Cast your mind back to your organisation’s GDPR training. For a lot of UK businesses, it happened in a burst of activity around 2018, was rolled out to everyone… and hasn’t been meaningfully repeated since. Meanwhile, the threat landscape those staff face has transformed: industrialised phishing, convincing AI-generated scam emails and voice cloning, ransomware groups targeting SMEs, and hybrid working that moved company data onto home networks and personal devices.
Training that predates all of that is not protection. It’s a certificate.
Why “once” was never the intention
UK GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data — and staff awareness is the organisational measure everything else depends on. The ICO’s accountability framework expects data protection training at induction and refreshed at appropriate intervals, with records kept. When the ICO investigates a breach, one of its standard questions is when the staff involved were last trained. “Six years ago” is not an answer that helps.
The same expectation now comes from several other directions at once:
- Cyber insurers increasingly ask about staff security awareness training — frequency included — before quoting, and non-compliance can jeopardise claims.
- Cyber Essentials and supply-chain security questionnaires routinely ask how staff are trained and how often.
- Client contracts and tenders, especially with public sector and larger corporates, commonly require evidence of annual data protection training.
The human firewall is the one that matters
The overwhelming majority of successful cyber attacks on UK businesses start with a person, not a technical exploit — a clicked link, a credential typed into a fake login page, an “urgent” payment request from a spoofed director. Technical controls filter most of it; a trained, sceptical workforce deals with what gets through. That’s why modern refresher training pairs data protection law with practical cyber security awareness — the two subjects have effectively merged, because the most likely way your organisation will breach UK GDPR is by being successfully attacked.
What an annual refresher should cover
An effective refresher is short, current and practical: the UK GDPR essentials people actually use (lawful handling, data subject rights, what counts as a breach and the 72-hour reporting clock); this year’s threats — phishing and smishing patterns, AI-generated scams, payment fraud; secure habits for hybrid work — devices, passwords and MFA, public Wi-Fi, sharing and disposal; and exactly what to do, and who to tell, when something goes wrong. An hour a year, documented, per employee.
A refresher built for the job
Our GDPR Refresher & Cyber Security Awareness (Annual) course is designed to be exactly that annual touchpoint: UK GDPR and Data Protection Act 2018 essentials, current cyber threats, safe data handling in and out of the office, and breach response — completed online in around an hour, with a dated certificate for your accountability records. At £15 per learner it is one of the cheapest controls in your entire security posture.
With staff increasingly using AI tools at work, it pairs well with our AI in the Workplace Awareness Training — the newest route by which company data leaks is also the least trained-for.


Leave a Reply