Each of us has probably heard that humans are the weakest link in the data protection system. This may indeed be the case if employees process data subject to the risk of harm (e.g., loss of funds by the client) without awareness of the threats, knowledge of the safeguards, or even care for security.
Receive a package of free GDPR guides and micro-trainings
Individuals with the broadest access to data are generally the most critical link—not only from the perspective of the potential consequences of an incident but also in terms of the realization of the rights of the data subjects. However, a serious incident can be caused by virtually any employee—not only due to a lack of awareness but sometimes also due to a lack of a sense of responsibility, and even malice or foolishness.
The most common types of incidents can usually be avoided if employees do not make mistakes such as: sending messages to the wrong address, losing a laptop, leaving unsecured documents, working from home with family and friends present, etc. It may also happen that an employee, for low motives, deliberately discloses information about a colleague or client, unaware of the possible consequences for themselves and the organization.
The effects of employee unawareness can be partially mitigated through technical solutions, but this is usually not sufficient. For example, we can set up automatic screen locking after a few minutes of inactivity, but not immediately after the employee leaves the computer. We can facilitate the use of the email address book, but we cannot block the possibility of incorrectly entering the recipient's address. We can purchase shredders, but documents can still be discarded without their use.
How to Best Approach Employee Awareness?
Employee awareness is key: a lack of knowledge on how to behave in a given situation can not only exempt an employee from responsibility but, more importantly, represent one of the fundamental vulnerabilities. How can this be addressed?
First, it is necessary to define what is expected from the employee in a given position. This is not about a general level of familiarity with regulations, but primarily about understanding the role of the employee within the data protection system. Well-prepared procedures allow for easy determination of the responsibilities of individual persons.
Example: Every person authorized to process data should adhere to the principles of necessary knowledge for their duties, secure data upon leaving their position, avoid increasing risks to data (e.g., by writing passwords on sticky notes or leaving printouts in the printer), and also know how to act in case of detecting threats or responding to requests for the exercise of rights under the GDPR.
Second, it is necessary to formally present the employee with their obligations related to data protection. Ideally, this should involve providing access to policies and procedures that the employee is required to follow. The documents should describe the step-by-step procedures—merely repeating the content of regulations may not be sufficient. Requirements should be tailored to the competencies and qualifications of the employee.
Third, it is necessary to properly train the employee. Familiarity with procedures is a minimum requirement; however, let us not be under any illusions: many will only skim through these documents. Data protection is not dry knowledge—it is primarily about skills. For this reason, it is best to organize training tailored to the specific category of employees or provide electronic training where knowledge will be assessed through a final test.
Fourth, security is not achieved once. Due to changes in the organization, technology, law, and also the composition of the employee team, the effects of a single training session diminish over time. To build awareness, it is best to approach it as a continuous process: organize introductory training for new employees, conduct regular awareness campaigns (e.g., in the form of emails, leaflets, posters), and also review the functioning processes.
Fifthly, employees need tools to meet the requirements set for them. For example, the implementation of data deletion deadlines or requests for data deletion often requires the provision of appropriate functionalities in IT systems. This indicates the necessity of verification – preferably during an audit – of how the adopted solutions function in practice and what the sources of shortcomings are.
GDPR Guide for Employees
presents key concepts in a simple and accessible manner, the knowledge of which is essential for understanding the issues of personal data protection. Additionally, thanks to the possibility of filling in a special field designated for indicating the contact details of the person appointed in your organization to be contacted in the event of an incident, it serves as a convenient tool for providing employees with information in this regard as well.
We encourage you to download and distribute the guide within your organization. To expand knowledge in the field of personal data protection, we recommend providing it primarily to employees and collaborators who have or may have access to personal data. On the seventh page of the guide, there is a field that you can fill in with your contact details to provide further explanations to interested parties. Download
Accountability also means… reduced liability
If the organization itself meets the requirements of the GDPR by properly informing, training, and equipping the employee, then any potential liability for a breach will fall on the employee themselves – most often in the form of disciplinary sanctions. The basic test in this regard is whether:
- The organization has implemented appropriate solutions.
- The employee was formally obligated to implement them.
- The employee had an adequate level of awareness.
- The employee had the tools necessary to implement them.
The same applies among employees themselves – each is responsible for fulfilling their own duties, and it is sufficient if they can demonstrate that they acted in accordance with the instructions.
Example: The data controller formally adopted and published a clean desk policy, requiring employees to lock documents in cabinets whenever they leave their workstation. A sales representative forgot to do this and, while moving around the sales floor, left a binder with signed contracts on the desk. The data loss occurred due to the employee's negligence.
When was the last time
you conducted a risk analysis?
What can be done to encourage employees to collaborate, treating security as a shared value?
Ensuring security requires not only awareness but also employee engagement. If one of them sees unsecured data, open doors, or other threats – they should respond not only out of a sense of duty but primarily because the well-being of the organization and its clients is also the well-being of its employees. The loss of reputation or the necessity to pay high damages or financial penalties could, after all, affect the entire team of employees.
Tip: It is worthwhile to clearly present the above relationship – preferably in a form that will be memorable. For example – after working hours, marking clean desks with green sticky notes, while red ones indicate where documents remain. The first time, personal consequences may not be enforced; instead, a message can be sent to everyone that a recurrence of the situation could lead to completely unnecessary breaches and liabilities, the effects of which will be felt by all.
Instead of a summary – another tip
The employee is one of the key elements of the data protection system – it is similar to an organism, where the dysfunction of a single organ can have a catastrophic impact on the functioning of the entire organism. Therefore, raising employee awareness is essential to ensure that the money spent on preparing clauses, documentation, as well as technical and organizational safeguards, does not go to waste due to the lack of practical use of these tools by our employees, or perhaps even due to ordinary human negligence characteristic of the times before the implementation of the GDPR.


