General Data Protection Regulation (GDPR)
Data protection relates to how all organisations collect, use, and store personal and sensitive data. That includes the government, companies, service providers and anyone who manages data.
Data protection legislation, which includes the General Data Protection Regulation (GDPR), aims to help prevent data misuse and inflicts penalties on those in breach of the law.
Our Data Protection Online Training Course will help your employees understand what personal and sensitive data are, why they need protection, and how to comply with the GDPR.
-
30 Minutes
-
For all staff
-
Global
-
Global Compliance Library
What you’ll learn in
this course
- Distinguish between non-personal, personal and special category ('sensitive') data
- Recognise how our Company complies with the General Data Protection Regulation (GDPR) and other data protection legislation
- Take appropriate action to safeguard personal and special category data
- Identify how and when to report breaches
Hear from our customers
We've been using Skillcast for approx. 1.5 years and have been very happy with the service received and the courses offered. The customer service from the support team is excellent, they always respond quickly and are very helpful. The courses offered cover a broad range and the FCA courses were particularly useful to our business.
Feefo Customer Rating ★★★★★ 4.9/5
Ready to try this course?
Start your free trial of this course and get instant access today.
Want to explore more courses?
Browse all courses and search by topic to find what matters most to you.
The importance of keeping your data governance on track
GDPR Subject Access Requests
Individuals have the right to access their personal data and organisations must respond to subject access requests (SARs) within legal timeframes.
GDPR Individual Rights
The General Data Protection Regulation (GDPR) grants individuals eight specific rights over their personal data, ensuring transparency and control.
GDPR International Transfers
The international transfer of personal data is restricted to ensure individuals' privacy rights are protected when data is sent abroad.
GDPR Legitimate Interests
Legitimate interests is a flexible lawful basis for processing personal data, but it requires balancing business needs with individuals' rights.
GDPR Lawful Bases for Processing
The General Data Protection Regulation (GDPR) requires organisations to have a lawful basis for processing personal data, chosen from six legal grounds.
GDPR and Consent
Consent is one of the six lawful bases for processing personal data under the GDPR, requiring individuals to give clear, informed and voluntary agreement.
GDPR Principle 7
The seventh principle of the GDPR, accountability, requires organisations to take responsibility for compliance and demonstrate good governance in data protection.
GDPR Principle 6
The sixth principle of the GDPR, integrity and confidentiality, requires that personal data be protected against unauthorised access, loss or damage.
GDPR Principle 5
The fifth principle of the GDPR, storage limitation, requires that personal data be retained only for as long as necessary for its intended purpose.
GDPR Principle 4
The fourth principle of the GDPR, accuracy, requires that personal data must be correct, up to date and not misleading.
GDPR Principle 3
The third principle of the GDPR, data minimisation, requires that personal data collected must be adequate, relevant and limited to what is necessary.
GDPR Principle 2
The second principle of the GDPR, purpose limitation, requires that personal data be collected for specified, explicit and legitimate purposes.
GDPR Principle 1
The first principle of the GDPR requires that personal data must be processed lawfully, fairly and transparently.
Special Category Data
In many workplaces, sensitive data, including special category data, is collected and requires extra care.
Controllers and Processors
The differences between data controllers and data processors are crucial to understanding data protection obligations.
Data Protection Impact Assessments
Data Protection Impact Assessments (DPIAs) are used to evaluate our data processing activities and mitigate risks to individuals.
Personal Data Breaches
Personal data breaches can occur through hacking, human error or unauthorised access, leading to serious legal and reputational consequences.
Understanding the GDPR
The General Data Protection Regulation (GDPR) sets out key principles for handling personal data and protecting individuals' rights.
Our LMS or yours?
Award-winning LMS
Leverage the award-winning Skillcast Portal to deliver your compliance training, track performance with analytics, and access compliance tools to support and strengthen your compliance programme.
Skillcast Remote Services
If you prefer to use your own LMS, we offer flexible pricing plans and delivery options to suit your unique needs, from off-the-shelf course libraries to fully bespoke solutions.
Your questions, answered
Data Protection (GDPR)
Where can I track incidents involving personal data?
How can I ensure that employees formally attest to our internal Data Protection Policy?
What makes a password secure?
What is a passphrase, and is it better than a password?
How can organisations help staff manage secure passwords?
What exactly must be included in a DSAR response under GDPR?
- Purposes of processing
- Types of personal data involved
- Recipients of data (including third countries)
- Retention period or criteria
- Data source (if not collected directly)
- Rights to rectification, erasure, restriction, or to object
- Right to lodge a complaint with a supervisory authority
- Automated decision-making logic and consequences
Can I ask for identification before fulfilling a DSAR?
How is the one-month response deadline calculated precisely?
When and how can the response deadline be extended?
A controller can extend the deadline by up to two months if the request is complex or the data subject has submitted multiple rights requests simultaneously (e.g., access, erasure, portability). However, the extension must be issued within the initial one-month period, providing reasons for the delay.