General Data Protection Regulations (GDPR) eLearning
Online data protection training that gives every member of staff the UK GDPR basics: what personal data is, what they must do with it, and what to do the moment something goes wrong.
Who it is for
Who this GDPR course is for
Data protection is not a job for one person in the office. Everyone who sees a customer record, an employee file, a CCTV screen or a spreadsheet of email addresses is handling personal data, and the organisation answers for what they do with it.
- All staff, as part of induction or annual refresher training
- Office, admin and reception teams handling customer and employee records
- Sales and marketing staff working with contact data and consent
- HR and payroll handling employee and applicant files
- Managers responsible for a team's data handling
- Anyone who may receive a subject access request or spot a breach
Course content
What the GDPR course covers
Five short lessons covering what personal data is, the principles and lawful bases, people's rights, keeping data secure, and what to do when it goes wrong, then a 12-question assessment.
What personal data is
What counts as personal data and special category data, and how to recognise it in the records you handle every day.
The principles and lawful bases
The data protection principles that govern every use of personal data, and what a lawful basis means in practice.
People's rights
The rights people have over their data, recognising a subject access request in any form, and passing it on quickly.
Keeping data secure
Practical security in everyday work: email, attachments, devices, sharing, retention and disposal.
When it goes wrong
Recognising a personal data breach, reporting it without delay, the 72-hour rule and the role of the regulator.
Outcomes
What you will be able to do afterwards
- Recognise personal data and special category data in your own work
- Explain the data protection principles and lawful bases in plain language
- Recognise a subject access request and the other rights, and pass them on
- Handle, share, store and dispose of personal data safely
- Spot a personal data breach and report it without delay
Your legal duty
The law behind data protection training
UK data protection is governed by the UK GDPR alongside the Data Protection Act 2018, and regulated by the Information Commissioner's Office. Both place obligations on the organisation rather than on the individual member of staff, but almost every obligation is met, or missed, by ordinary people doing ordinary work.
Staff training is not a standalone offence to skip. It is how an organisation demonstrates the accountability the law expects: that it has taken appropriate measures, that people knew what was required of them, and that breaches get recognised and reported rather than quietly buried.
- UK GDPR
- Data Protection Act 2018
- Regulated by the Information Commissioner's Office (ICO)
Practicalities
How the course works
Would you rather have a tutor?
Where your own retention schedule, systems and reporting lines need to be in the training, we can build that version for you.
For employers
Rolling GDPR training out across a workforce
Data protection is the training most often bought for everybody at once, which makes it the worst one to buy card payment by card payment. An account gives you one invoice and a record of who has done it.
- One invoice instead of a card payment per person
- Licences allocated as people join, so induction is covered
- Completion and expiry reporting for your accountability records
- Renewal reminders before certificates lapse
- Bespoke versions written around your own policies and systems
General Data Protection Regulations (GDPR) eLearning: common questions
No single course does. It gives your staff the awareness the law expects them to have and gives you a dated training record for each person. Your policies, lawful bases, retention schedule and records of processing still have to exist alongside it.
About 30 to 45 minutes. There is no time limit: start it, pause it, and come back whenever suits. The certificate is issued as soon as you pass the end assessment.
Annually is the most common interval organisations set for themselves, and sooner if your systems, policies or the law change. The certificate itself is valid for one year.
UK. The course is written around the UK regime and the Information Commissioner's Office as the regulator.
Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.
Yes. Open a business account and we invoice you for the licences, which you allocate as people join, with completion reporting included.
A request from an individual to see the personal data you hold about them. The course teaches staff to recognise one, which matters because the clock starts when it arrives, not when it reaches the right desk.