Regulation and standard

What does GDPR require for staff training and awareness?

Short answer

The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) has no single article requiring every employee to be trained. Training is required indirectly: controllers must implement appropriate measures and be able to demonstrate compliance (Articles 5(2) and 24), staff may process personal data only on instructions (Articles 29 and 32(4)), the data protection officer monitors awareness raising and training (Article 39), and binding corporate rules must include training (Article 47).

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
7 min
Jurisdiction
European Union
Regulator
National data protection supervisory authorities in each Member State, coordinated by the European Data Protection Board (EDPB)

Key takeaways

  • The GDPR has applied since May 25, 2018 as a directly applicable EU regulation; it names staff training explicitly only in Articles 39 and 47.
  • Accountability (Article 5(2)) and controller responsibility (Article 24) mean organizations must be able to demonstrate compliance, and training records are a standard part of that evidence.
  • Articles 29 and 32(4) require that people with access to personal data process it only on the controller's instructions, which is hard to show without training.
  • Infringing Articles 25 to 39 can attract fines of up to EUR 10 million or 2% of worldwide annual turnover; breaches of the core principles, up to EUR 20 million or 4%.
  • The European Data Protection Board's guide for small businesses names awareness sessions and regular procedure updates as organizational security measures.

Does GDPR require staff training, as at September 2026?

Yes, in effect, although no article says "train all staff". As at September 2026, the GDPR makes training a practical necessity through its accountability and security duties, and names staff training explicitly in two places: the tasks of the data protection officer (DPO) and the content of binding corporate rules.

The GDPR is an EU regulation, so the same text applies directly in every Member State from May 25, 2018 (Article 99). That differs from an EU directive, which each country must transpose into its own law. Member States can still add national rules in areas the GDPR leaves open, such as employment data, so a multinational should check the national law of each country where it employs people.

Which GDPR articles create a training obligation?

Six provisions together create the expectation that people who handle personal data are trained. Two mention training by name; the others require outcomes that an untrained workforce cannot reliably deliver.

GDPR provisions that drive staff training
ArticleWhat it requiresWhy training follows
Article 5(2) AccountabilityThe controller is responsible for, and must be able to demonstrate, compliance with the data protection principlesTraining records are part of the evidence that principles such as data minimization and security are applied in practice
Article 24 Responsibility of the controllerAppropriate technical and organizational measures, reviewed and updated where necessary, including data protection policies where proportionateA policy that staff do not know is not an effective measure
Articles 29 and 32(4)Anyone acting under the authority of the controller or processor who has access to personal data processes it only on instructionsStaff must be told what the instructions are and understand them
Article 28(3)(b)Processors ensure persons authorized to process personal data have committed to confidentialityConfidentiality commitments are usually made and refreshed through onboarding and training
Article 39(1)(b)The DPO monitors compliance, including "awareness-raising and training of staff involved in processing operations"Training is named as something the DPO checks, so it is expected to exist
Article 47(2)(n)Binding corporate rules must specify "the appropriate data protection training to personnel having permanent or regular access to personal data"Groups using binding corporate rules for international transfers must run and evidence this training

What is the data protection officer's role in training?

The DPO informs and advises staff and monitors whether awareness raising and training happen; the DPO is not required to deliver the training personally. Article 39(1)(a) requires the DPO to inform and advise the controller or processor "and the employees who carry out processing" of their obligations. Article 39(1)(b) adds monitoring of "awareness-raising and training of staff involved in processing operations, and the related audits".

Article 38(2) also requires the organization to give the DPO the resources needed to maintain their expert knowledge, which means the DPO's own continuing professional development is a GDPR matter. Because the DPO reports to the highest management level (Article 38(3)), training coverage and results are a natural item in the DPO's board reporting. See how to report training compliance to the board.

How does training relate to security and personal data breaches?

Training is one of the organizational measures that Article 32 expects for the security of processing. The European Data Protection Board's data protection guide for small business states that it is essential to make employees who handle personal data aware of the privacy risks, the measures taken to address them, and the potential consequences of failure.

The EDPB guide lists awareness sessions, regular updates on procedures relevant to each role, and internal communications such as email reminders as ways to raise awareness. It also recommends information security training and awareness sessions with periodic reminders, and confidentiality agreements or clauses with employees. Breaches can start with simple human error, such as a misdirected email or a lost device, so incident recognition and the internal reporting route are core content, because Article 33 requires notification to the supervisory authority within 72 hours of the controller becoming aware of a notifiable breach.

What are the penalties for getting it wrong?

Failing to train is not a separate offense, but it can contribute to infringements that carry the GDPR's two fine tiers under Article 83. Infringements of the controller and processor obligations in Articles 25 to 39 can attract fines of up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)).

Infringements of the basic principles in Articles 5, 6, 7 and 9, data subject rights, or international transfer rules can attract up to EUR 20,000,000 or 4% of worldwide annual turnover, whichever is higher (Article 83(5)). When a supervisory authority investigates an incident, evidence that staff were trained and that training was current is relevant to how it views the organization's measures.

How should a GDPR training program be structured?

A defensible program has a baseline for everyone with access to personal data and deeper modules for roles with specific GDPR duties. The mapping below is illustrative, not a legal minimum; it shows how each obligation can become a testable learning outcome and a record.

Illustrative mapping: GDPR obligation to learning outcome to assessment evidence
ObligationAudienceLearning outcomeAssessment evidence
Articles 29 and 32(4): process only on instructionsAll staff with access to personal dataApplies the organization's data handling rules to everyday tasksScenario quiz results and policy acknowledgment
Article 33: breach notification within 72 hoursAll staff; incident team in depthRecognizes a personal data breach and reports it internally without delayScenario results; incident team exercise records
Articles 12 to 22: data subject rightsCustomer service and HR teamsIdentifies an access or erasure request in any form and routes it correctlyObserved handling or case review sign off
Article 35: data protection impact assessmentProject managers and product ownersRecognizes when a DPIA is required and involves the DPOProject gate records showing DPIA screening
Article 47(2)(n): binding corporate rulesPersonnel with permanent or regular access to personal data in the groupApplies the group's transfer rulesCompletion and assessment records retained for BCR review

Link each module to an entry in a compliance obligations register, and set refresh cycles by risk, as described in how to set mandatory training refresh cycles. The GDPR does not set a frequency, so the organization's own policy should state and justify one.

What evidence should an organization keep?

Keep evidence that shows who was trained, on what version of the content, when, and whether they understood it. Because Article 5(2) places the burden of demonstrating compliance on the controller, the absence of records is itself a weakness.

  • A training needs analysis linking roles to GDPR obligations.
  • Content versions with dates, updated after policy changes, new guidance or incidents.
  • Per person completion and assessment results, including contractors.
  • DPO monitoring reports on training coverage and results (Article 39(1)(b)).
  • Records of policy attestation and confidentiality commitments.

Preparing these records is covered in how to prepare training records for an audit.

How does Knowledge Foundry approach this?

Knowledge Foundry maps GDPR articles to role based concepts and assessment points before content is written, so every module traces to the obligation it serves. When a policy or regulator guidance changes, the affected concepts and learners can be identified from the map rather than by reviewing the whole library.

Frequently asked questions

How often does GDPR require staff training?

The GDPR does not set a frequency. Article 24 requires measures to be reviewed and updated where necessary, and the EDPB recommends periodic reminders. Many organizations train at onboarding and annually, with extra briefings after incidents or policy changes, and record the reasoning in their training policy.

Does GDPR training apply to contractors?

Articles 29 and 32(4) cover any natural person acting under the authority of the controller or processor who has access to personal data, which can include contractors and temporary staff. Organizations either train them directly or require equivalent training by contract and check the evidence.

Must the data protection officer deliver the training?

No. Article 39(1)(b) makes monitoring of awareness raising and training a DPO task, and Article 39(1)(a) requires the DPO to inform and advise employees. Delivery can sit with HR, compliance or learning teams, but the DPO should be able to see coverage and results.

Does GDPR apply to organizations outside the EU?

It can. Article 3 extends the GDPR to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior there. Such organizations should train the staff who handle that personal data to the same standard.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), Official Journal of the European Union (EUR-Lex)
  2. Data protection guide for small business: Secure personal data, European Data Protection Board
  3. Data protection, European Commission

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.