Skip to main content
Data Protection / GDPR

Data protection training

Data protection training is the planned awareness-raising and instruction of staff involved in processing operations, a task expressly assigned to the data protection officer by Art. 39(1)(b) GDPR and one that must be documented in a verifiable way.

Data protection training is the key organisational instrument through which a controller ensures that the people who actually handle personal data understand the requirements of the GDPR and apply them in daily work. Art. 39(1)(b) GDPR explicitly assigns the data protection officer the task of informing and advising staff, and of raising awareness and training the personnel involved in processing operations, including the related audits. Responsibility for making the training happen nevertheless stays with management: the data protection officer monitors and supports, but does not assume liability in the controller's place. Where no data protection officer has to be appointed because the thresholds of Art. 37 GDPR and section 38 BDSG are not met, the training duty does not disappear — it then follows directly from Art. 24 and Art. 32 GDPR.

Legally, the obligation is assembled from several provisions. Art. 32(4) GDPR requires the controller and the processor to take steps to ensure that any person acting under their authority processes personal data only on instructions — something that is not achievable in practice without instruction and training. Art. 29 GDPR restates that duty from the perspective of the individual employee, and Art. 28(3)(b) GDPR obliges the processor to ensure that persons authorised to process the data have committed themselves to confidentiality. Training therefore counts as a technical and organisational measure under Art. 32 GDPR and forms part of the appropriate measures required by Art. 24 GDPR. Neither the GDPR nor the German Federal Data Protection Act prescribes a fixed interval or minimum duration; an annual cycle supplemented by ad-hoc sessions — after a personal data breach, before a new processing activity, or when a new system is rolled out — has become the accepted market standard.

What determines the external effect is the documentation. The accountability principle in Art. 5(2) GDPR requires the controller to be able to demonstrate compliance, so a session that took place but cannot be evidenced is worthless in proceedings before a supervisory authority. The record should capture at least the date, the content or agenda, the target audience, the trainer, the duration and the attendance of each individual; for e-learning, add the completion rate and the test result. Mature organisations complement this with a signed confidentiality undertaking, a role-specific training plan — sales, HR, IT and marketing carry very different risks — and retention of the evidence beyond the end of the employment relationship, in line with applicable limitation periods. After an incident, supervisory authorities routinely ask whether training took place: demonstrable training can act as a mitigating factor under Art. 83(2) GDPR, while its absence is read as an organisational failure on the part of management.

Legal Basis

Art. 39(1)(b) GDPR (awareness-raising and training), Art. 32(4) and Art. 29 GDPR (processing only on instructions), Art. 24 GDPR (appropriate measures), Art. 5(2) GDPR (accountability), Art. 28(3)(b) GDPR (confidentiality undertaking), section 53 BDSG

Practical Example

A mid-sized machinery manufacturer with 240 employees receives an enquiry from the state supervisory authority after a sales representative sent a quotation list containing customer data to the wrong recipient. The data protection coordinator submits the training concept: an annual 45-minute e-learning module for all staff, an additional classroom session for sales and HR, and an onboarding unit that every new joiner completes within the first four weeks. The training register shows that the employee concerned attended on 14 March of the previous year and passed the final test, alongside a signed confidentiality undertaking. Because the company can also evidence that a short, incident-driven refresher on secure e-mail handling was delivered to the whole department within three weeks of the breach, the authority accepts the organisational set-up as appropriate and closes the case with a reprimand rather than a fine.

FAQ

The GDPR sets no fixed interval. In practice an annual cycle has become the norm, supplemented by sessions for new joiners, for people changing roles, and whenever there is a specific trigger such as a personal data breach or the introduction of a new processing system. What matters is that the frequency matches the risk of the processing and can be justified.
At minimum the date, duration, content or agenda, target audience, trainer and the attendance of each named participant. For e-learning, add the completion date and the test result. These records form part of the accountability obligation under Art. 5(2) GDPR and should be stored in an audit-proof way together with the confidentiality undertaking.
No. Under Art. 39(1)(b) GDPR the data protection officer is tasked with raising awareness, training staff and monitoring that this happens; responsibility for implementation and for providing the resources lies with the controller. Missing training is attributed to management as an organisational failure, not to the data protection officer.

How preeco supports you

Learn how our software supports you with this topic.

Learn more