How it works today in many organizations
Once a year the data protection training is due. A date is set, the staff spend ninety minutes in the large meeting room, someone presents, and a printed attendance sheet lies by the door. Whoever is there signs. The sheet is then scanned, saved as "Training_Data_Protection_2025.pdf" and filed in the personnel file or in the shared-drive folder "Data protection/Training".
A second track runs alongside. For field sales, part-time staff and everyone who missed the session there is an e-learning tool. It sends invitations, and whoever passes receives a PDF certificate by email. Those certificates land in the HR mailbox or directly with the data protection officer. To keep an overview anyway, there is also an Excel list with four columns: name, department, date, check mark.
The table is always maintained by the same person, usually on the side: they enter whatever certificates come their way and add the names from the attendance sheet. Anyone who joined this year appears only once someone remembers; anyone who has left often stays on the list. Nobody reconciles it against the current staff list: nobody has asked, and in this form it takes hours.
Information security runs the same exercise a second time – different date, different list, different filing location. The people affected are the same. And the confidentiality undertaking, which belongs with the briefing, sits in a third folder: as an annex to the employment contract.
This is not a bad process. It has grown over the years, it can be explained, and it satisfies the awareness and training obligations in principle. What it does not deliver is proof in the individual case.
The moment it becomes apparent
It shows up in three situations: a customer requesting training records in a supplier review, an upcoming certification audit, or the question after an incident whether the person involved had been trained.
The question is then never "do you run training?" It is: "show me, for these eleven people, when they were last trained, with what result, and when the next briefing is due." This process has no answer, because it keeps the record at the session, not at the person. An attendance sheet knows who was in the room. It does not know who should have been there.
Before every audit the same painstaking work starts: searching personnel files for scans, collecting certificates from the mailbox, reconciling the Excel list against the staff list and adding the past twelve months of joiners by hand. Two to three days is realistic in mid-sized organizations.
The analysis
Five Problems Every Attendance Sheet Creates
They arise no matter how carefully the training is delivered – they are properties of the form of proof, not of the training.
View training in preecoOverdue Cases Are Manual Work
A list of attendees does not show who is missing. The question of the open cases is answered only by whoever reconciles the participant list against the current staff list. That evaluation is therefore rarely carried out – usually only once someone from outside asks for it.
New Joiners Fall Between the Sessions
Anyone who starts in March waits seven months for their first briefing if the annual session is in October. Role changes work the same way: the colleague who moves into the HR department needs different training than before. Without a fixed trigger, nobody notices.
Records Sit in Three Systems
The scan sits in the personnel file, the certificate in the e-learning tool or in a mailbox, the status in a spreadsheet. None of these three places answers the question completely. Compiling the evidence for an audit is therefore a project every time, not an export.
Data Protection and Information Security Run Twice
Both topics concern the same people, but they are planned separately, invited separately and filed separately. The effort doubles, and over time the two states drift apart. In the end nobody knows which of the two lists is current.
The Confidentiality Undertaking Is Missing From the Picture
The briefing and the confidentiality undertaking belong together, but they are filed separately – one in the training folder, the other in the employment contract. In a review it is regularly the very document that turns the training into complete evidence that is missing.
The target process in six steps
The difference is not the content of the training. It is what the record is attached to. These six steps describe the sequence – whatever tool you work with.
1. Attach the record to the person, not to the session. The central unit is no longer the event of October 12 but each person's training status: which briefings are intended, which are completed, when, with what result, and when the next is due. Every further step follows from this change.
2. Define who needs which training. Not everyone needs the same thing. Management, HR, sales and IT have different points of contact with personal data. Assign training to roles and departments instead of inviting everyone. That reduces the volume per person and makes the assignment defensible.
3. Fixed intervals instead of ad hoc planning. Every course gets a cycle – usually annual, tighter for exposed areas. What matters is not the interval length but that it is recorded and carries a reminder. In preeco, follow-up reminders point to pending and due training.
4. Deliver the training where the record is created. Online training consists of learning units with image and video content and single or multiple choice examination questions. The minimum score for certification is freely adjustable. Whoever passes automatically receives a certificate of participation as a PDF – the record arises as a by-product instead of being collected afterwards.
5. Add participants cleanly, once. People are added manually, from existing contacts or by XLSX import; an availability period with a start and end date can be set for answering. That documents everyone under obligation – not only those who turned up.
6. Evaluation as a report, not as painstaking work. Progress is visible at any time: who has completed, who is outstanding. Status reports follow from this and export as PDF or DOCX, with the activity log of time stamp, user and action.
Why data protection and information security belong together
preeco | data protection and preeco | information security share one platform. For training that is not a detail but the actual lever: the people are the same, the organizational structure is the same, and the question about training status is asked identically in both disciplines. Instead of two plans, two invitation rounds and two filing locations, one picture per person emerges with both briefings side by side.
In practice: template courses for both areas sit in the same stock – from GDPR training through data protection in the home office and AI literacy to "IT security – awareness for employees" and the NIS2 training for management. Anyone who runs both topics plans once instead of twice.
Before and after in direct comparison
| Criterion | Before: attendance sheet and Excel | After: training status per person |
|---|---|---|
| Unit of reference | The session: who was in the room | The person: which status applies |
| Maintenance effort | Scanning, filing, updating the table | The record arises with participation |
| Completeness | Only attendees visible, absentees invisible | Target and actual side by side per person |
| Intervals | In one person's calendar | Cycle recorded, reminder as a follow-up |
| Provability | Scan without result or examination | Participation certificate as PDF with exam result |
| Data protection and security | Two plans, two filing locations | Both briefings in one picture per person |
| Evaluation | Days of reconciliation before the audit | Progress in real time, status report as export |
| Failure risk | Knowledge and table depend on one person | Process, history and log sit in the system |
In practice
This is what it looks like in preeco | data protection
The three building blocks that carry the process described.
Training and Qualification
Online training made up of learning units and examination questions, a freely adjustable minimum score, an automatic certificate of participation as a PDF. Participants are added manually, from the contacts or by XLSX import; template courses are included.
Training in Information Security
The same mechanics for the ISMS: availability period, follow-up reminders that point to pending and due training, a complete training history per person – including the template for the training obligation of management bodies under NIS2.
Reporting and Activities
Status reports with a table of contents, schedulable recurring reports with email notification and a filterable activity log. Export as PDF and DOCX (reports) as well as XLSX (overview tables) for auditors and management.
What the switch means in practice
The most common objection is that the classroom session would then have to be abolished. That is not the case. The talk in the meeting room stays if it has proven itself – it is often the better opportunity for questions out of everyday work. What changes is the record behind it: the content is also available as a learning unit, the examination questions are answered afterwards, and participation is documented per person – including for everyone who could not attend.
The effort lies less in the technology than in a clarification that is due anyway: which role needs which briefing, at what interval, and who decides. Once that assignment is made, the rest runs through dates and reminders.
Three mistakes that make the switch unnecessarily hard
Trying to reconstruct the old records in full. The existing status is adopted as a starting point, not rebuilt. From the first cycle in the new process onwards the documentation is complete – that is enough, and it does not cost weeks.
Assigning every course to every person. A blanket assignment produces high completion rates and little effect. Assignment by role and department keeps the volume per person small and defensible towards auditors.
Continuing to plan data protection and information security separately. Anyone who runs the two topics in two lanes in the new tool rebuilds the old duplication. Both belong in one plan, because they concern the same people.
How you can tell it is time
An attendance sheet is not a mistake. It becomes a risk as soon as one of these points applies:
- You cannot say within a few minutes who is currently overdue.
- New people regularly join between two training sessions.
- Records sit in more than one system or mailbox.
- Customers, auditors or certification bodies ask for records regularly.
- Data protection and security training are planned and filed separately.
If none of these applies, the list is fine. If two or more apply, it is already costing you time at the next review.
FAQ
Frequently asked questions about training records
The GDPR does not prescribe any particular form of proof. An attendance sheet, however, documents only who was present – not who had to take part, whether the content was understood and when the next briefing is due. For the accountability obligation under Art. 5(2) GDPR, the training status per person is the more robust basis, because it also makes the open cases visible.
The GDPR does not name a fixed interval. Art. 39(1)(b) GDPR counts the awareness-raising and training of the staff involved among the tasks of the data protection officer, without specifying a cycle. In practice an annual briefing has become established, supplemented by an initial briefing on joining and additional training when roles change or new processing activities are introduced.
There is no statutory deadline for the initial briefing. Professionally, the next annual session is nevertheless too late if the person works with personal data from their first working day. A briefing within the first few weeks is customary, together with the confidentiality undertaking. If the training is kept per person, this trigger arises automatically when someone joins instead of when a session takes place.
Yes. preeco | data protection and preeco | information security share one platform, so both briefings are planned and evaluated for the same people and the same organizational structure. Template courses for both areas sit in the same stock, among them the NIS2 training for management.
Through the certificate of participation and the training history. Once the examination has been passed, the certificate is generated automatically as a PDF and stays assigned to that person; the overview shows the participation status of everyone involved. From this a status report can be generated for auditors and exported as PDF or DOCX, supplemented by the activity log.
Go through your training status together
Bring your Excel list along. In 30 minutes we show how the training status per person comes about and where the gaps are.