Skip to content
+370 5 212 1506 info@dat.lt

Data protection training for organisations

Online data protection training

  • Training for staff in a range of roles;
  • Delivered over Zoom or any other remote working platform you normally use;
  • The programme can be tailored to your individual needs.

In-person data protection training

  • Training for staff in a range of roles;
  • Delivered at your office or another suitable venue;
  • The programme can be tailored to your individual needs.

Most businesses handle large amounts of personal data, whether it belongs to customers, employees or other individuals. Collecting, using and storing that data is subject to the complex requirements of the General Data Protection Regulation, and failing to meet them carries severe sanctions.

Data protection training for your staff builds awareness of data protection among employees and across the whole organisation, gives them practical knowledge and helps them deal with the everyday issues that arise when collecting, using and storing personal data. Regular staff training also meets the State Data Protection Inspectorate’s (VDAI) requirements on staff training. The State Data Protection Inspectorate recommends training staff at least once a year.

We can adapt the training programme to your needs, tailoring it to your sector and to your employees’ level of knowledge of data protection.

To arrange training for your company, contact us using the form on the right-hand side of this page.

Contact us

    Check it yourself

    You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

    Frequently asked questions

    Is data protection training for employees mandatory?

    The GDPR has no separate article saying “training is mandatory”, but the obligation follows from two places. First, the data protection officer’s tasks expressly include awareness-raising and training of staff. Second, the controller must implement organisational measures appropriate to the risk and be able to demonstrate that it has done so, and VDAI’s security guidelines name staff training as one such measure. In practice, the date of the last training is a standard inspection question.

    How often should employees be trained?

    In its guidelines on security measures, VDAI suggests training once a year and states that a training plan with objectives and targets must be prepared and implemented every year. The practical standard is therefore one training session a year, plus induction training for new employees. In service agreements with a data protection officer, annual training is usually a separately agreed item.

    What topics does data protection training cover?

    For organisations whose staff have not yet had any training, we offer a basic programme: the key GDPR concepts; the principles of data processing; special categories of personal data and how they are processed; the conditions for lawful processing; informing data subjects and their rights; personal data breaches; data protection impact assessment; the functions of the data protection officer; employees’ obligations when processing personal data; practical examples and tips.

    Is the training programme tailored to our field of activity?

    Yes, and this is done once the date is confirmed: the topics are agreed individually, based on the specifics of your activity and the questions that arise in practice. For schools and other educational institutions, for example, the programme covers the purposes of data processing in an educational institution, informing parents and guardians, consent for pupils’ photographs, filming and publication, processing staff data, workplace video surveillance policy, managing access rights and passwords, the procedure for detecting and reporting breaches, handling requests, contracts with service providers and disclosure of data to public authorities. For healthcare institutions, the focus shifts to health data and the processing of special categories of data.

    How long does the training last?

    Usually 2–4 hours; the exact length also depends on how engaged the audience is. Broader programmes, for example for educational institutions, usually take 3–4 hours. A shorter session is enough for a narrower range of questions or for a single group of employees. The length is agreed in advance, together with the topics.

    Is the training held online or in person?

    Both: the choice is yours. Online training is delivered over Zoom or another platform you normally use; in-person training takes place at your premises. Where the audience has different roles, one booking is often split, with some groups trained online and one group in person.

    Do participants receive certificates?

    Yes. After the training, participants receive an electronic certificate of attendance. It is an internal document of the organisation confirming that the employee has completed the training, which is exactly what you need to prove the training took place during an audit or inspection.

    Do participants receive training materials?

    Yes. The training materials (PDF) are provided electronically together with the certificates. The materials stay with the organisation and can be used for induction of new employees and as a reminder between annual training sessions.

    How many employees can take part, and do we need several groups?

    There is no formal limit on group size, but two things decide it: whether employees can genuinely ask questions, and whether their roles are similar enough. Where the audience is large or the roles are very different, the training is split into groups, for example one for administration and another for specialists working with customer or patient data. In practice, one booking is often divided into two or three groups on different days.

    Who delivers the training?

    The training is delivered by the same firm’s advocates and lawyers who work in data protection every day: they draft GDPR documents, carry out audits and data protection impact assessments, and act as external data protection officer in client organisations. Part of the team holds international data protection qualifications. So the examples used in training come from real cases, not from a textbook.

    Can we send in advance the questions we want answered during the training?

    Yes, and we recommend it. Questions can be sent by email before the training or asked during it; a separate part at the end of the training is set aside for answers. Questions sent in advance allow the programme to focus on what actually causes problems in your organisation.

    Do new employees need to be trained separately?

    Yes. VDAI’s guidelines state that an organisation’s ongoing staff training programmes must include a specific programme for training new employees in data protection and cyber security. In practice, the materials handed over after the annual training are used for this, and larger organisations run a separate induction briefing and keep a record that it took place.

    Do you run training for data protection officers and internal auditors?

    Yes. This is a separate programme that goes deeper than general staff training. A data protection officer or an internal auditor needs a working method, not an overview of principles: how to keep records of processing activities, how to assess legitimate interest, how to carry out a data protection impact assessment, how to manage a breach within 72 hours and how to prepare for an inspection by the supervisory authority. The programme is adjusted depending on whether the organisation operates in the public or the private sector.

    Is the training suitable for staff with no legal background?

    Yes. The programme is adapted to the participants’ background, and the examples are taken from your own activities.

    Can we have training on a single topic only?

    Yes. A common choice is the one topic that raises the most questions in the organisation, for example data subject requests or photographs at events.