With the gradual change in the awareness of management staff in companies and institutions, there is an increasing demand for reliable education in this field. Management teams, information security administrators (ABI), as well as employees themselves expect specific information on how to process personal data safely and in compliance with the law.
The response to these needs is high-quality training that coherently and logically connects theory with practice. According to various studies, including statistics conducted by our company, over 80 percent of corporate data breaches result from human error, often due to a lack of knowledge. Training appears to be the most effective solution.
Receive a package of free GDPR guides and micro-trainings
To comprehensively raise awareness of the necessity of protecting processed data within the enterprise, it is essential to train all those who process personal data.
It is important for owners and managers of companies or institutions to be aware of what their role as data controllers (ADO) entails – what obligations they have in this regard. This is very significant, as it is the ADO who makes strategic decisions regarding the method of data protection, including, for example, the decision to appoint or not an information security administrator (ABI).
Information security administrators, on the other hand, according to the January amendment to the Personal Data Protection Act, must possess the appropriate knowledge and skills to perform this function. Although the law does not impose specific requirements on candidates for the position of DPO, such provisions have already been included in the draft Regulation of the European Parliament and Council, which is to be adopted by the end of 2015. According to the draft, the DPO should have extensive knowledge of personal data protection regulations and the industry in which they will perform their duties, be familiar with the technical requirements regarding data protection, be able to conduct inspections and consultations, maintain documentation, etc. However, regardless of formal requirements, it seems that DPOs themselves should strive to enhance their qualifications, as they bear the responsibility for the data processed within enterprises.
It is extremely important to train all employees who, in any way, come into contact with data processing. It is essential that employees know how to process data in compliance with the law, what threats are associated with it, what can and absolutely must be avoided when working with data, and how and to whom to report a personal data breach or a violation of applicable procedures.

