include global cloud services, outsourced support with remote access, and analytics platforms with multi-region replication. Troubleshooting guidance focuses on incomplete vendor answers, dynamic architectures that make data location ambiguous, and how to keep transfer assessments current when providers change regions, features, or sub-processors. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #65
    February 22 · 18 min

    Episode 65 — Execute DPIAs end-to-end: triggers, scope, risk scoring, and remediation tracking

    This episode teaches how to execute a DPIA end-to-end, because CIPM expects you to understand DPIAs as a structured process that produces defensible decisions and tracked remediation, not just a document. You will learn how to identify DPIA triggers based on processing characteristics, scale, sensitivity, monitoring, profiling, and novelty, then define scope so the assessment covers real data flows, stakeholders, and systems rather than a narrow description of intent. We cover practical risk scoring approaches that account for likelihood and impact to individuals, how to evaluate necessity and proportionality, and how to document mitigations as specific controls with owners and timelines. Real-world examples include launching new behavioral analytics, deploying biometrics, integrating third-party identity services, and rolling out AI-driven decisioning, where risks can be misunderstood or minimized under business pressure. Troubleshooting guidance focuses on incomplete inputs, teams resisting transparency, and DPIAs that stall because remediation is not assigned, funded, or verified to closure. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #64
    February 22 · 16 min

    Episode 64 — Apply privacy assessment types: PIA, DPIA, TIA, LIA, and PTA fundamentals

    This episode covers the fundamentals of common privacy assessment types—PIA, DPIA, TIA, LIA, and PTA—because CIPM exam scenarios often ask you to choose the right assessment approach for the situation and explain what it should accomplish. You will learn the purpose of each assessment, the typical triggers that require it, and the core outputs that make it useful, such as documenting processing context, evaluating necessity and proportionality, identifying risks to individuals, and defining controls and remediation plans. We discuss how assessment types differ in focus, including when transfer risk and jurisdictional factors matter most, when legitimate interest analysis is relevant, and how privacy threshold assessments can serve as lightweight triage to decide whether deeper work is needed. Practical examples include new tracking features, third-party tool onboarding, employee monitoring initiatives, and cross-border processing expansions. Troubleshooting guidance focuses on avoiding checkbox assessments, ensuring stakeholder input is captured, and creating assessment records that stand up during audits, incidents, and regulator inquiries. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #63
    February 22 · 15 min

    Episode 63 — Run continuous risk assessments across systems, processes, and business activities

    This episode explains how to run continuous privacy risk assessments across systems, processes, and business activities, because CIPM questions often test whether you can treat risk as an ongoing management discipline rather than a one-time project. You will learn how to identify assessment triggers such as new products, new data uses, new vendors, new jurisdictions, incidents, and control failures, and how to scope assessments so they focus on real processing and realistic threats. We cover practical risk inputs, including data inventory and flow maps, control test results, incident history, complaint trends, and vendor performance, then discuss how to translate findings into prioritized actions with owners, deadlines, and measurable outcomes. Real-world scenarios include analytics expansion, AI adoption, mergers, and re-architecting systems into cloud services, where risk can shift quickly and quietly. Troubleshooting guidance focuses on preventing assessment fatigue, avoiding “paper risk registers,” and building lightweight assessment routines that still produce defensible evidence and meaningful remediation. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #62
    February 22 · 18 min

    Episode 62 — Analyze program performance data to prove impact and guide investments

    This episode focuses on analyzing privacy program performance data to prove impact and guide investments, because the CIPM exam expects you to connect measurement to governance decisions, resourcing, and continuous improvement. You will learn how to interpret trends across rights requests, complaints, incidents, training effectiveness, vendor oversight, and control testing results, and how to separate signal from noise by validating data sources and definitions. We discuss how to tell a defensible performance story that leaders can use, including linking improvements to reduced risk, faster cycle times, fewer exceptions, and stronger audit outcomes, while avoiding misleading conclusions based on incomplete data. Practical examples include using backlog patterns to justify tooling, using repeat findings to justify control redesign, and using incident root causes to prioritize training and access changes. Troubleshooting guidance covers conflicting metrics across teams, “green dashboards” that hide risk, and how to propose investments with clear expected outcomes and verification plans. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #61
    February 22 · 20 min

    Episode 61 — Choose monitoring methods aligned to goals, controls, and contractor performance

    This episode explains how to choose monitoring methods that match your privacy program goals, the controls you rely on, and the realities of contractor and vendor performance, because CIPM exam questions often test whether you can validate operating effectiveness instead of assuming compliance. You will learn how to align monitoring to specific risks, such as delayed DSAR fulfillment, uncontrolled sharing, weak retention enforcement, or inconsistent training, and how to select methods like sampling, continuous control monitoring, attestations, KPI reviews, audit testing, and operational walkthroughs. We also cover how to monitor third parties and contractors in a way that is evidence-driven, including performance reporting, reassessment cadence, incident and change notifications, and spot checks tied to data access and processing scope. Practical troubleshooting includes what to do when metrics look “fine” but complaints rise, when contractors bypass procedures, and when monitoring produces noise without clear remediation ownership. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #60
    February 22 · 14 min

    Episode 60 — Enforce safeguards through policies, procedures, contracts, and accountability checks

    This episode explains how to enforce safeguards by tying policies, procedures, contracts, and accountability checks into a single operating system, because CIPM expects you to maintain controls over time rather than treating implementation as a one-time project. You will learn how each layer contributes to enforcement, with policies defining requirements, procedures making them executable, contracts extending expectations to third parties, and accountability checks validating that controls operate as intended. We discuss how to design enforcement so it is consistent and fair, including clear ownership, defined escalation paths, and measurable thresholds that trigger corrective action. Practical examples include enforcing retention through automated deletion plus verification, enforcing vendor controls through periodic reassessment and incident drills, and enforcing access controls through review cycles and exception management. Troubleshooting guidance focuses on weak enforcement signals, such as repeated exceptions, missing evidence, and “checkbox” audits, and how to convert those signals into targeted remediation that improves control performance without paralyzing the business. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #59
    February 22 · 13 min

    Episode 59 — Control secondary use by verifying guidelines are followed in daily operations

    This episode focuses on controlling secondary use by verifying that guidelines are followed in day-to-day operations, because CIPM questions often test whether you can prevent “purpose drift” after data has already been collected. You will learn how secondary use emerges through analytics expansion, marketing enrichment, internal research, model training, and cross-team access, and how to set practical governance gates that require review before new purposes are introduced. We cover verification methods such as monitoring access patterns, reviewing new data pipelines, auditing exports, and testing whether teams can demonstrate documented justification for new uses. Practical examples include product teams adding new tracking events, analysts merging datasets for new insights, and vendors proposing new features that require broader data sharing. Troubleshooting guidance addresses environments where guidelines exist but are not enforced, including how to align incentives, define consequences, and create evidence trails that make compliance measurable rather than assumed. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #58
    February 22 · 15 min

    Episode 58 — Enable privacy-enhancing technologies: minimization, obfuscation, and secure processing

    This episode explains how privacy-enhancing technologies support privacy outcomes through minimization, obfuscation, and secure processing, because the CIPM exam expects you to recognize technical options that reduce exposure while preserving business utility. You will learn what these techniques are intended to accomplish, how they reduce identifiability and breach impact, and where they commonly fit in analytics, testing environments, data sharing, and product telemetry. We discuss practical examples such as masking and tokenization for identifiers, aggregation and sampling for reporting, and secure handling approaches that limit raw data access while still enabling necessary processing. We also cover implementation considerations, including key management, access controls around de-obfuscation, and the danger of relying on techniques that can be reversed when combined with other datasets. Troubleshooting guidance focuses on preventing misuse, validating that protections work in practice, and avoiding overpromising what a technique achieves when communicating to stakeholders and in notices. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #57
    February 22 · 14 min

    Episode 57 — Embed privacy throughout the system development life cycle without slowing delivery

    This episode teaches how to embed privacy throughout the system development life cycle without slowing delivery, because CIPM questions often test whether you can design processes that are both compliant and workable for engineering teams. You will learn where privacy should show up in requirements, design reviews, development, testing, deployment, and post-release monitoring, and how to define lightweight artifacts that capture decisions without creating bottlenecks. We cover practical mechanisms such as privacy checklists tied to risk level, reusable patterns for data minimization and logging, and automated controls like configuration checks that catch issues early. Real-world scenarios include rapid feature iteration, third-party SDK additions, and architectural changes that affect data location and retention. Troubleshooting guidance focuses on reducing rework by catching issues at design time, preventing “last-minute privacy reviews,” and building shared vocabulary so privacy and engineering discuss the same risks in operational terms. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #56
    February 22 · 14 min

    Episode 56 — Integrate Privacy by Design principles into governance, product, and operations

    This episode covers how to integrate Privacy by Design principles into governance, product development, and daily operations, because the CIPM exam expects you to move privacy upstream so it becomes routine rather than reactive. You will learn how to express Privacy by Design as practical program behaviors, such as designing for minimization, setting default protections, documenting purposes and data flows early, and building review gates that prevent unapproved processing from shipping. We discuss how governance supports this work through clear decision authorities, standards, and training, and how operational teams use those standards in intake processes, vendor reviews, and change management. Practical examples include new feature launches that introduce tracking, experiments that collect additional fields, and integrations that create new sharing relationships. Troubleshooting guidance focuses on avoiding “privacy theater” checklists, aligning privacy review to existing delivery workflows, and ensuring design decisions are recorded and revisited as products evolve. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

    • Transcript
  • #55
    February 22 · 15 min

    Episode 55 — Apply technical, administrative, and organizational measures to mitigate privacy risk

    This episode explains how to apply technical, administrative, and organizational measures together to mitigate privacy risk, because CIPM exam scenarios often require a balanced control set rather than a single “silver bullet.” You will learn how technical measures like encryption, configuration baselines, and secure deletion work alongside administrative measures like policies, procedures, and training, and organizational measures like clear ownership, governance forums, and accountability reporting. We cover how to select measures based on the risk scenario, such as reducing unauthorized access, preventing inappropriate secondary use, improving rights fulfillment reliability, and limiting breach impact through minimization and segmentation. Practical examples show how controls interact, such as pairing retention rules with deletion automation and verification, or combining vendor contractual requirements with monitoring and reassessment. Troubleshooting guidance focuses on common gaps like strong policies with weak tooling, strong tooling with unclear ownership, and programs that measure activity but cannot demonstrate operating effectiveness. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path.

    • Transcript
Showing 1–20 of 20 episodes