Data Protection Training for Staff

Live GDPR training for your team, delivered by a named, experienced DPO who knows your organisation and its data flows.

Why your staff need data protection training

UK GDPR applies to everyone who handles personal data. One employee sending a spreadsheet to the wrong address, saving records to a personal device, or sharing a colleague's health information can breach it, and the organisation is liable.

The ICO expects regular, documented training, and when it investigates a breach, one of the first things it asks is whether staff were trained and when.

Why live training matters: generic online modules teach generic rules. They cannot tell your customer service team how UK GDPR applies to the CRM they actually use or show HR how retention periods work for the employee files they manage. Alex builds every session around your real systems, data flows and risk areas, so staff remember it.

What the training covers?

What personal data is and why it matters

The definition of personal data under UK GDPR, what counts as sensitive (special category) data, and the real consequences of getting it wrong — for individuals and for the organisation

The lawful bases for processing

The six lawful bases under Article 6 in plain English — consent, legitimate interests, legal obligation, and the others — and how to identify which applies to what your team does every day

Handling personal data correctly

Safe collection, storage, access controls, sharing with third parties, and deletion — practical rules for the specific systems your organisation uses

Recognising and reporting a data breach

What counts as a breach, what to do in the first hour, the 72-hour window for reporting to the ICO, and what happens when staff don't report in time

Subject access requests and individual rights

What a Subject Access Request (SAR) is, who can make one, what you have to provide, the one-month deadline, and the mistakes that trigger ICO complaints

Common mistakes and how to avoid them

Real scenarios drawn from ICO enforcement cases — misdirected emails, inadequate access controls, unlawful sharing, and failure to respond to rights requests — with practical steps to prevent each

How its delivered

Alex Goodman delivers every session himself, live over video. He brings his working knowledge of the ICO's enforcement priorities, the sectors he works across, and your organisation's own compliance context.

Live and online

Every session runs live over video, led by Alex, never a pre recorded module. Full Q&A throughout, and it works for teams of any size.

On your schedule

Sessions are booked at a time that suits your team, from a 90-minute overview to a half day for larger groups.

For your organisation

Content is shaped to your systems, your sector and your real risks, so staff learn what actually applies to them rather than generic rules.

Session length: 90 minutes for a core overview, up to a half day for larger teams or when role specific breakout content is included. Alex recommends the right format based on your team size and what you need to cover.

Documentation: After every session Alex provides a written attendance record showing who attended and what was covered, which is what the ICO expects to see if your training is ever reviewed.

Who the training is for

Almost every UK organisation handles personal data, and keeping staff trained is part of the accountability and security duties UK GDPR places on you, and something the ICO expects to see. It matters most for:

Customer-facing teams

Staff handling enquiries, bookings, complaints, or sales: any role where personal data passes through.

HR and payroll

Teams working with employee records, references, health information, and payroll data. All of it falls under the most sensitive categories in UK GDPR.

IT and operations

Staff with administrative access to systems holding personal data, responsible for access controls, backups, and system security.

Management and board

Decision-makers who sign off on new processing activities, supplier contracts, and marketing campaigns. Most compliance risk starts here.

Customer-facing teams

Anyone handling enquiries, bookings, complaints or sales, where personal data passes through every day.

HR and payroll

Teams working with employee records, references, health information and payroll, some of the most sensitive data you hold.

IT and operations

Staff with administrative access to systems holding personal data, responsible for access controls, backups and security.

Management and board

Decision makers who sign off new processing, supplier contracts and marketing. Most compliance risk starts here.

Consultant-led vs generic e-learning

Generic e-learning modules

  • Same content for every organisation in every sector

  • No reference to your systems or data

  • Completion certificates, not real understanding

  • Staff click through to finish and retain little

  • No chance to ask about real situations

Alex Goodman - GDPR Consultant

  • Tailored to your organisation's processing activities

  • Scenarios drawn from your actual systems and workflows

  • Live Q&A so staff can raise the real situations they face

  • Delivered by a practicing DPO who works with ICO guidance and enforcement cases day to day

  • Written attendance record for your compliance files

Frequently asked questions

How often should staff be trained?

The ICO does not set a fixed frequency, but annual training is the standard the ICO looks for. Organisations handling special category data, processing data at scale, or operating in regulated sectors need more frequent sessions. Alex recommends training for all new starters as part of onboarding, followed by annual refreshers for the full team.

Can the session be recorded for staff who can't attend?

Yes, with all participants' consent. New starters who miss the session can watch a recording as part of their induction. Alex recommends a live session each year. GDPR guidance and ICO enforcement priorities shift, and a static recording goes stale.

We only have a small team — is training still worthwhile?

Yes. Small organisations are fully subject to UK GDPR, and the ICO regularly investigates and fines smaller businesses. A 90-minute session for a team of five carries the same legal weight as training a team of 500. An untrained employee creates the same breach risk whether your headcount is five or five hundred.

Can training be tailored to a specific role or department?

Yes. Alex can structure a session specifically for your HR team, your customer service function, your IT department, or any other group with distinct data protection responsibilities. Role specific training works better than a single session when different teams handle distinctly different types of data.

What counts as evidence of training for the ICO?

The ICO expects records of who was trained, when, and what was covered. Alex provides written documentation after every session that meets this standard. Alex also recommends signed attendance sheets for organisations subject to sector specific regulation.

Is this connected to an ongoing DPO service?

Training runs as a standalone service you can book on its own. It is also built into two of the plans: the GDPR Compliance Fix (£699) includes a session as part of the project, and the Ongoing DPO cover retainer (from £299 per month) includes an annual training session, so your staff stay current as guidance changes. Already on a plan? Your session is arranged as part of it.

Client Testimonials

Existing DPO clients

Driven by expertise and personalised service, we’re here to guide you towards GDPR compliance every step of the way.

© 2026 - GDPR Consultant - All Rights Reserved.

Alex Goodman is an experienced GDPR consultant and outsourced Data Protection Officer working with UK businesses to improve their DPO and GDPR compliance.

© 2026 - GDPR Consultant - All Rights Reserved.