In the era of advancing digitization, the development of artificial intelligence, and the growing importance of data, data controllers are facing increasingly serious threats. Staff training is an important organizational measure that mitigates risks in this area. It should be an integral part of the organizational culture, and raising employee awareness should be a priority for management.
GDPR Training for Employees is key to ensuring that the policies and procedures adopted within the organization function correctly, and that the technical and organizational measures implemented are effective. If the staff does not understand their obligations or their significance, it will not be possible to realistically implement the provisions arising from the policies and procedures or to apply the adopted safeguards. Only a well-trained employee can effectively prevent security incidents or quickly detect them.
Who Should Attend the Training?
The security of the organization and the information processed within it requires ensuring appropriate awareness among all individuals associated with it – regardless of the legal basis for cooperation. This applies not only to employees but also to contractors, volunteers, interns, trainees, and others performing tasks on behalf of the organization. For the purposes of this article, any references to employees also include the other groups of individuals.
All individuals with access to the organization's resources should be adequately trained. The more aware the employee is, the greater the chances of avoiding threats. Among the trainings that employees should certainly undergo are those related to GDPR, information security, and cybersecurity, and for entities subject to the NIS2 directive – also training concerning the areas indicated in this directive and in the amended Act on the National Cybersecurity System.
Who Must Undergo GDPR Training?
Training on the GDPR must be attended without exception by employees who process personal data in their work. Training should also be completed by individuals whose work is generally not related to the processing of personal data but who may have occasional contact with it, for example, through attendance lists, identification badges, time registration systems, as well as in the context of access to technical documentation or information about orders or clients. An example of such individuals includes production employees. They should also be aware of the requirements arising from the GDPR, how to handle materials containing personal data, and how to behave, for instance, in the event of finding documents left in a visible place by another person (i.e., in a situation of potential personal data breach).
All employees should also undergo information security training – appropriate to their tasks. This training should cover not only personal data but also all information processed within the organization, regardless of its form. This may include both information in paper form and in systems or communicated orally.
To be effective, training must be tailored to the specific nature of the work of individual groups of employees and to the risks characteristic of those groups. Therefore, the training for individuals whose daily work involves processing large amounts of personal data should look different than the training for production employees, whose contact with this data is significantly less and occurs under specific circumstances.
Are GDPR Trainings Necessary – and What Do They Provide for the Organization?
Training for Employees on the GDPR is essential for the safety of the entire organization and the individuals whose data is processed within it. Breaches in this area can result in serious consequences for both the organization (including financial and reputational) and for data subjects in the event of a personal data breach (e.g., disclosure of data to unauthorized entities or theft of information due to a hacking attack).
The data controller must process data in accordance with applicable regulations. The GDPR contains a number of principles and associated obligations that the controller is required to comply with. For the organization to meet these requirements, its staff must be aware of and understand them. Training on personal data protection allows employees to familiarize themselves with the requirements, raises awareness of the importance of data security issues, and demonstrates how their engagement in these processes translates into the safety not only of the organization itself but also of the individuals whose data the organization processes.
Proper management and documentation of training processes and other activities aimed at raising employee awareness constitute an element of the accountability principle required by the GDPR (and in relation to cybersecurity training – also by the NIS2 directive and the amended Act on the National Cybersecurity System). Accurate documentation allows the organization to demonstrate to the authority that it is fulfilling its imposed obligations. Both the failure to fulfill the training obligation and the lack of documentation may result in the imposition of financial penalties on the organization.
What is the source of the training obligation and does it apply to the employer?
The implementation of training constitutes the fulfillment of obligations arising directly or indirectly from legal provisions (e.g., GDPR or the NIS2 directive). In some cases, this obligation also arises from standards adopted by the organization (e.g., ISO standards), which require ensuring that employees possess appropriate competencies and raising their awareness.
Clear rules regarding the processing of personal data are established in Article 5 of the GDPR. To be able to implement them, individuals processing personal data must have knowledge about it. The organization’s obligation in this regard arises from Articles 24 and 32 of the GDPR. These provisions concern the implementation of adequate technical and organizational measures to ensure the security of the processed data. Training should be regarded as such a measure. This is indicated by the President of the Polish Data Protection Authority in his decisions.
The training obligation also arises in the context of data protection by design (Article 25 of the GDPR). The European Data Protection Board, in its guidelines No. 4/2019 regarding Article 25 “Data protection by design and by default,” lists training among organizational measures.
The issue of raising awareness and training personnel involved in processing operations also appears in the GDPR as a task of the Data Protection Officer. It is part of their duties to monitor this area (Article 39(1)(b) of the GDPR).
Furthermore, the GDPR specifies requirements regarding binding corporate rules, which are a set of principles and procedures that may be adopted by a group of enterprises operating in different countries to legally transfer personal data outside the EEA within that group. Among these requirements is the obligation to provide appropriate data protection training to personnel who have permanent or regular access to data and to monitor compliance with this obligation (Article 47(2)(h) and (n) of the GDPR).
For entities subject to the NIS2 Directive and the amended Act on the National Cybersecurity System (once it comes into force), the obligation for training also arises from these legal acts. The management of essential and important entities must undergo at least annual cybersecurity training and fulfill obligations arising from the amended Act on the National Cybersecurity System. Such training should cover, among other things, risk management, incident reporting, and legal and financial liability. The regulations also impose a requirement to raise staff awareness regarding cyber threats, the obligation to apply cybersecurity hygiene principles, and to respond to and report incidents (Article 20(2) and Article 21(2)(g) of the NIS2 Directive and Article 8d(3) and Article 8e of the amended Act on the National Cybersecurity System).
How to Train?
The GDPR does not contain guidelines on how the training process for personal data processors should be structured. However, it indicates the outcome that the data controller should achieve by implementing appropriate technical and organizational measures (organizational measures include, among others, training and other activities aimed at raising staff awareness). This outcome is to ensure a level of security that corresponds to the risk posed (Articles 24 and 32 of the GDPR). Therefore, training planning should take into account existing risks.
The data controller has significant discretion in shaping the training process. However, they should consider the positions of the President of the Polish Data Protection Authority, who refers to this topic in many of their decisions. The manner of conducting training is one of the standard obligations verified in proceedings conducted by the Polish DPA.
Positions of the Polish DPA Regarding Training
In decision DKN.5131.44.2022, the Polish DPA indicates:
“Properly conducted training allows trainees to correctly understand the principles of personal data processing defined by the Data Controller, and consequently contributes to reducing the risk of breaches in this area. It should also be noted that conducting training on personal data protection, in order to be considered an adequate security measure, must be carried out periodically, which will ensure constant reminders and, consequently, the reinforcement of the principles of personal data processing covered by the training. Furthermore, all individuals authorized to process personal data must participate in such training, and the training program must encompass all issues related to personal data processing within the established training topic. The omission of any of these elements will result in the training failing to fulfill its role, as some individuals will not be trained at all, or the training participants will not receive complete knowledge in the given area. (…) Moreover, the lack of training conducted in the manner described above means that this security measure does not effectively reduce the risk of personal data breaches, which undoubtedly contributes to weakening the level of personal data protection and necessitates the recognition of a violation of the provisions of Regulation 2016/679 concerning the obligations of the Data Controller regarding data security. (…) Regular training conducted by the Data Controller on the discussed topic enables them to assess the knowledge level of employees in this regard. (…) The Data Controller did not possess knowledge of whether employees were properly trained in the discussed area and whether they had the knowledge necessary to process data in a manner that ensures its appropriate security.”
The conclusions drawn from the cited excerpts are as follows:
- training for employees on GDPR must be conducted periodically,
- all individuals authorized to process personal data in the organization must participate in the training,
- the training program must cover all issues related to personal data processing within the established training topic (comprehensiveness of the training),
- the knowledge of employees acquired during the training should be assessed (e.g., through a test),
- the Data Controller should verify that all employees have completed the training.
With regard to the frequency of training, the timelines indicated by the British data protection authority (ICO) can be treated as a certain guideline, which considers annual training to be the ideal solution. However, it also stipulates that training should not be conducted less frequently than every two years. Conversely, the Polish supervisory authority does not specify what exactly it understands by frequency, but in one of its decisions (mentioned later in the article), it deemed a 17-month gap in training to be too long. It is generally accepted that training should be repeated no less frequently than every 12 months.
Ultimately, it is the responsibility of the data controller to demonstrate the appropriateness of the time intervals between individual training cycles. The purpose of training is to reinforce and deepen knowledge. Multi-year gaps between training do not meet the requirement of frequency, which is meant to guarantee the currency of employees' knowledge.
In order for the security measure in the form of training to be considered appropriate, the employer should identify what type of training is needed and who should be trained and at what level. Depending on the scope of data that individual employees have access to, the scope of training they should undergo may vary. In today's world, it is difficult to find a situation where an employee does not come into contact with any data in their work. Therefore, it is worth reiterating that it is recommended to train the entire organization, with differences arising from the scope of training for individual groups of employees.
Training must have an appropriate subject matter. It should cover all issues related to data protection addressed within the established topic. The subject matter of the training should be selected with consideration of the risks faced by the organization and individual employee groups (comprehensiveness of training).
The data controller should be able to demonstrate that a given person has undergone training (accountability of training). A mere statement in this regard is not sufficient. Evidence may include, for example, signed attendance lists, certificates of completion, or reports from e-learning platforms.
The data controller must maintain control over the training of employees and their level of knowledge. This means that they should ensure that all individuals processing data have undergone training, and additionally verify their knowledge, for example, through a knowledge test completed after the training.
From other decisions of the Polish DPA, further conclusions regarding employee training issues can be drawn.
Decision ZSOŚS.421.25.2019
- Monitoring by the data controller and the Data Protection Officer (DPO) of compliance with regulations, including actions aimed at raising awareness regarding personal data protection and training employees involved in data processing operations, should take into account the risks to the rights and freedoms of natural persons.
- Educational activities should be verified by the data controller and the Data Protection Officer (DPO).
- Educational activities should be tailored to the specific nature of the work of the staff.
- The data controller, as the employer, has legal instruments based on applicable regulations that allow for the mobilization of employees to participate in training, especially since it is related to their job responsibilities.
- The data controller is fully responsible for implementing the principles and processes resulting from personal data protection regulations, including overseeing them, even when a Data Protection Officer (DPO) has been appointed.
- The data controller should be able to demonstrate monitoring of the training process, including having confirmation of the completion of training sessions.
- In the event of an employee's absence from training (e.g., due to long-term leave), the data controller should take effective measures to retrain them in the planned scope, e.g., by providing an appropriate form of education.
- The data controller does not fulfill the training obligation properly if they do not adapt the form of training to the specific nature of the employees' work. Both the lack of such adaptation and the failure to ensure sufficient accountability regarding training conducted for employees negatively impact the data security and protection system within the organization.
- Building data security awareness within the organization and focusing employees' attention on related issues reduces the risk associated with personal data processing. It is in the interest of the data controller to adequately train individuals authorized to process personal data, particularly those data whose processing is associated with higher risks due to their scale, scope, and context.
Decision DKN.5131.17.2022
- Training is significant in the case of changes in procedures introduced by the organization, especially after a personal data breach has been identified.
- After a breach, the data controller should make changes to the procedure, involving the introduction of security principles adequate to the identified risk (in the discussed case: principles applicable in the event of the need to transport medical documentation outside the premises of the medical facility, including during home visits), and then conduct training for employees covering the update of this procedure.
- Without conducting training, the mere updating of documentation would not achieve the desired effect, as the human factor is crucial – in practice, it is the employee who must apply the adopted procedures.
- The actions taken by the data controller to implement appropriate remedial measures, establish suitable security measures, and train employees may be considered by the Polish DPA as a mitigating circumstance that influences the reduction of the imposed fine (as reflected in this case).
Decision DKN.5110.14.2022
- A thematic compilation of issues related to training cannot be considered a training plan.
- The training plan should be prepared well in advance and include a schedule of specific actions and the manner of their execution, aimed at achieving a specific result.
- Planning should pertain to a defined period during which specific actions are to be carried out. Therefore, the preparation of the plan involves the prior determination of the scope of actions, describing (detailing) the planned activities, and defining the deadlines for their implementation and methods of execution.
- When planning training, the data controller should:
- prepare the training plan well in advance,
- establish the training schedule,
- define the manner of conducting the training,
- indicate the implementation deadlines.
Decision DKN.5131.1.2021:
- The weakest link affecting the occurrence of personal data breaches remains the human factor. The data controller cannot claim that human error could not have been avoided if appropriate training was not provided.
- A one-time, general training on personal data protection regulations is insufficient to consider that the data controller has implemented effective measures to mitigate risks, e.g., of a ransomware attack. In the case discussed, prior to the occurrence of the breach, the data controller provided employees with only one training session on the principles of applying the GDPR, which did not cover issues related to safe navigation on the Internet. Furthermore, it took place 17 months before the occurrence of the malware attack.
- The mere introduction of an organizational measure (e.g., a ban on independently configuring hardware or software settings) does not equate to providing employees with knowledge on how to effectively protect themselves against cyber threats.
- To mitigate the risk associated with a ransomware attack, the data controller should ensure that the training:
- provides participants with knowledge about the types of cyber threats and appropriate prevention techniques (at least at a basic level),
- were directed to all individuals involved in the personal data processing processes,
- were cyclical in nature, and subsequent sessions served to reinforce the acquired skills.
- The data controller should also provide training on cyber security awareness. Such training may constitute an organizational security measure appropriate to the risks associated with personal data processing, for which the data controller bears sole responsibility for implementation.
- The data controller should ensure appropriate accountability for the training, including the ability to demonstrate that it has actually been conducted and covered the relevant individuals. The lack of such accountability indicates the failure to implement adequate organizational measures.
In summary: a one-time, generic training does not fulfill its function. Employee training must be cyclical, repeated at appropriate – not overly long – intervals to reinforce skills and update employees' knowledge. Furthermore, it must take into account existing risks and cover issues relevant to those threats.
Decision DKN.5131.34.2022:
- Properly conducted training must lead to a correct understanding of the principles of personal data processing defined by the data controller, which ultimately reduces the risk of violations in this area.
- Training should be conducted cyclically in order to be considered an adequate security measure. Cyclicality allows for the reinforcement of knowledge and constant reminders of the principles of personal data processing.
- All individuals authorized to process personal data must participate in the training.
- The training program must cover all issues related to personal data processing within the established topic. Properly conducted training that addresses data protection issues should indicate, among other things, social engineering threats, such as emails infected with viruses.
- Omission of any of these elements (cyclicality, full scope, participation of all authorized individuals, appropriate topics) results in the training not fulfilling its function. The consequence may be a violation of personal data protection and GDPR provisions.
- If training is not conducted in the described manner, it does not effectively reduce the risk of violations and weakens the level of personal data protection. In such a situation, a violation of GDPR provisions regarding the data controller's obligations concerning data security may be established.
- Training does not replace technical solutions. The data controller must combine organizational and technical measures to ensure an appropriate level of security.
Decision DKN.5131.44.2022:
- The data controller must be able to demonstrate that specific individuals participated in the training. If they cannot prove that the person responsible for the data breach was properly trained, they do not fulfill the accountability principle.
- The issue of personal data protection is subject to continuous changes. New types of threats and changes in regulations governing matters related to broadly understood security in the data processing process are emerging. Regular training allows the data controller to monitor the knowledge level of employees in this area.
- The data controller must not only ensure that employees have up-to-date knowledge about personal data protection but also be able to demonstrate that they are properly trained in this regard and can process data in a manner that ensures its appropriate security.
Decision DKN.5131.2.2022:
- The data controller should not only train employees but also assess the effectiveness of that training. The lack of mechanisms for testing, measuring, and evaluating knowledge after training means there is no certainty whether employees understood the content of the material provided and whether they are aware of the risks and threats (e.g., regarding the use of portable storage devices).
- The absence of periodic training on the adopted principles of personal data processing leads to violations of personal data protection, as well as breaches of the obligations of the data controller arising from Article 24(1), Article 25(1), Article 32(1), and Article 32(2) of the GDPR, as well as the confidentiality principle from Article 5(1)(f) of the GDPR and the accountability principle from Article 5(2) of the GDPR.
- Case law indicates that the accountability principle is based on the legal responsibility of the data controller for properly fulfilling their obligations and imposes on them the duty to demonstrate, both before the supervisory authority and the data subject, evidence of compliance with all data processing principles (judgment of the Administrative Court in Warsaw of February 10, 2021, case no. II SA/Wa 2378/20). The data controller has significant discretion regarding the security measures applied; however, they are still liable for violations of personal data protection regulations. It follows directly from the accountability principle that it is the data controller who should demonstrate, and thus prove, that they comply with the provisions specified in Article 5(1) of the GDPR (judgment of the Administrative Court in Warsaw of August 26, 2020, case no. II SA/Wa 2826/19).
In summary: employees' knowledge should be regularly assessed, and training must be periodic. The data controller must have evidence confirming that they are properly fulfilling their obligations.
What training is required under the GDPR?
As part of the obligations arising from the GDPR, the following are required:
- initial training – after hiring an employee, before they begin processing personal data,
- refresher training – periodic, reinforcing, and expanding employees' knowledge.
Additionally, ad-hoc training may be necessary, for example, in the event of insufficient employee knowledge, after a personal data breach, after changes in applicable procedures or processes, or after the introduction of new security measures.
Data protection training should cover issues such as:
- basic concepts,
- principles of data processing and legal bases,
- identification and reporting of breaches,
- rights of data subjects and handling requests under the GDPR,
- maintaining records,
- data processing security (including remote work, use of AI tools),
- risk analysis, DPIA, audits,
- data sharing and principles of data processing delegation,
- transfers outside the EEA,
- inspections and cooperation with the supervisory authority.
What form should GDPR training take?
Training can be conducted in various ways, and the choice of a specific form is up to the data controller. The organization should analyze which method will be most effective in its case, taking into account its structure, the way employees perform their work, organizational, technical, and financial capabilities, as well as the target training group.
Among the various forms of training, the following can be mentioned:
- in-person or online training – allowing for direct contact with the trainer, discussion, and working on examples from the organization's experience,
- GDPR e-learning – enabling self-paced learning at a convenient time,
- webinars – shorter training sessions dedicated to selected topics,
- other interactive forms – e.g., simulation games, online quizzes, case study-based workshops,
- blended forms – combining different methods.
How to choose the training format for the audience?
For employees who process large amounts of personal data on a daily basis (e.g., managers, executives, HR staff, IT, or marketing employees), in-person or online training sessions are the most effective. They allow for interaction with the instructor, deepening of the topics discussed, and discussion of practical cases that employees encounter in their work.
On the other hand, e-learning courses may be a good solution for individuals who participate to a lesser extent in data processing activities, or they can serve as a form of knowledge refreshment.
Thematic webinars and other interactive forms of training are also an excellent way to deepen knowledge acquired in other training sessions. In the case of e-learning or webinars, it is advisable to provide the opportunity to ask questions and raise concerns, for example, via email, through the training platform, or to a contact person.
Individuals conducting training or answering questions must possess the appropriate knowledge; therefore, they should participate in more advanced training sessions. If there are no such individuals within the organization, there is a risk of improperly training the remaining staff, which consequently increases the risk of errors and incidents. For this reason, it is advisable to involve experts in the training process. In organizations where a Data Protection Officer (DPO) operates, they usually are responsible for conducting the training.
It is important that the training takes an active form. Simply providing employees with documentation for independent review does not fulfill this requirement. This may serve as an addition to the training but should not replace it.
How to personalize training content?
Training should be tailored to the specifics of individual departments (e.g., HR, IT, marketing), taking into account the risks and obligations characteristic of each. A very good practice is to discuss examples from one's own organization, such as actual security incidents. Incorporating personalized content into the training program makes it a more effective organizational measure for securing data, as participants better understand the information conveyed and can apply it in practice.
Some positions or roles within the organization require in-depth knowledge. This particularly applies to individuals conducting training, processing special categories of data or data concerning children, as well as those dealing with incident management or handling GDPR requests. For these groups, it is worthwhile to provide more advanced training that allows for a deeper understanding of the topics they deal with on a daily basis.
In any case, high-quality training materials should also be provided, and regular updates should be ensured.
Who can train employees?
The data controller is responsible for the proper training of personnel. Therefore, the employer will be the entity accountable – also before the supervisory authority.
Training can be conducted by a designated person from the organization or by an external entity. It can also be led by the Data Protection Officer (DPO). It is essential that the trainer possesses adequate knowledge of the subject matter covered in the training and is well acquainted with the data processing processes occurring within the organization. Employees should have the opportunity to ask the trainer questions and express their doubts.
If the data controller opts for external training, they should ensure that it addresses the needs of the organization, such as the profile of its activities and the data processing processes that occur within it. Situations where employees undergo exactly the same training every year should be avoided. Instead, it is advisable to focus on developing and regularly refreshing the content.
How to provide employees with space for training?
The organization should provide employees with a real opportunity to participate in training. In practice, it happens that individuals burdened with responsibilities treat training as less important and focus on current tasks. This does not benefit either the employee or the organization. Therefore, it should be clearly communicated that training is not optional but a duty that requires time and attention.
Training should be an element of the organizational culture, embedded in the organization's standards, supporting data security and minimizing the risk of errors.
How to assess knowledge and document training?
The employer should be aware of the level of training of their staff. After the training, it is important to check whether the employee has indeed absorbed the knowledge, for example, through a test or survey – in electronic or paper form. This allows for the evaluation of the training's effectiveness and the identification of areas that may require additional support.
The fact of participation in the training, its scope, and the test result should be documented in such a way that the employer can demonstrate (e.g., in the event of an inspection by the Polish Data Protection Authority after a confirmed breach) that a specific employee was trained, when it occurred, to what extent, and with what outcome.
Documentation of training can include, for example, signed attendance lists, certificates or attestations of completion generated after achieving a positive test result, as well as reports from the e-learning platform containing information about participants, test results, dates of completed training, and planned dates for subsequent editions. To demonstrate the thematic scope of the training, it is advisable to keep its program, presentation, or a copy of the training materials provided to participants.
Example
The employer has created a list of employees required to undergo refresher training on personal data protection, specified the format (e-learning), and set the date for its implementation. The list is stored in the HR department. Is this sufficient from the perspective of the accountability principle?
Answer
No. The employer should have confirmation that each employee has indeed completed the training, for example, in the form of signatures on an attendance list or certificates generated from the e-learning platform. The mere list of individuals required to participate in the training is not sufficient. The employer should monitor whether all employees have fulfilled their training obligation and take action against those who have not yet completed it. Additionally, the employer should have a training program to demonstrate what topics were covered.
How often should employees be trained on GDPR?
The GDPR does not specify how often employees should undergo training. The first training on personal data protection must take place before allowing the employee to process data. In practice, it is advisable to refresh training at least once a year, and more frequently if necessary.
Situations that may necessitate retraining include:
- security incidents, data breaches,
- the emergence of new threats (e.g., due to changes in work methods, such as transitioning from on-site to remote work),
- the introduction of new solutions, tools, technologies (e.g., implementing AI systems),
- significant changes in business processes involving the processing of personal data (e.g., initiating marketing activities),
- changes in legal regulations imposing new obligations (e.g., the enactment of whistleblower legislation or the so-called Kamilka Act).
The frequency of cybersecurity training for management, required under the NIS2 directive, is specified in the amendment to the Act on the National Cybersecurity System (implementing this directive in Poland). The manager of a key entity and an important entity is obliged to undergo training in the area specified in this Act once a year. Similar to the area of GDPR – participation in the training should be documented.
Regular training should be supplemented with activities that encourage employees to continuously improve and to increase their knowledge and awareness. For example, educational content can be systematically sent out: newsletters (from supervisory authorities or entities professionally engaged in the relevant subject matter), thematic brochures, information about incidents (both internal and external) and the conclusions drawn from them, as well as communications regarding new threats. The manner of presenting and conveying information depends on the organization's decision. It is also advisable to document the actions taken in this area so that they can be demonstrated in the event of a supervisory authority inspection.
How long does GDPR training last?
It is not possible to determine a specific duration for training. It all depends on the type of training, its subject matter, format, and the level of participants' expertise.
As a rough estimate, one can assume that:
- employee training on basic issues related to personal data protection usually lasts from 2 to 4 hours,
- training for management or individuals responsible for personal data protection (including Data Protection Officers) typically lasts 1–2 days,
- more specialized training can take from 8 to even 32 hours,
- webinars usually last about 1 hour,
- e-learning requires a commitment of approximately 30 minutes to 3 hours.
What should good training look like?
Good training is one that:
- truly resonates with the employee's awareness,
- is thematically appropriate, addressing all issues relevant from the perspective of the data processing processes in which the employee participates,
- raises awareness of existing threats,
- provides the ability to handle specific situations (e.g., in the event of a data protection incident or the impact of a GDPR request),
- enables the employee to participate actively and effectively,
- is documented in a way that allows the data controller to demonstrate that they have fulfilled their obligations in this area (accountability principle).
Examples of positions from the UK ICO and EU authorities
Information Commissioner's Office – UK regulatory authority
- The organization should have a training program for all employees regarding data protection and information security. This program should:
- take into account national and sectoral requirements,
- be comprehensive and cover key areas related to data protection, such as handling GDPR requests, data sharing, information security, data breaches, and maintaining records,
- to take into account the training needs of individual employees and departments (identified based on a needs analysis) and to be tailored to the scope of responsibilities of each individual,
- to specify the timeframe for addressing training needs,
- to be approved by top management, as well as regularly reviewed and updated,
- to be supervised or approved by the Data Protection Officer (DPO) or by another person designated to manage information.
- The program should include initial and refresher training. Initial training should take place before allowing the employee access to personal data, no later than within one month of employment. Refresher training should be conducted periodically, at appropriate intervals, in a manner that ensures employees maintain up-to-date knowledge. The responsible person should maintain a training schedule for each employee, indicating the date of initial training and refresher training. The authority considers annual training to be ideal, indicating that it should not be conducted less frequently than every two years.
- Training and skill requirements should be included in job descriptions. Training must also take into account new responsibilities in the event of a change in position or scope of responsibility related to data processing.
- Individuals responsible for managing training should be designated within the organization. They should have a training plan developed, adequate to the needs in this area, and implement it at established time intervals. The organization should also ensure that appropriately qualified personnel are available to conduct the training.
- All employees are subject to training, regardless of their length of service or basis of employment. Individuals involved in personal data protection within the organization, such as the Data Protection Officer (DPO) and members of request fulfillment and records management teams, should receive additional professional training and opportunities for development.
- The foundation of the training should consist of the seven principles of data protection:
- lawfulness, fairness, and transparency,
- purpose limitation,
- data minimization,
- accuracy,
- storage limitation,
- integrity and confidentiality (security),
- accountability.
Training should include an explanation of key concepts related to data protection, such as personal data, the data subject, data breach, and the right to information. In addition, each employee should receive training tailored to their roles and responsibilities. For example, a cleaning person is unlikely to need training on all aspects of data protection, but must be able to recognize situations where personal data is not stored securely and know whom to inform about it. Conversely, other individuals may require more in-depth training, for instance, in the areas of:
- data sharing,
- avoiding personal data breaches,
- ensuring the security of facilities and data,
- the importance of good documentation management.
- The data controller should verify the effectiveness of the training. This can be done, for example, through assessments (tests at the end of the training with a minimum passing score) or surveys. If an employee does not achieve a satisfactory result on the knowledge check test from the training, they should be retrained without waiting for the next scheduled training. The data controller should also ensure that individuals who have not completed the training do so as soon as possible. Additionally, staff should have the opportunity to provide feedback regarding the training they have undergone, and the feedback received should be taken into account in program updates. The results of training monitoring should be reported to management.
- The organization should assess whether it can demonstrate compliance with its training activities to the supervisory authority (accountability principle). The data controller must ensure the ability to prove that individuals in key positions have completed relevant, up-to-date training and participate in supplementary training. They must also keep records of trained individuals and copies of training materials provided to participants. Employees should be familiar with their training documentation, meaning they should be able to explain what training they have completed, when, and to what extent.
- The organization should ensure regular awareness-raising among staff regarding data protection, information management, and applicable policies and procedures. This can take place during meetings, on corporate forums, or through various communication tools such as emails, posters, brochures, leaflets, or blogs. The data controller should have evidence confirming the conduct of such activities. It is also essential to provide easy access to training materials and designate a contact person for questions related to the training topics.
- The employee training register should be maintained up to date and accurately reflect the type of training conducted. The register should include:
- the date of the last training,
- the type of training, e.g., initial, additional, or refresher,
- the deadline by which the refresher training must be conducted,
- the results of data protection tests (if applicable),
- areas requiring additional support and the deadline for providing it,
- information about additional training needed due to changing employee roles.
Swedish Data Protection Authority (IMY)
- Training is a key factor enabling employees to contribute to ensuring security within the organization.
- To meet the requirements of the GDPR and ensure actual data protection, employees must adhere to internal guidelines and procedures regarding personal data protection.
- It is concerning that even half of the employees lack sufficient knowledge of the internal guidelines and procedures for processing personal data applicable in their organization, which prevents them from applying them. Additionally, there is a belief that compliance with the GDPR is not significant. Such an approach does not create favorable conditions for actual compliance with the regulations.
- In organizations that do not ensure all employees understand and accept the common European principles of privacy and data protection, the risk of personal data breaches increases.
- The most common cause of personal data breaches reported to the authority is human error. Therefore, it is recommended to offer regular training that enables employees to take responsibility for ensuring the secure processing of personal data.
French Data Protection Authority (CNIL)
- Personal data protection is a task not only for lawyers and IT specialists but also for all individuals involved in the processing of personal data (other employees, contractors, or clients).
- Employees should be aware of the seriousness of the obligations related to data protection. Therefore, their awareness should be increased, and they should be trained regularly.
- Each department should be able to identify requests regarding the exercise of data subjects' rights and also know the further procedure to follow (e.g., in a situation where a data subject submits an objection to the customer service department regarding the sending of advertisements). Training should cover the principles of data access, including the principle of necessary knowledge, the prohibition of disclosing data to unauthorized persons, and the rules regarding access to archived data and backups. It is also necessary to discuss data security requirements, such as password policies, securing workstations during absences, and using personal devices for business purposes.
- Individuals serving as Data Protection Officers (DPOs) who do not have at least 2 years of professional experience in this area should undergo specialized training lasting a minimum of 35 hours.
Supporting Materials
When developing a training program for employees, it is advisable to refer to guidelines, positions, and decisions from supervisory authorities in various member states. Their websites often publish ready-to-use materials. The information contained in these resources highlights key aspects that should be included in employee training – also because they attract the attention of supervisory authorities. Utilizing these sources facilitates understanding of the expectations of regulators and helps create better practices within the organization.


