GDPR training – who initiates it: the DPO or the controller?
ANSWER
Responsibility for organising training lies with the controller, and it is the controller who should initiate training. However, Article 39 GDPR provides that the data protection officer should also recommend that training be conducted and suggest its subject matter and scope — so the initiative may also come from the DPO. Nevertheless, it is the controller who is accountable to UODO for the lack of training.


