Introducing GDPR
Course Overview
This course is designed for front line data processors and provides a clear introduction to the main elements of the GDPR, including compliance and the consequences of non-compliance. It explains the roles of key players and covers the main categories of personal data and the lawful basis for data processing. Other topics examined include the main Principles of the GDPR and the Rights for Individuals, along with the importance of your Privacy Policy. Finally, there's important information on data breaches; how to avoid them, what to do if one is discovered and how to file a breach report
Course Content
Since the UK left the EU, UK organisations are governed by UK GDPR, retained under the Data Protection Act 2018, rather than the EU version directly. Both frameworks share the same core principles and structure, but this course has been updated to reflect the UK-specific legal position rather than treating GDPR as purely an EU regulation.
The course explains the roles of Data Protection Officers, Data Controllers, Data Protection Leads and Data Processors, so staff understand who does what and who they should escalate a query or concern to.
UK GDPR training online covers the six lawful bases that allow an organisation to process personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Understanding which basis applies to a given activity is central to lawful data handling.
The course covers the seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
This GDPR e-learning course covers the eight rights individuals have over their data: the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights related to automated decision-making and profiling.
The course explains what qualifies as a personal data breach, covering accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Where a breach is likely to result in a risk to individuals, organisations must report it to the Information Commissioner's Office within 72 hours of becoming aware of it. This GDPR staff training course explains what needs to be included in that report and who within an organisation is responsible for making it.
The course also covers the importance of a clear privacy policy, how to construct one, and how to use it effectively when dealing with data subjects.
There's no single law that names GDPR training itself as mandatory, but UK GDPR requires organisations to ensure staff handling personal data are appropriately trained and aware of their obligations. Regulators expect this as part of demonstrating accountability, so in practice GDPR awareness course online training is the standard way organisations meet this expectation.
This course is designed for front-line staff who regularly handle personal data as part of their role, rather than specialist Data Protection Officers, who typically need more advanced training.
Course Duration
60 mins
Course Certification
Approved by CPD