General Data Protection Regulations (GDPR) eLearning
Half an hour of online data protection training that gives every member of staff the UK GDPR basics: what personal data is, what they must do with it, and what to do the moment something goes wrong.
Who it is for
Who this GDPR course is for
Data protection is not a job for one person in the office. Everyone who sees a customer record, an employee file, a CCTV screen or a spreadsheet of email addresses is handling personal data, and the organisation answers for what they do with it.
- All staff, as part of induction or annual refresher training
- Office, admin and reception teams handling customer and employee records
- Sales and marketing staff working with contact data and consent
- HR and payroll handling employee and applicant files
- Managers responsible for a team's data handling
- Anyone who may receive a subject access request or spot a breach
Course content
What the GDPR course covers
Five short modules taking a member of staff from “what counts as personal data” to “what I do in the first hour of a breach”, with an interactive test at the end that records the result.
What personal data is
Personal data and special category data, and how to recognise it in the records you handle every day.
The principles
The data protection principles that govern every use of personal data, and what lawful basis means in practice.
People's rights
The rights individuals hold over their data, including subject access requests and how to recognise one when it arrives.
Keeping data secure
Practical security in day-to-day work: email, attachments, devices, sharing, retention and disposal.
When it goes wrong
Spotting a personal data breach, who to tell, how quickly, and the role of the Information Commissioner's Office.
Outcomes
What you will be able to do afterwards
- Recognise personal data and special category data in your own work
- Explain the data protection principles in plain language
- Recognise a subject access request and know who to pass it to
- Handle, share, store and dispose of personal data more safely
- Spot a personal data breach and report it without delay
- Say what the ICO is and what it regulates
Your legal duty
The law behind data protection training
UK data protection is governed by the UK GDPR alongside the Data Protection Act 2018, and regulated by the Information Commissioner's Office. Both place obligations on the organisation rather than on the individual member of staff, but almost every obligation is met, or missed, by ordinary people doing ordinary work.
Staff training is not a standalone offence to skip. It is how an organisation demonstrates the accountability the law expects: that it has taken appropriate measures, that people knew what was required of them, and that breaches get recognised and reported rather than quietly buried.
- UK GDPR
- Data Protection Act 2018
- Regulated by the Information Commissioner's Office (ICO)
Practicalities
How the course works
For employers
Rolling GDPR training out across a workforce
Data protection is the training most often bought for everybody at once, which makes it the worst one to buy card payment by card payment. An account gives you one invoice and a record of who has done it.
- One invoice instead of a card payment per person
- Licences allocated as people join, so induction is covered
- Completion and expiry reporting for your accountability records
- Renewal reminders before certificates lapse
- Bespoke versions written around your own policies and systems
Where your own retention schedule, systems and reporting lines need to be in the training, we can build that version for you. Talk to us about a bespoke version →
General Data Protection Regulations (GDPR) eLearning: common questions
No single course does. It gives your staff the awareness the law expects them to have and gives you a dated training record for each person. Your policies, lawful bases, retention schedule and records of processing still have to exist alongside it.
About 30 minutes. There is no time limit: start it, pause it, and come back whenever suits. The certificate is issued the moment you finish.
Annually is the most common interval organisations set for themselves, and sooner if your systems, policies or the law change. The certificate itself is valid for three years.
UK. The course is written around the UK regime and the Information Commissioner's Office as the regulator.
Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.
Yes. Open a business account and we invoice you for the licences, which you allocate as people join, with completion reporting included.
A request from an individual to see the personal data you hold about them. The course teaches staff to recognise one, which matters because the clock starts when it arrives, not when it reaches the right desk.