Training and awareness

This makes sure that all employees receive appropriate training about your privacy programme, including what its goals are, what it requires people to do and what responsibilities they have. The training must be relevant, accurate and up to date. Training and awareness is key to actually putting into practice your policies, procedures and measures by:

At a glance – what we expect from you

All-staff training programme

You have an all-staff data protection and information governance training programme.

Ways to meet our expectations:

Have you considered the effectiveness of your accountability measures?

Induction and refresher training

Your training programme includes induction and refresher training for all staff on data protection and information governance.

Ways to meet our expectations:

Have you considered the effectiveness of your accountability measures?

Specialised roles

Specialised roles or functions with key data protection responsibilities (such as DPOs, subject access and records management teams) receive additional training and professional development beyond the basic level provided to all staff.

Ways to meet our expectations:

Have you considered the effectiveness of your accountability measures?

Monitoring

Your organisation can demonstrate that staff understand the training. You verify their understanding and monitor it appropriately eg through assessments or surveys.

Ways to meet our expectations:

Have you considered the effectiveness of your accountability measures?

Awareness raising

You regularly raise awareness across your organisation of data protection, information governance and associated policies and procedures in meetings or staff forums. You make it easy for staff to access relevant material.

Ways to meet our expectations:

Have you considered the effectiveness of your accountability measures?

Further reading

ICO guidance:

External guidance: