Your Data Protection Training Pathway

GDPR schools cyber security online

Why is DATA training so important?

Data protection training and certification has accelerated in growth and demand since the GDPR was enforced in 2018, bringing with it huge fines and penalties for companies that breach the law.
It’s critical that employers, training providers, and professionals recognise the importance of keeping skills in this area up to date and relevant. Breaches cannot only affect financially, in penalties, but can also affect the brand of an organisation.

  • Protect your business. 
  • Reduce human error.
  • Demonstrate to your customers that you care.
  • Change staff behaviour.
  • Promote a data protection culture. 
  • Reduce the likeliness of you falling subject to fines. 
  • Minimise potential data breaches.

The GDPR is:“…about moving away from seeing the law as a box ticking exercise, and instead, to work on a framework that can be used to build a culture of privacy that pervades an entire organisation.”

What training should my staff have?

All staff members that are involved in the processing of personal data should have adequate awareness training about data protection, and information security. For example, a sales team member has access to customers account details; email address, name, address etc. That team member would require a basic level of understanding. This can be facilitated with our online eLearning, or a virtual or onsite 2-4 hour Data Protection Awareness training session

We would advise that those team members that have access to sensitive information, use personal information on a daily basis or are team managers should have a further understanding of data protection. They should be able to recognise a subject access request & the appropriate response, understand when, and why a data protection impact assessment needs to be completed, how to handle a data breach and so on. This can be facilitated with our onsite or online 1 day Data Protection Foundation Course. 

 For those team members that work in data protection and privacy, information governance, risk and compliance, data management, project management, legal and procurement, marketing, information security and human resources. We would advise them to do our BCS, The Chartered Institute for IT, Foundation Certificate in Data Protection Course. This will ensure that your employees are better placed to support your organisation process customer data – in compliance with the GDPR and the Data Protection Act (2018).

Further to the above list of departments that could require supplementary training, those professionals who have, or wish to have, some responsibility for the compliance of data protection within an organisation, and need to understand the changes that the GDPR and the UK Data Protection Act 2018 will bring to data protection legislation, and what needs to be done to prepare their organisations for compliance – should hold the BCS, The Chartered Institute for IT, Practitioner Certificate in Data Protection.

Those assigned the role of the Data Protection Officer or Deputy Data Protection Officer should work towards the CPD Role of the DPO accredited course. This course will ensure that those team members become an expert in data protection, are adequately resourced (free tools throughout the course), and understand how to remain independent and avoid conflicts of interest. 

Our Accredited Training Pathway

How much does it cost?

We understand that times are difficult for businesses at the moment, due to Covid-19. We can offer either out of the box courses, or courses designed specifically with your organisation in mind. 

Current prices are as follows and based on the organisation purchasing the training for the time / days specifed:

Online tutor led – Data Protection Awareness Session – 3 hours (up to 20 staff per session) – from £500 

Online tutor led – Data Protection Foundation Course – 1 day (up to 15 staff per course) – from £1,000

Online or classroom based – BCS Foundation Certificate in Data Protection – 3 days – (up to 8 staff per course) – from £6,000

Online or classroom based – BCS Practitioner Certificate in Data Protection – 4 days – (up to 8 staff per course) – from £8,000

If you would like to send individual employees onto one of our arranged courses, please see https://www.dataprivacyadvisory.com/dpas-training/upcomingevents/ for current course dates and prices. Alternatively, get in touch.

related posts

Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »

Get a Free Consultation