Most data protection problems don’t start with a rogue IT system or a sophisticated cyberattack. Instead, they start with someone forwarding an email to the wrong person, sharing a spreadsheet with more columns than intended, or not knowing what to do when a colleague asks for a customer’s details.
Your staff are handling personal data every day. Many may not realise this. And without offering clear, practical data protection awareness training, even well-meaning employees can create serious compliance problems.
This article cuts through the jargon to explain what your team actually needs to understand – and the specific moments when the risk is highest.
Why GDPR is everyone’s responsibility – not just the data team’s
It’s tempting to treat the General Data Protection Regulation (GDPR) as an issue for legal, IT, or a designated data protection officer. But in reality, it’s often a lot less clear.
Personal data moves through your organisation constantly. HR holds employee records. Customer-facing teams process contact details. Managers handle sensitive information about performance or health. Every one of those touchpoints is a potential liability if the person involved doesn’t know the rules.
The good news is that most of these risks are preventable. Staff don’t need to become data protection experts; they simply need to understand the basics well enough to make the right call in the moment.
What “handling data” means for your team
Before you can train people on GDPR compliance, they need to understand what counts as personal data.
Personal data includes:
- Names, email addresses and phone numbers
- Employee records and payroll information
- Customer purchase history or service interactions
- IP addresses and device identifiers
- Anything that could directly or indirectly identify a living person
Once your team understands what they’re dealing with, the next step is understanding the basic principles that govern how it should be handled. Under UK GDPR, personal data must be:
- Collected for a clear, lawful purpose
- Not kept longer than necessary
- Kept accurate and up to date
- Stored securely and accessed only by those who need it
These aren’t abstract legal requirements. They translate directly into everyday decisions: who you cc on an email, how long you keep a record, whether you leave a screen unlocked in a shared space.
ICO data shows that 77% of incidents reported from October-December 2025 were non-cyber – meaning they didn’t involve a deliberate external attack. Human error is often a key factor in these breaches – which is where GDPR compliance training in the workplace makes the biggest difference.
💡 Want to make sure your team is fully covered on data protection? Our GDPR in the Workplace Certification gives employees a clear, practical grounding in UK GDPR – what it means for their role, and how to apply it day to day. You can try it free for 14 days.
The data requests your team can’t afford to mishandle
Subject access requests – or SARs – are one of the most commonly mishandled areas of GDPR in the workplace. Under UK GDPR, individuals have the right to request a copy of any personal data your organisation holds about them. Your team has one month to respond.
That sounds straightforward, but in practice many organisations struggle because:
- Staff don’t recognise a SAR when they receive one (it doesn’t need to say “subject access request” to be one)
- Requests aren’t logged or escalated in time
- Responses include more data than they should – or less
In December 2024, the ICO reprimanded United Lincolnshire Teaching Hospitals NHS Trust for failing to respond to 32% of subject access requests within the statutory timeframe. The root cause wasn’t bad intent – it was inadequate systems and a lack of staff awareness.
Your employees don’t need to know every nuance of data law. But they do need to know what a SAR looks like, who to tell when one arrives, and why the deadline matters. That’s the kind of practical knowledge that makes all the difference when a request lands on someone’s desk.
The shared spreadsheet problem – and other everyday risks
Here’s a scenario that plays out across UK organisations regularly. Someone builds a spreadsheet to track customer orders; over time, it gets added to; eventually it contains names, addresses, health preferences, payment notes and more. It’s saved on a shared drive. 30 people have access. No one’s sure who added which rows, or whether the data should still be there.
That spreadsheet is a data protection problem waiting to happen.
The everyday mistakes that create the most risk include:
- Sending emails to the wrong recipient – particularly easy on autocomplete, and one of the most reported breach types
- Oversharing in attachments – sending a full dataset when only a subset was needed
- Using personal devices for work data – without the same security controls as company equipment
- Keeping data “just in case” – holding onto records far beyond any legitimate purpose
- Verbal disclosure – discussing a client’s or colleague’s details in a public or semi-public space
None of these are acts of negligence in the traditional sense. They happen because staff haven’t been given a clear framework for thinking about data – and that’s something the right training can help put in place.
Making GDPR training land with non-specialist staff
The biggest challenge with data protection awareness training for staff isn’t the content – it’s getting people to engage with it.
GDPR has a reputation for being dry and impenetrable. Most employees have sat through a long policy read-through and retained very little. The training that works is the training that connects the rules to real situations your team encounters.
What effective GDPR training for employees in the UK should do:
- Explain what GDPR is clearly and in an accessible way
- Explain the main principles of GDPR
- Highlight GDPR risks and penalties of non-compliance
- Include an assessment so you can evidence completion
That last point matters more than many employers realise. If the ICO investigates a breach, demonstrating that your team received appropriate training is a key part of showing you took your responsibilities seriously.
In 2024/25, the ICO received over 42,300 data protection-related complaints – an increase of around 2,500 on the previous year. The pressure on organisations to show they’re doing the right things isn’t going away.
Getting your team up to speed
GDPR doesn’t have to be complicated for the people who aren’t data specialists. They just need to know enough to recognise a risk, make the right call, and escalate when they’re unsure. That’s achievable with the right training.
The question worth asking isn’t, “Do we have a GDPR policy?” It’s, “Does every person who touches personal data in our organisation know what to do – and what not to do – in the moments that matter?”
If the answer isn’t a confident yes, that’s where to start.
Ready to train your team?
Staff Skills academy+ gives your team access to 750+ Continuing Professional Development (CPD)-certified courses – including the GDPR in the Workplace Certification. Start a free 14-day trial today or speak to our team about what works for your organisation.