Why Data Protection Training Still Matters (Probably More Than Ever!) 

One of the questions I’m asked most often as a Data Protection Officer is: 

“Do we really need data protection training?” 

My answer is always the same… Absolutely! And not because the law says so. 

Don’t get me wrong – complying with UK GDPR and the Data (Use and Access) Act is important. But if data protection training is simply something you do to tick a compliance box once a year, you’re missing the bigger picture. 

The reality is that we’re asking our people to make decisions about data every single day. 

Should I email this?   Can I share this?  Is this AI tool safe to use?   Should I click that link?   Do I really need to keep this information? 

Those aren’t IT decisions. They’re people decisions.  And that’s exactly why training matters. 

Technology Can’t Do It All 

Organisations spend thousands—sometimes millions—on cyber security technology. 

Firewalls. Email filtering. Multi-factor authentication. AI detection tools.  

They’re all good and effective if applied correctly. 

But none of them can stop someone sending sensitive information to the wrong person, uploading confidential information into an AI tool without thinking, or clicking a convincing phishing email because they’re busy and distracted. 

Technology protects systems but people protect information.  Yes, that includes me and you!  

We Need to Move Beyond Compliance 

When I deliver training, I rarely start by talking about legislation. Instead, I ask people one simple question… 

“Would you trust your organisation with your own personal information?” 

It’s a question that usually gets people thinking and I always make sure when discussing elements on any course I deliver to get the attendees to think about their own data within their organisation, as this message sometimes gets forgotten about by them. Think like its your own data then you will understand why it needs protecting! 

Because data protection isn’t really about legislation. It’s about trust. 

Every customer, employee, supplier and partner is placing trust in us every time they hand over their information. Our job is to earn that trust every single day. 

AI Has Changed the Conversation 

How many times in the last week have you heard the words AI mentioned in your organisation? 

A couple of years ago, most organisations were focused on phishing emails and passwords. Now the conversation has changed. People are using AI tools every day to help them work faster. That’s fantastic……provided they understand what they should and shouldn’t be putting into those systems. 

Good training today isn’t just about GDPR. It’s about helping people make sensible decisions when using new technology, understanding the risks, and knowing when to stop and ask the question: 

“Is this actually OK?” 

Most Data Breaches Aren’t Hollywood 

When people think about cyber incidents, they often picture hooded hackers sitting in dark rooms. The reality is usually much less dramatic. It’s the email sent to the wrong recipient. The spreadsheet attached by mistake. The document left on a train. The conversation held where everyone can hear it. Or someone trying to be helpful without realising they’ve just shared information they shouldn’t. 

These are the incidents I see time and time again. And they’re exactly the sort of things good awareness training can help prevent. 

Data Protection is Everyone’s Job 

One thing I always say during training is this: The Data Protection Officer doesn’t protect data. 

Everyone does. Every member of staff makes decisions every day that either reduce risk or increase it. 

The more confident people feel, the better those decisions become. That’s why training should never be about catching people out or making them fear getting it wrong. 

It should be about giving them the confidence to stop, think and make good decisions. 

So… Is Data Protection Training Worth It? 

For me, the answer has never been clearer. Yes, it helps organisations comply with the law. Yes, it reduces risk. Yes, it supports cyber resilience. 

But perhaps most importantly, it creates a culture where people understand that protecting information is simply part of doing a good job. 

And in a world of AI, cyber threats and increasing public expectations around privacy, that’s becoming more valuable than ever. 

At OSP Cyber Academy, we believe the best training isn’t about overwhelming people with legislation or technical jargon.  

It’s about making data protection relevant, practical and engaging so that people leave feeling more confident than when they arrived. 

Because when people understand Why Data Protection Matters, they’re far more likely to make the right decisions when it counts. 

I also want you to consider the Executive and Board members in your organisation  as training and awareness for them is even more important as how can you lead a positive Data Protection Culture if your behaviour at the top is not reflected in the culture? – look out for my next blog as you wont escape just because you are a board member! 

I’d love to hear your thoughts. 

Has data protection training in your organisation evolved beyond compliance, or is it still viewed as an annual tick-box exercise? 

#DataProtection #CyberSecurity #Privacy #AIGovernance #UKGDPR #DataProtectionTraining #CyberAwareness #Leadership #Trust 

Author 

Irene Coyle, Data Protection Officer 

Shopping Basket