GDPR Training Requirements: Who Needs Training and How Often?

Scott Dooley
6 min read · Aug 19, 2022 Last updated: August 3, 2026

UK GDPR does not set one universal course, format or annual timetable for every worker. But organisations need people who handle personal information to understand the safeguards that apply in their role. A proportionate programme starts with basic awareness for staff, adds role-specific learning where the risk is higher, and keeps evidence that the training was completed and works in practice.

The ICO’s training guidance is part of its accountability audit-framework control measures: it describes ways to meet the ICO’s expectations, rather than creating a new standalone legal rule. The page says it is under review following the Data (Use and Access) Act, so organisations should check the current ICO material when reviewing their programme.

What does the law say about GDPR training?

Training is relevant to accountability and security because organisations must put appropriate measures into practice, not merely write policies. The legal text does not, however, create a universal rule that every employee must take the same GDPR course each year.

Article 39: a DPO monitoring task

Where an organisation has designated a Data Protection Officer (DPO), Article 39(1)(b) includes awareness-raising and training of staff involved in processing operations within the DPO’s monitoring tasks. This does not mean every organisation must appoint a DPO, nor does it create an annual training requirement. It explains a task of a DPO where one is designated.

Article 47: a Binding Corporate Rules requirement

Article 47(2)(n) concerns Binding Corporate Rules (BCRs), a transfer mechanism used by corporate groups. In that specific setting, BCRs must include appropriate data-protection training for personnel with permanent or regular access to personal data. It should not be read as a general rule that a course alone proves compliance for every employer.

The practical question for most employers is therefore: which people use personal information, what could go wrong in their work, and what do they need to do differently? Training is one part of a wider set of accountability measures.

Who should receive data-protection training?

Start with staff who access, collect, record, share, delete or otherwise use personal information. That can include HR teams handling recruitment or absence records, customer-service staff viewing account details, marketing teams using contact lists, managers approving access, and IT teams administering systems. Temporary workers, contractors and senior staff may also need training if their role gives them access to personal information.

The ICO’s control measure is an all-staff data-protection and information-governance programme. Its suggested approach includes all-staff coverage of key areas such as requests, data sharing, information security, breaches and records management, while taking account of individual and sector-specific needs.

Use a needs-based programme

  • All staff: give a basic introduction to personal information, secure handling, recognising a possible breach, and where to get help.
  • Higher-risk roles: add practical learning for the tasks they actually perform—for example responding to requests, using marketing data, sharing information or administering systems.
  • New starters: provide induction before they access personal information, with a clear owner for checking completion.
  • Specialist roles: assess the training and professional-development needs of DPO, information-governance, records-management and subject-access teams separately.

Training should support the processes people use every day. For example, a team that receives subject access requests may benefit from a short workflow alongside training; our SAR guide explains the operational issues that such a team may need to recognise.

How often should GDPR training be refreshed?

The ICO says staff should complete refresher training at appropriate intervals. It does not prescribe an annual minimum. Choose and record an interval that fits the role, the sensitivity and volume of information handled, changes to working practices, known errors or incidents, and evidence of whether the existing training is effective.

A fixed annual schedule may be a sensible internal choice for some organisations, but it is not a UK GDPR or ICO minimum. Additional, targeted training may be appropriate when someone takes on a new responsibility, a new system changes the way personal information is handled, an assessment exposes a gap, or an internal incident shows that a control is not understood. A regular review should distinguish a material change to the organisation’s own processing from every external legal or regulatory development.

For a closer look at the regulator’s wording, see ICO refreshers. The key decision is not “annual or nothing”; it is whether the timing is justified for the risk and whether the organisation can show that staff remain able to apply the learning.

What evidence should employers keep?

The ICO’s accountability control measures say organisations should keep copies of training material and details of who received it. They also point to assessments or surveys, completion monitoring, follow-up for people who do not complete training, and staff feedback as ways to demonstrate that training is understood and monitored appropriately.

  • the programme owner, audience and training-needs assessment;
  • the version of materials used and when they were reviewed;
  • assignments, completion dates and any required follow-up;
  • assessment, survey or other effectiveness evidence; and
  • the reason for refresher intervals and any role-specific additions.

These records do not guarantee compliance, and training does not replace access controls, policies or incident handling. They do help an organisation manage its programme, spot gaps and explain the steps it has taken as part of its wider accountability arrangements.

A practical manager checklist

  • Map the roles that use personal information and identify higher-risk tasks.
  • Set a basic induction standard before access is granted.
  • Give relevant role-specific learning, not just one generic module.
  • Choose refresher intervals using risk, role, change and effectiveness evidence.
  • Monitor completion, follow up missed training and test understanding.
  • Keep materials and completion records, then review the programme periodically with relevant privacy or information-governance input.

Frequently asked questions

Is GDPR training legally required for every employee?

There is no universal UK GDPR rule prescribing the same training for every employee. The appropriate scope depends on whether the person handles personal information and the risks in their role. The ICO’s accountability control measures expect an all-staff programme and extra learning for specialist functions.

Does GDPR require annual refresher training?

No. The ICO says refresher training should take place at appropriate intervals. An employer should set an interval that it can justify by role, risk, organisational change and evidence of effectiveness.

Can online GDPR training be part of the programme?

Yes. The ICO’s control measures focus on whether staff receive suitable training, complete it and understand it; they do not prescribe one delivery format. Online learning can form part of a programme if it is appropriate for the role and supported by completion and effectiveness checks.

What should be kept on file?

Keep the materials or version used, who received training, completion and follow-up information, and evidence from assessments, surveys or feedback. Also keep the rationale for the programme and review it when roles, risks or working practices change.

Sources

Author

  • Scott Dooley is a seasoned entrepreneur and data protection expert with over 15 years of experience in the tech industry. As the founder of Measured Collective and Kahunam, Scott has dedicated his career to helping businesses navigate the complex landscape of data privacy and GDPR compliance.

    With a background in marketing and web development, Scott brings a unique perspective to data protection issues, understanding both the technical and business implications of privacy regulations. His expertise spans from cookie compliance to implementing privacy-by-design principles in software development.

    Scott is passionate about demystifying GDPR and making data protection accessible to businesses of all sizes. Through his blog, he shares practical insights, best practices, and the latest developments in data privacy law, helping readers stay informed and compliant in an ever-changing regulatory environment.

    View all posts