Schools have a firmer number, because the Department for Education asks for data protection training at least every two years and recommends annual training. This guide covers who needs training, what it should include, how often to run it, and the training record a school, charity or care provider should keep.
The rule: accountability, security and the DPO’s duty to train
No provision of the UK General Data Protection Regulation (UK GDPR) says “train your staff” in those words, but four articles make training the ordinary evidence of compliance. Article 5(2), the accountability principle, says “the controller shall be responsible for, and be able to demonstrate compliance with” the data protection principles. Article 24 requires “appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation”, which “shall be reviewed and updated where necessary”. Article 32(4) requires the controller to “take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller”. And where there is a data protection officer, Article 39(1)(b) makes it one of the DPO’s tasks to monitor compliance with the organisation’s policies, “including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits”.
The Information Commission’s Office turns that into practice in its accountability framework: training and awareness, the control measures its auditors look for. The first is that “there is an all-staff data protection and information governance training programme”, and the risk it names is that without one staff “will have access to personal information without fully understanding their responsibilities in its protection and security”, which “may breach articles 5(1) and 5(2) of the UK GDPR”. Article 5(1)(f), integrity and confidentiality, is the principle most often at stake: personal data must be processed “in a manner that ensures appropriate security”, using “appropriate technical or organisational measures”. Training is an organisational measure.
The ICO notes at the top of that page that, because of changes made by the Data (Use and Access) Act 2025, the guidance “is under review and may be subject to change”. The Act amends the UK GDPR and the Data Protection Act 2018 in stages, so check the date on each ICO page you use and make sure the training reflects the law as amended.
Who needs data protection training
Every employee, volunteer and trustee who handles personal data, which in practice is everyone, has a part in protecting it. The ICO’s expectation is to “deliver induction and refresher training to all staff, regardless of how long they will be working for your organisation, their contractual status or grade”. Temporary, part-time, bank and agency staff and volunteers who see personal information are in scope.
The Department for Education’s data protection guidance for schools (updated 9 July 2026) lists who that means in a school: “teaching staff, catering staff, welfare supervisors, library staff, cleaners, first-aiders, governors and trustees, volunteers”. It says “the responsibility and accountability for compliance sits with governors and trustees”, and that senior leaders are accountable for “making sure staff receive training on data protection every 2 years (we recommend annually as best practice)”.
- Schools and academy trusts: all staff, governors and trustees, and volunteers, on the DfE’s two-year minimum, with the school’s own processes for breaches and information rights requests included.
- Care providers registered with CQC: regulation 18(2)(a) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires that staff “receive such appropriate support, training, professional development, supervision and appraisal as is necessary to enable them to carry out the duties they are employed to perform”, and handling care records is one of those duties. Many adult social care providers in England also complete the Data Security and Protection Toolkit (DSPT), which Digital Care Hub describes as “the official self-assessment tool for the care sector”, to be completed “at least once a year”, and which includes training requirements.
- Charities: staff, volunteers and trustees who handle beneficiaries’, donors’ or members’ details. Trustees carry the accountability as the governing body of the controller, so their training is part of the programme, not an extra.
Some roles need more than the all-staff course. The ICO expects that “specialised roles or functions with key data protection responsibilities (such as DPOs, subject access and records management teams) receive additional training and professional development beyond the basic level provided to all staff”, with “a training needs analysis” to work out what each role needs.
What data protection training should include
The ICO expects the programme to be “comprehensive” and to include “training for all staff on key areas of data protection such as handling requests, data sharing, information security, personal data breaches and records management”, with “national and sector-specific requirements” built in. The DfE’s list of what all school staff should be aware of is a good all-sector checklist. Staff should know:
- what personal data is, and what “processing” means;
- their duties in handling personal information, and the processes for using it;
- what usage of the data is permitted;
- the risks if data gets into the wrong hands;
- their responsibilities when recognising and responding to a personal data breach; and
- the process for recognising and escalating information rights requests, such as a subject access request.
Around that core, good training covers the seven principles in Article 5 in plain language; the special categories – the most sensitive personal data, such as health, ethnicity and religion – that most schools, charities and care providers hold; who the DPO or data protection lead is and how to reach them; secure handling of paper, email, devices and working away from the office; and the organisation’s own rules on where work conversations about people may take place. The DfE adds that training should cover “specific school processes such as: personal data breach reporting processes” and “the escalation of information rights requests” – the two moments when a member of staff’s first reaction decides whether the organisation meets a legal deadline.
Generic e-learning builds knowledge of the law; it rarely covers the local process. The test is whether a cleaner, a care worker on a night shift or a volunteer could say what to do in the first ten minutes after finding a lost list of names, and to whom.
When and how often to train
At induction, before access. The ICO’s expectation is to “deliver induction training to all staff prior to accessing personal information and within one month of their start date”, and it warns that “allowing staff to begin working with personal information before undergoing induction training, greatly increases the risk of a personal data breach”.
Refreshers at appropriate intervals. The ICO says staff should “complete refresher training at appropriate intervals” and suggests setting “a specified timeframe for staff to complete refresher training”, notifying staff when it is due, and even removing access to personal information if refresher training is not completed in time. Schools have the DfE’s minimum of every two years and its recommendation of annual training. For care providers that use the DSPT, the assessment is completed at least once a year, and many set an annual refresher to match.
When something changes. A breach, a near miss, a new system, a change in the law or a pattern in the questions staff ask are all reasons to brief people before the next scheduled course. The ICO suggests using “organisational reports to feed back into training so you can address any areas of concern”.
Awareness between courses. The ICO’s last control measure is that awareness is raised “in meetings or staff forums” using “a variety of appropriate methods … for example by emails, team briefings and meetings, posters, handouts and blogs”, and that staff can easily find relevant material and “who to contact if they have any queries”.

The data protection training record
Accountability means being able to show the training happened and worked, so the record matters as much as the course. The ICO’s framework names the evidence it expects to see:
- “details of who received the training” and “copies of the training material provided”, kept on record;
- an assessment “to test staff understanding”, which “could include a minimum pass mark”;
- completion tracked “in line with organisational requirements at all levels of the organisation”, with follow-up for “staff who do not complete the training”;
- evidence that key roles complete “up-to-date and appropriate specialised training”; and
- a training programme that senior management signs off and reviews regularly.
In practice that is a register with a row per person: name, role and start date; the course or briefing, its version and date; the date completed, the assessment result and any certificate issued; the next due date; and any follow-up for a missed deadline. Keep the version of the material each person completed, so that a later question – did this person know the breach procedure in March? – can be answered from what they were actually taught. The ICO asks auditors to consider whether staff “could explain their training records”.
The record is itself personal data, so it needs a retention period in the organisation’s schedule and the same security as any other staff record. Where the organisation is a CQC-registered provider, the same register often sits alongside the regulation 18 training matrix; in a school, beside the safeguarding training record described in our safeguarding training records guide.
Where the training is tested
The course teaches staff to recognise two things: a personal data breach and a request for information. Neither usually arrives where the course said it would.
A parent messages a teaching assistant on her own phone on a Saturday: could the school send her everything it holds about her son? That may well be a subject access request: the ICO’s guidance on recognising a SAR says people “can make it to any part of your organisation, and they do not have to direct it to a specific person or contact point”, and the one-month time limit runs from receipt. In a care home, a senior carer photographs the handover sheet so the night staff have the residents’ names and medicines in the staff group chat. In a charity, a volunteer forwards a list of beneficiaries’ addresses to her own email so she can deliver food parcels from home. Each member of staff passed the module. Each first moment happened in an app the organisation does not run, and none of it reaches the breach log or the request log unless the person who saw it remembers the training and acts on it.
Training cannot fix where people talk; it can only tell them what to do once they notice. The training record shows the course was completed. Whether the organisation can show what happened next depends on where those first messages land. A question for the next leadership or board meeting: when a member of staff reports a possible breach or passes on a request for information, which channel does it arrive through, and would the organisation hold that message if the ICO asked?
Questions people ask
How often should staff do GDPR training?
UK law sets no fixed interval for data protection training: the ICO expects induction training before staff access personal information and within one month of starting, then refresher training “at appropriate intervals” set by the organisation. The Department for Education asks schools for data protection training at least every two years and recommends annual training, and many care providers and charities choose to refresh annually.
What should data protection training include?
Data protection training should cover, in the ICO’s words, “handling requests, data sharing, information security, personal data breaches and records management”, along with what personal data is, the data protection principles, the organisation’s own procedures and who to contact. Staff in specialist roles such as the DPO or the team handling subject access requests need additional, role-specific training.
What are the 7 key principles of data protection?
The seven principles in Article 5 of the UK GDPR are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability. Article 5(2) makes the controller responsible for, and able to demonstrate, compliance with the other six, which is why training records matter.
Where can employees get free GDPR training?
Free data protection training material is available from the ICO, which publishes guidance and resources for organisations; from the Department for Education, which offers training videos and posters for schools on its data protection in schools pages; and, for adult social care, from Digital Care Hub’s free data security e-learning, which it says will help care organisations meet the training requirements in the Data Security and Protection Toolkit.
Is data protection training a legal requirement?
The UK GDPR does not name training as a standalone duty, but it requires appropriate organisational measures to keep data secure and to demonstrate compliance (Articles 5, 24 and 32), and the ICO treats an all-staff training programme as one of the measures it expects. For CQC-registered care providers, regulation 18 also requires staff to receive the training necessary for their duties.
Official guidance and your next step
The primary sources are the ICO’s accountability framework on training and awareness, Articles 5, 24, 32 and 39 of the UK GDPR on legislation.gov.uk, the Department for Education’s data protection in schools: responsibilities, and, for care, regulation 18 and the Digital Care Hub’s DSPT guidance. Each is being updated for the Data (Use and Access) Act 2025; check the date on the page.
This guide is a general summary for organisations in the UK, not legal advice. Your data protection officer, if you have one, should sign off the training programme.
Then do one thing: pick three people at random – one new starter, one volunteer or bank worker, one long-serving member of staff – and check the training record shows, for each, what they completed, when, and the assessment result. If any one of them is missing, that is the gap to close before the next refresher.
We build ComplyChat for the work conversations organisations need to keep, which is where data protection questions and breach reports often first appear. It does not deliver training or keep a training register. It is a channel for work conversations where everyone added is told it is on the record and messages are stored and processed in the UK; on paid plans, once your Microsoft 365 tenant is connected, the lasting record files there under your own retention rules.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Article 24 legislation.gov.uk
- Article 32(4) legislation.gov.uk
- Article 39(1)(b) legislation.gov.uk
- Accountability framework: training and awareness ico.org.uk
- Data protection guidance for schools gov.uk
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
- Digital Care Hub digitalcarehub.co.uk
- Guidance on recognising a SAR ico.org.uk




