Data Protection Training

Your Team Handles Personal Data Every Day.
Do They Know the Rules?

UK GDPR places legal obligations on every person in your organisation who handles personal data — not just your DPO or IT team. Aursec's data protection training gives your whole team the knowledge they need to handle data correctly, recognise risks, and keep your organisation compliant.

£17.5m Maximum UK GDPR fine
72hrs To report a data breach to the ICO
Live Virtual delivery, no travel needed
UK GDPR Focused
Plain English — No Legal Jargon
All Levels Covered
One-Off or Annual Programme

Data Protection Isn't Just a Legal Requirement —
It's Everyone's Responsibility

Most data protection failures don't happen because of malicious intent. They happen because staff don't know the rules, don't recognise a breach when it happens, or don't know what to do when something goes wrong.

£17.5m

Maximum Fine Under UK GDPR

The ICO has the power to fine organisations up to £17.5 million or 4% of global annual turnover for serious breaches. Most enforcement action follows incidents that proper training would have prevented.

72 Hours

To Report a Breach to the ICO

When a personal data breach occurs, organisations have 72 hours to notify the ICO. Staff who don't recognise a breach — or don't report it internally — make that deadline impossible to meet.

39%

of UK Businesses Reported a Breach or Attack in the Last Year

Data breaches are not rare events. Staff who understand their obligations and know how to respond are your first and most important line of defence.

Practical Data Protection Training
Grounded in UK Law

Every session is delivered in plain English — no legal jargon, no dense policy documents. Real scenarios, practical guidance, and clear actions your team can apply immediately.

UK GDPR Fundamentals

What UK GDPR is, why it exists, what it requires of your organisation, and what the consequences of non-compliance look like in practice. The foundation every member of staff needs before anything else.

Lawful Basis for Processing

The six lawful bases under UK GDPR, when each applies, and how to identify the correct basis for the data your organisation processes. Particularly relevant for marketing, HR, and customer data handling.

Data Subject Rights

The rights individuals have over their personal data — access, erasure, rectification, portability, and objection. How to recognise a rights request and what your organisation is required to do when one arrives.

Data Breaches & Reporting Obligations

What constitutes a personal data breach, how to recognise one, the internal reporting process, and when and how to notify the ICO and affected individuals. The 72-hour clock starts when your organisation becomes aware — not when it's confirmed.

Privacy by Design

Building data protection into processes, systems, and products from the start — not bolted on afterwards. Relevant for anyone involved in designing processes, services, or technology that handles personal data.

Records of Processing Activities

What a ROPA is, why it's required, what it needs to contain, and who in your organisation is responsible for maintaining it. Practical guidance on building and keeping a ROPA current.

International Data Transfers

The rules governing transfers of personal data outside the UK, what safeguards are required, and how to identify when a transfer is happening — including transfers via cloud services and third-party suppliers.

Live, Virtual, and Tailored
to Your Organisation

Data protection training works best when it reflects your organisation's actual data — the systems you use, the data you hold, and the scenarios your team faces. Every Aursec session is tailored accordingly.

Format 1
One-Off Session

Ideal for: Annual compliance refresh, new starter induction, or responding to a specific incident or audit finding.

What's included
  • 60–90 minute live virtual session
  • Up to 25 participants
  • Tailored to your sector and data processing activities
  • Q&A included
  • Attendance record provided

Per-person pricing available — contact us for a quote.

Format 3
Annual Programme

Ideal for: Businesses needing documented annual training for compliance purposes — DSPT, ISO 27001, or ICO accountability requirements.

What's included
  • Regular sessions throughout year
  • Topics refreshed as legislation and guidance evolves
  • Annual completion report and attendance records
  • Evidence formatted for DSPT and ISO 27001 requirements
  • Priority scheduling

Annual pricing available — contact us for a quote.

Different Training for
Different Roles

Data protection obligations vary significantly by role. A receptionist handling patient enquiries needs different training to a DPO managing a ROPA. We tailor every session accordingly.

All Staff — Fundamentals

The baseline every employee needs — what personal data is, why it matters, how to handle it correctly, and what to do if something goes wrong. Delivered in plain language for non-technical audiences.

Data Protection Leads & DPOs

Deeper training for those with specific data protection responsibilities — ROPA management, DPIA process, rights request handling, breach management, and ICO engagement. Tailored to your organisation's processing activities.

HR & Finance Teams

HR and finance handle the most sensitive personal data in most organisations — payroll, employment records, bank details. Focused on the specific obligations and risks relevant to these teams.

Senior Leadership & Board

Accountability under UK GDPR sits at the top. Board-level training covers strategic obligations, reputational risk, ICO enforcement, and the board's role in data protection governance.

Could not be happier with the services provided by Aursec in supporting the IT of my Business. From initial engagement, Aursec worked with me to understand my requirements and ensured an efficient rollout of my Company's IT solution. They took the stress out of achieving CyberEssentials Plus certification and now are fully embedded with my organisation as a partner to deliver long term IT Service Support. Aursec would be a great option for any size business but are particularly valuable for smaller businesses that require that additional hands-on knowledge and experience.
NM
Nathan Molnar
CEO, Avencys Group Ltd

Ready to Train Your Team on Data Protection?

Book a free 30-minute call to discuss your training needs. We'll recommend the right format, tailor the content to your organisation, and give you a clear quote.

Book a Training Call

Get in Touch About Data Protection Training

Tell us about your organisation, your team, and what's driving the need for training. We'll come back to you within one working day.

info@aursec.co.uk