More than 5000 satisfied customers worldwide

  • Adidas
  • Balay
  • BBVA
  • Campofrío
  • Coca-Cola
  • Damm
  • Decathlon
  • Desigual
  • Ford
  • Heineken
  • Iberia
  • Kyocera
  • Liverpool
  • MAN
  • Merck
  • Nivea
  • Olympus
  • P&G
  • Pepsi
  • Banco Sabadell
  • Sigma
  • Unifoods
  • Vestas
  • Kellogg's
  • Burger King
  • Bayer
  • Camper
  • Citibanamex
  • Codorníu
  • Danone
  • Deliplus
  • Ericsson
  • Generali
  • Iberdrola
  • Iglo
  • LG
  • L'Oréal Paris
  • Mapfre Tepeyac
  • Michelin
  • Novartis
  • Otis
  • Pemex
  • Philips
  • Sanofi
  • Toyota
  • Unilever
  • Volvo

What the ICO expects from data protection training for staff

The short version: train everyone, train them again, and be able to prove it.

The UK GDPR, read alongside the Data Protection Act 2018, rests on seven principles. The last one is accountability: you have to protect personal data and be able to show how you do it. Staff training is one of the clearest ways to show it, and the ICO’s accountability framework spells out what it looks for:

  • an all-staff data protection and information governance training programme;
  • induction training for new starters and refresher training for everyone;
  • content on key areas such as handling requests, data sharing, information security, personal data breaches and records management;
  • evidence that staff complete and understand the training, with completion monitored at every level of the organisation.

Two other ICO guides point the same way. The personal data breach guide calls human error the leading cause of reported breaches, lists mandatory induction and refresher training among the ways to reduce it and expects staff to know how to escalate a security incident. The subject access guide asks whether you train staff to recognise and deal with a request, whether it arrives in writing or verbally.

The ICO notes that parts of this guidance are under review following the Data (Use and Access) Act, so check the latest version before you sign off your programme. This is general information, not legal advice.

Sources (checked October 2026): ICO, accountability framework: training and awareness; ICO, personal data breaches: a guide; ICO, a guide to subject access; ICO, a guide to the data protection principles.

What good GDPR training for employees covers

Nobody outside the DPO’s office needs to quote articles. They need to recognise these six situations and know what to do next.

  • Lawful basis

    Every use of personal data needs a lawful basis, and “we’ve always done it this way” isn’t one. Staff don’t have to choose the basis; they have to know when to stop and ask.

  • Data minimisation

    Personal data should be adequate, relevant and limited to what’s necessary. In practice: no collecting “just in case”, and no exporting the whole spreadsheet when one column will do.

  • Breaches and the 72-hour clock

    A notifiable breach must reach the ICO without undue delay and within 72 hours of becoming aware of it, and every breach must be recorded. A misdirected email or a lost laptop can start that clock, so people need to spot it and escalate at once.

  • Subject access requests

    A request can arrive verbally or in writing, even on social media, without any particular wording, and you normally have one month to respond. The colleague who takes the call has to recognise it.

  • Phishing and security

    Integrity and confidentiality is one of the seven principles. Most of it comes down to habits: spotting phishing, strong passwords and two-factor authentication, care with public Wi-Fi and mobile devices.

  • Roles and rights

    Who is responsible for what, what rights people have over their data and who inside your organisation deals with each request.

Why a simulation makes data protection stick

In Classified, Steve has just landed his dream job as head of Marketing, days before the launch of a revolutionary device. One data protection mistake could take the company down, and the player is right there with him. Through practical exercises they work through the GDPR’s key concepts and principles, who is involved and what each party answers for, the rights of data subjects and the duties that keep personal data safe.

Every decision comes with feedback and areas to improve, so people learn by getting things wrong where it costs nothing. That’s the difference with a slide deck: staff rehearse the moment that matters, instead of reading about it.

Crypt0 covers the security side. Players go undercover with an ethical hacker inside a biotech company and fix the careless mistakes cybercriminals exploit, from phishing and social engineering to passwords, public Wi-Fi and email. Together they form the data protection strand of our compliance training catalogue.

Classified, the GDPR training video game from Game Strategies

What the games cover, and what you add

Honest mapping. The games handle the behaviour; your own procedures handle the specifics.

Classified (1 h 30 min)

  • Basic concepts, principles and who’s involved
  • Roles and responsibilities
  • Data subjects and their rights
  • Guidelines that keep personal data safe

Crypt0 (2 h)

  • Phishing and social engineering
  • Passwords and two-factor authentication
  • Mobile devices, public Wi-Fi and email
  • Storing and sharing files safely

Add from your own policies

  • Who your DPO or data protection lead is
  • Your internal route for reporting a breach
  • How you log and answer subject access requests
  • Your retention schedule

How to run staff data protection training, step by step

  1. New starters1

    Induction

    Add Classified to onboarding so new people learn the basics before they touch customer or employee data.

  2. Everyone2

    Refreshers

    Set a deadline, send the whole organisation through Classified and Crypt0, and let rankings and badges do some of the chasing.

  3. Check3

    Understanding

    Feedback on every decision shows people where they went wrong, and the surveys built into each course feed Kirkpatrick-based reports on what was learnt and applied.

  4. Record4

    Evidence

    The Admin module tracks progress per learner and group in real time, from our campus or your LMS (integration or hybrid SCORM, with SSO). Everyone who finishes gets a certificate.

Compliance training people remember

DKV Seguros put 900 employees through mandatory compliance training with our serious games: 90% completed it and 98.6% would recommend it.

The subject of compliance is something we see a lot in our day-to-day. There’s a difference between learning something and internalizing it, and participating in an initiative such as this focuses on the latter.

Julián NuñoDigital Transformation Manager, DKV

You drive. Your CSM navigates.

Every project has a Customer Success Manager (CSM) who knows it inside out. They work with you to connect the goal you started with, what happens during the project and the results you get.

We don't just track progress. We help you decide what to do with what we learn.

Alwayswith a CSM by your side

StartYour goal

FinishYour results

  1. Defines success with you

    What you want to achieve, what should change and how we'll know it's happening.

  2. Gets your team on board

    Works with you to reach the participation you need and drive results.

  3. Measures what's changing

    Participation, progress, applicability and results. And, where the project allows, how your team is evolving.

  4. Spots where to act

    Flags risks before they put the result at stake, and opportunities to improve it.

  5. Turns results into decisions

    What we've achieved, what we've learned and what the next step should be.

One more lap: every review ends in a decision (keep going, improve or take the next step), always with someone who already knows your project.

GDPR training for employees: FAQs

General information, not legal advice. ICO guidance checked in October 2026.

Is GDPR training for employees a legal requirement in the UK?

The UK GDPR makes organisations accountable for protecting personal data and for being able to show how they do it. In its accountability framework, the ICO expects an all-staff training programme with induction and refresher training, and evidence that staff complete and understand it. Check your own obligations with your DPO or legal adviser.

How often should staff do data protection training?

The ICO expects induction training for new starters and refresher training for all staff, with completion monitored. Set a refresher cycle that fits your risks, record it and stick to it.

What should data protection training for staff cover?

The principles (including lawful basis and data minimisation), recognising and escalating personal data breaches, recognising subject access requests, security habits such as spotting phishing, and who in your organisation is responsible for what.

Does Classified follow the UK GDPR or the EU GDPR?

Classified is built on the General Data Protection Regulation. The UK GDPR keeps the same seven principles and the same core ideas, so the game works for UK staff. For UK specifics, such as how and when you report to the ICO, add a short briefing from your own procedures.

How long do the courses take, and in which languages?

Classified takes about 1 h 30 min and is available in English, Spanish, French and German. Crypt0 takes 2 hours and is available in English, Spanish and French. Both run on computer, tablet or phone.

Can we keep a record of who has completed it?

Yes. The Admin module shows each learner’s and group’s progress in real time, whether they play from our campus or from your LMS, and everyone who finishes gets a certificate.

Want to see Classified in action?

Book a personalised demo: we’ll walk you through Classified and Crypt0, show you the Admin reports and work out how they fit your induction and refresher cycle.