KlarComply
HomeKnowledge › GDPR staff training

GDPR staff training: what is truly required, what a record must offer — and how to spot snake oil

“Are your staff trained in data protection — and can you prove it?” That question does not come from the supervisory authority first. It sits in your biggest customer's supplier questionnaire, in your insurer's audit plan, and in the room after every breach. You will search the GDPR in vain for a literal training duty — and still there is no way around training. The reason is called accountability.

By , Founder of KlarComply · Reviewed on

Infographic: GDPR staff training: what a record must offer — No literal duty in the law — and still no way around it.
The key points of this article as a graphic — feel free to share or download it.

The legal basis: no literal duty, but three roads leading there

The GDPR nowhere says “train your staff”. It says something more effective: the controller must implement appropriate measures and be able to demonstrate compliance (Art. 5(2), Art. 24), and must take technical and organisational measures appropriate to the risk (Art. 32). Staff who missend customer data, miss phishing attempts or paste customer lists into open AI tools are a risk — and training is the organisational measure against it. Where a DPO is appointed, awareness-raising is expressly among their tasks (Art. 39(1)(a)).

The takeaway: training is not mandatory as a word, but as a measure — and its record certainly is, via accountability.

What a usable training record contains

“We did something at some point” does not count. A record that survives questionnaires and audits is personal and verifiable:

FeatureWhy
Per person, with name and dateBlanket claims (“the team was trained”) cannot be checked
Named contentsThe auditor wants to see WHAT was trained — basics, data subject rights, breach handling, safe working
Assessment with a resultAttendance is not competence; a quiz with a pass mark comes closer
Publicly verifiableAnyone can print a PDF — a check-ID resolving to a database record, not
Expiry and refresherPrivacy knowledge ages; an annual refresher is the accepted rhythm

How to spot snake oil

A “GDPR certification” of employees or companies within the meaning of the regulation can only be issued by accredited certification bodies under Art. 42/43 — and those schemes certify processing operations, not people. Whoever sells you a “GDPR certificate” that makes your company “GDPR-compliant” is selling a wording the seller cannot grant. The honest product is the training record: “trained in GDPR-compliant working, with assessment” — claiming no more than was delivered, and exactly what accountability demands.

What belongs in it — 35 to 45 minutes suffice

An effective baseline training for all staff needs no seminar day: core concepts and accountability, the ground rules (legal basis, purpose limitation, data minimisation), recognising and forwarding data subject requests, the breach and the 72-hour reflex, safe day-to-day working (passwords, phishing, screens, home office) — and the company's own rules: which tools are approved, who the contact person is. That last part matters most and is what off-the-shelf trainings miss.

How KlarComply does it

Our data protection training (about 35–45 minutes per person) ends in a training record with a publicly verifiable ID — per person, with contents, result and 12 months validity. The company module pulls your real rules and your named contact from your audit file automatically. Included from the Team Plus plan; an add-on for Starter and Team. The free 2-minute check shows where you stand.

Frequently asked questions

Is GDPR training for staff legally required?

Not as a literal duty — but as an organisational measure under Art. 24 and 32 GDPR whose observance the company must be able to demonstrate under Art. 5(2). In practice, supervisory authorities, business customers and insurers ask for the training record routinely.

Is there an official GDPR certification for employees?

No. Certifications under Art. 42 GDPR are issued only by accredited bodies — and they cover processing operations, not people. For staff there is the training record: personal, with contents, assessment and a verifiable ID.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → US tools & transfers →
Sources:
Article 5 GDPR — principles, para. 2: accountability
Article 32 GDPR — security of processing
Article 42 GDPR — certification (accredited bodies only)
Reviewed on 1 September 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.