“Are your staff trained in data protection — and can you prove it?” That question does not come from the supervisory authority first. It sits in your biggest customer's supplier questionnaire, in your insurer's audit plan, and in the room after every breach. You will search the GDPR in vain for a literal training duty — and still there is no way around training. The reason is called accountability.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
The GDPR nowhere says “train your staff”. It says something more effective: the controller must implement appropriate measures and be able to demonstrate compliance (Art. 5(2), Art. 24), and must take technical and organisational measures appropriate to the risk (Art. 32). Staff who missend customer data, miss phishing attempts or paste customer lists into open AI tools are a risk — and training is the organisational measure against it. Where a DPO is appointed, awareness-raising is expressly among their tasks (Art. 39(1)(a)).
The takeaway: training is not mandatory as a word, but as a measure — and its record certainly is, via accountability.
“We did something at some point” does not count. A record that survives questionnaires and audits is personal and verifiable:
| Feature | Why |
|---|---|
| Per person, with name and date | Blanket claims (“the team was trained”) cannot be checked |
| Named contents | The auditor wants to see WHAT was trained — basics, data subject rights, breach handling, safe working |
| Assessment with a result | Attendance is not competence; a quiz with a pass mark comes closer |
| Publicly verifiable | Anyone can print a PDF — a check-ID resolving to a database record, not |
| Expiry and refresher | Privacy knowledge ages; an annual refresher is the accepted rhythm |
A “GDPR certification” of employees or companies within the meaning of the regulation can only be issued by accredited certification bodies under Art. 42/43 — and those schemes certify processing operations, not people. Whoever sells you a “GDPR certificate” that makes your company “GDPR-compliant” is selling a wording the seller cannot grant. The honest product is the training record: “trained in GDPR-compliant working, with assessment” — claiming no more than was delivered, and exactly what accountability demands.
An effective baseline training for all staff needs no seminar day: core concepts and accountability, the ground rules (legal basis, purpose limitation, data minimisation), recognising and forwarding data subject requests, the breach and the 72-hour reflex, safe day-to-day working (passwords, phishing, screens, home office) — and the company's own rules: which tools are approved, who the contact person is. That last part matters most and is what off-the-shelf trainings miss.
Our data protection training (about 35–45 minutes per person) ends in a training record with a publicly verifiable ID — per person, with contents, result and 12 months validity. The company module pulls your real rules and your named contact from your audit file automatically. Included from the Team Plus plan; an add-on for Starter and Team. The free 2-minute check shows where you stand.
Not as a literal duty — but as an organisational measure under Art. 24 and 32 GDPR whose observance the company must be able to demonstrate under Art. 5(2). In practice, supervisory authorities, business customers and insurers ask for the training record routinely.
No. Certifications under Art. 42 GDPR are issued only by accredited bodies — and they cover processing operations, not people. For staff there is the training record: personal, with contents, assessment and a verifiable ID.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free