More than 5000 satisfied customers worldwide
What the ICO expects from data protection training for staff
The short version: train everyone, train them again, and be able to prove it.
The UK GDPR, read alongside the Data Protection Act 2018, rests on seven principles. The last one is accountability: you have to protect personal data and be able to show how you do it. Staff training is one of the clearest ways to show it, and the ICO’s accountability framework spells out what it looks for:
- an all-staff data protection and information governance training programme;
- induction training for new starters and refresher training for everyone;
- content on key areas such as handling requests, data sharing, information security, personal data breaches and records management;
- evidence that staff complete and understand the training, with completion monitored at every level of the organisation.
Two other ICO guides point the same way. The personal data breach guide calls human error the leading cause of reported breaches, lists mandatory induction and refresher training among the ways to reduce it and expects staff to know how to escalate a security incident. The subject access guide asks whether you train staff to recognise and deal with a request, whether it arrives in writing or verbally.
The ICO notes that parts of this guidance are under review following the Data (Use and Access) Act, so check the latest version before you sign off your programme. This is general information, not legal advice.
Sources (checked October 2026): ICO, accountability framework: training and awareness; ICO, personal data breaches: a guide; ICO, a guide to subject access; ICO, a guide to the data protection principles.
What good GDPR training for employees covers
Nobody outside the DPO’s office needs to quote articles. They need to recognise these six situations and know what to do next.
Lawful basis
Every use of personal data needs a lawful basis, and “we’ve always done it this way” isn’t one. Staff don’t have to choose the basis; they have to know when to stop and ask.
Data minimisation
Personal data should be adequate, relevant and limited to what’s necessary. In practice: no collecting “just in case”, and no exporting the whole spreadsheet when one column will do.
Breaches and the 72-hour clock
A notifiable breach must reach the ICO without undue delay and within 72 hours of becoming aware of it, and every breach must be recorded. A misdirected email or a lost laptop can start that clock, so people need to spot it and escalate at once.
Subject access requests
A request can arrive verbally or in writing, even on social media, without any particular wording, and you normally have one month to respond. The colleague who takes the call has to recognise it.
Phishing and security
Integrity and confidentiality is one of the seven principles. Most of it comes down to habits: spotting phishing, strong passwords and two-factor authentication, care with public Wi-Fi and mobile devices.
Roles and rights
Who is responsible for what, what rights people have over their data and who inside your organisation deals with each request.
Why a simulation makes data protection stick
In Classified, Steve has just landed his dream job as head of Marketing, days before the launch of a revolutionary device. One data protection mistake could take the company down, and the player is right there with him. Through practical exercises they work through the GDPR’s key concepts and principles, who is involved and what each party answers for, the rights of data subjects and the duties that keep personal data safe.
Every decision comes with feedback and areas to improve, so people learn by getting things wrong where it costs nothing. That’s the difference with a slide deck: staff rehearse the moment that matters, instead of reading about it.
Crypt0 covers the security side. Players go undercover with an ethical hacker inside a biotech company and fix the careless mistakes cybercriminals exploit, from phishing and social engineering to passwords, public Wi-Fi and email. Together they form the data protection strand of our compliance training catalogue.

What the games cover, and what you add
Honest mapping. The games handle the behaviour; your own procedures handle the specifics.
Classified (1 h 30 min)
- Basic concepts, principles and who’s involved
- Roles and responsibilities
- Data subjects and their rights
- Guidelines that keep personal data safe
Crypt0 (2 h)
- Phishing and social engineering
- Passwords and two-factor authentication
- Mobile devices, public Wi-Fi and email
- Storing and sharing files safely
Add from your own policies
- Who your DPO or data protection lead is
- Your internal route for reporting a breach
- How you log and answer subject access requests
- Your retention schedule
How to run staff data protection training, step by step
- New starters1
Induction
Add Classified to onboarding so new people learn the basics before they touch customer or employee data.
- Everyone2
Refreshers
Set a deadline, send the whole organisation through Classified and Crypt0, and let rankings and badges do some of the chasing.
- Check3
Understanding
Feedback on every decision shows people where they went wrong, and the surveys built into each course feed Kirkpatrick-based reports on what was learnt and applied.
- Record4
Evidence
The Admin module tracks progress per learner and group in real time, from our campus or your LMS (integration or hybrid SCORM, with SSO). Everyone who finishes gets a certificate.
Compliance training people remember
DKV Seguros put 900 employees through mandatory compliance training with our serious games: 90% completed it and 98.6% would recommend it.
The subject of compliance is something we see a lot in our day-to-day. There’s a difference between learning something and internalizing it, and participating in an initiative such as this focuses on the latter.
You drive. Your CSM navigates.
Every project has a Customer Success Manager (CSM) who knows it inside out. They work with you to connect the goal you started with, what happens during the project and the results you get.
We don't just track progress. We help you decide what to do with what we learn.
Alwayswith a CSM by your side
StartYour goal
FinishYour results
Defines success with you
What you want to achieve, what should change and how we'll know it's happening.
Gets your team on board
Works with you to reach the participation you need and drive results.
Measures what's changing
Participation, progress, applicability and results. And, where the project allows, how your team is evolving.
Spots where to act
Flags risks before they put the result at stake, and opportunities to improve it.
Turns results into decisions
What we've achieved, what we've learned and what the next step should be.
One more lap: every review ends in a decision (keep going, improve or take the next step), always with someone who already knows your project.
GDPR training for employees: FAQs
General information, not legal advice. ICO guidance checked in October 2026.
Is GDPR training for employees a legal requirement in the UK?
The UK GDPR makes organisations accountable for protecting personal data and for being able to show how they do it. In its accountability framework, the ICO expects an all-staff training programme with induction and refresher training, and evidence that staff complete and understand it. Check your own obligations with your DPO or legal adviser.
How often should staff do data protection training?
The ICO expects induction training for new starters and refresher training for all staff, with completion monitored. Set a refresher cycle that fits your risks, record it and stick to it.
What should data protection training for staff cover?
The principles (including lawful basis and data minimisation), recognising and escalating personal data breaches, recognising subject access requests, security habits such as spotting phishing, and who in your organisation is responsible for what.
Does Classified follow the UK GDPR or the EU GDPR?
Classified is built on the General Data Protection Regulation. The UK GDPR keeps the same seven principles and the same core ideas, so the game works for UK staff. For UK specifics, such as how and when you report to the ICO, add a short briefing from your own procedures.
How long do the courses take, and in which languages?
Classified takes about 1 h 30 min and is available in English, Spanish, French and German. Crypt0 takes 2 hours and is available in English, Spanish and French. Both run on computer, tablet or phone.
Can we keep a record of who has completed it?
Yes. The Admin module shows each learner’s and group’s progress in real time, whether they play from our campus or from your LMS, and everyone who finishes gets a certificate.
More ways to train by playing
Data protection is one part of the picture. These are the others.
Want to see Classified in action?
Book a personalised demo: we’ll walk you through Classified and Crypt0, show you the Admin reports and work out how they fit your induction and refresher cycle.



