Staff training is one of the organisational measures GDPR expects, and it's the one most often "done" verbally and therefore unprovable. The obligation isn't to send everyone on a course - it's to make sure each person handling personal data understands the risks of their own role, and to be able to show that you did. This guide covers what to cover, by role, how to document it, and how GDPR training now overlaps with AI literacy. For the wider picture, see the GDPR compliance checklist pillar.
- Training is an organisational measure under Art. 32 and part of accountability under Art. 5.
- Tailor content to the role - marketing, HR and support face different risks.
- Undocumented training doesn't count; record content, date and participants.
Is GDPR Staff Training Mandatory?
What does the law actually require?
GDPR doesn't name a specific course, but it requires appropriate organisational measures (Art. 32) and the ability to demonstrate compliance (Art. 5 accountability). In practice, that means staff who process personal data must be competent to do so safely, and you must be able to evidence it. Authorities and enterprise clients both ask for training records, so "we talked about it once" is not enough.
What to Cover, by Role
What should each team actually learn?
| Team | Focus |
|---|---|
| All staff | Basics: what personal data is, lawful handling, reporting a suspected breach |
| Marketing | Consent, tracking, which tools may receive data |
| HR | Applicant/employee data, retention, AI-assisted screening limits |
| Sales | CRM hygiene, lawful basis for prospect data, recording disclosures |
| IT / Ops | Security measures, access control, the 72-hour breach process |
Role-specific beats generic: a salesperson needs to know which customer data may go into an AI tool, not the full text of Article 6.
How to Document Training
What records do I need?
Keep, for each session: the content covered, the date, and the participants. Add a process for repeating training when new tools are introduced or staff change roles, and assign clear accountability for keeping it current. That record is what turns "we train our people" into something an auditor accepts.
Staff Training Template & Tracker (DOCX)
GDPR Training and AI Literacy
How does this connect to the EU AI Act?
If your team uses AI tools, training now has two overlapping drivers. GDPR requires data-handling competence; the EU AI Act (Art. 4) requires AI literacy - that staff using AI systems understand their limits, risks and responsibilities. The two overlap heavily and are best delivered together: one role-based session covering both data protection and responsible AI use. See EU AI Act compliance for the AI literacy requirement in full.
ETHYX keeps your training records - GDPR and AI literacy together - in one place and flags when refreshers are due, so the evidence is there when an auditor asks.