The Briefing Room HR & Compliance

What Is a GDPR Course and Do You Need One?

A GDPR course teaches staff to handle personal data lawfully under the UK GDPR and Data Protection Act 2018. This guide explains what a good course should cover in 2026, including the Data (Use and Access) Act changes, the new complaints duty and the Information Commission, and which learndirect course suits which role.

The learndirect compliance team - learndirect
• 12 min read
What Is a GDPR Course and Do You Need One?

A GDPR course teaches staff how to handle personal data lawfully under the UK GDPR and the Data Protection Act 2018: what counts as personal data, the seven data protection principles, the lawful bases for processing, people's rights over their data, and what to do when something goes wrong. No law names a specific course, but the UK GDPR makes every organisation accountable for showing it handles personal data properly, and trained staff are the most practical evidence of that. UK data protection law has also changed more in the last 18 months than at any time since 2018. The Data (Use and Access) Act 2025 has now largely come into force, organisations have had a new complaints duty since 19 June 2026, and on 30 September 2026 the Information Commission took over from the Information Commissioner as the UK regulator. This guide explains what a good GDPR course should cover in 2026, which learndirect course fits which role, and the facts many older courses still get wrong.

If your question is whether GDPR training is mandatory for your organisation, read our companion guide, What is GDPR training and why is it mandatory in the UK? This article focuses on choosing the right course.

What a GDPR course is, and what it is not

Most GDPR courses fall into one of two groups:

  • Staff awareness courses are short online courses, usually between 40 minutes and 2 hours, for anyone who handles personal data as part of their job. They cover the principles, lawful bases, individual rights, security and breach reporting at a practical level and end with an assessment and a CPD certificate. This is what most employees need, and it is what the learndirect courses provide.
  • Practitioner qualifications are multi-day programmes for data protection officers, compliance leads and privacy professionals. They go into the law in depth, including data protection impact assessments, international transfer mechanisms and regulator investigations, and are usually examined by a professional body.

A CPD-accredited awareness course is not a practitioner qualification, and it does not make someone a data protection officer. Be wary of any provider that claims its course is "approved by the ICO" or "required by law". The regulator does not approve or endorse training courses, and the law does not require any named course.

Do you need a GDPR course?

The UK GDPR applies to almost every organisation that handles information about living people, from sole traders to large employers. It does not say "every employee must complete a GDPR course", but several of its duties are very hard to meet without training:

  • Accountability. Under Article 5 of the UK GDPR, the controller is responsible for complying with the principles and must be able to demonstrate compliance. Training records are one of the clearest ways to show this.
  • Security. Organisations must have appropriate technical and organisational measures to keep personal data secure. Many breaches start with a person rather than a system: an email sent to the wrong address, a phishing link clicked, a file shared too widely.
  • Awareness and training. Where an organisation has a data protection officer, Article 39 of the UK GDPR makes raising awareness and training staff involved in processing part of the DPO's tasks.

In practice, anyone whose job involves collecting, viewing, storing, sharing or deleting personal data should be trained. That includes customer service, HR and recruitment, finance and payroll, marketing and sales, IT support, managers, and front-line staff in health, care and education.

What changed in 2025 and 2026

The Data (Use and Access) Act 2025 amends the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). It is being brought into force in stages. According to the regulator's commencement statement, most of the remaining data protection provisions came into force on 5 February 2026. If your training was written before then, check that it reflects these changes:

  • A new regulator. On 30 September 2026 the office of Information Commissioner was abolished and its functions passed to a board-led Information Commission, under the Commencement No. 9 Regulations. The government confirmed that the regulator's role, responsibilities and powers have not changed, and existing cases and notices carry on. Breaches are still reported through the regulator's website at ico.org.uk.
  • A complaints duty for every controller. Since 19 June 2026, section 103 of the Act has required organisations to make it easy for people to complain about how their data is used, for example with an electronic complaint form. Organisations must acknowledge each complaint within 30 days, look into it, and tell the person the outcome without undue delay. Front-line staff need to recognise a data protection complaint when they receive one.
  • Recognised legitimate interests. The Act adds a new lawful basis for a defined list of purposes, such as safeguarding and responding to emergencies, with no separate balancing test. It also confirms that direct marketing, sharing within a group of companies for administrative purposes, and network security can be legitimate interests.
  • Subject access requests. Organisations only need to carry out reasonable and proportionate searches. They can also pause the clock while they ask the requester to clarify a request, where that is genuinely needed. See the regulator's summary of the changes.
  • Automated decisions. Solely automated decisions with significant effects are now allowed in more situations, as long as safeguards are in place: telling people about the decision, letting them make representations, offering human intervention and letting them contest the decision.
  • Higher PECR fines. The maximum fine for breaking the rules on marketing calls, emails, texts and cookies has risen from GBP 500,000 to the UK GDPR level of GBP 17.5 million or 4% of worldwide turnover.

What a good GDPR course should cover

Use this checklist to judge any GDPR course, including ours.

The seven principles

The UK GDPR principles are: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability. Some courses list only six and leave out storage limitation, the rule that personal data must not be kept for longer than it is needed. Many organisations fail on this principle in practice.

Lawful bases and special category data

There are six lawful bases for processing: consent, contract, legal obligation, vital interests, public task and legitimate interests, plus the new recognised legitimate interests. A good course explains that consent is only one option and often not the best one. It also covers the extra conditions that apply to special category data, such as health information, ethnic origin, religious beliefs, sexual orientation, trade union membership, and genetic and biometric data.

Individual rights

People have the right to be informed, the right of access, and the rights to rectification, erasure, restriction, data portability and objection, plus rights around automated decision-making. For subject access requests, the regulator's guidance says you must respond without undue delay and within one month, which can be extended by up to two further months for complex or repeated requests. It is one calendar month, not "30 days". Staff should know how to recognise a request, which can be made verbally or through social media, and where to pass it on.

Security and breaches

The course should explain what a personal data breach is: not just hacking, but also lost devices, misdirected emails and unauthorised access. Under the regulator's breach guidance, a notifiable breach must be reported without undue delay and, where feasible, within 72 hours of becoming aware of it. People must be told directly if the breach is likely to result in a high risk to them, and every breach must be recorded, whether or not it is reported.

Marketing and PECR

Marketing emails and texts are governed by PECR as well as the UK GDPR. Under the regulator's electronic mail guidance, you need specific consent to email or text individuals, unless the "soft opt-in" applies. The soft opt-in covers your own existing customers who bought, or negotiated to buy, a similar product or service, provided they were given a clear chance to opt out when their details were collected and in every message. Emails to corporate bodies such as limited companies do not need consent, but sole traders and some partnerships are treated as individuals.

International transfers, roles and records

A good course should also cover:

  • The difference between a controller and a processor.
  • When personal data can be sent outside the UK.
  • When a data protection impact assessment is needed.
  • The records and privacy notices an organisation must keep.
  • Who to go to with a question.

For most staff, the most important outcome is knowing when to stop and escalate.

Which learndirect course is right for you?

learndirect offers three CPD-accredited courses in this area. Each is delivered online, ends with a final assessment and costs GBP 25 per learner, with an instant certificate.

  • GDPR Compliance Training (around 60 minutes). The best starting point for most staff and managers. Modules cover the key principles of the UK GDPR, lawful bases, data subject rights and handling requests, consent, accountability and data protection officers, and preventing and reporting breaches.
  • Data Protection Training (around 1.5 hours). More practical and operational. It suits people who handle personal data every day, such as HR, finance and customer service teams, with modules on handling data securely, responding to data subject requests, applying data protection policies in practice, and escalating breaches.
  • Cyber Security Training (around 40 minutes). Covers the security side: phishing, passwords, securing devices, malware and reporting incidents. It works well alongside either of the courses above, because human error and phishing are behind many personal data breaches.

For teams, volume pricing applies: 10 learners for GBP 212.50, 25 for GBP 468.75, 50 for GBP 812.50 and 100 for GBP 1,375.

Fines and enforcement

Under section 157 of the Data Protection Act 2018, the higher maximum fine is GBP 17.5 million or 4% of total worldwide annual turnover, whichever is greater. The standard maximum is GBP 8.7 million or 2%. You will often see GBP 20 million and GBP 10 million quoted, but those are the EU GDPR figures, not the UK ones.

Notable UK fines include:

  • British Airways, GBP 20 million (2020) for failing to protect the personal and payment details of more than 400,000 customers (BBC News). This related to a 2018 breach and was issued under the pre-Brexit regime.
  • Marriott International, GBP 18.4 million (2020) following a cyber attack that exposed millions of guest records (BBC News).
  • TikTok, GBP 12.7 million (2023) for using children's personal data unlawfully. In September 2026 TikTok withdrew its appeals and accepted the fine.
  • Capita, GBP 14 million (October 2025) after a 2023 cyber attack affecting more than 6 million people. The regulator found it had failed to ensure the security of personal data.

Fines are only part of the picture. The regulator can also issue reprimands, enforcement notices and information notices. Individuals can claim compensation, and the reputational damage from a public breach often costs more than the fine.

Five habits a GDPR course should build

  1. Check before you send. Confirm the recipient, use BCC for group emails and double-check attachments. Misdirected emails are among the most common breaches.
  2. Only collect and keep what you need. If you would struggle to explain why you hold a piece of data, you probably should not hold it.
  3. Treat unexpected links and requests with suspicion. Verify urgent requests for data or payments through a separate channel.
  4. Report suspected breaches straight away. The 72-hour clock starts when the organisation becomes aware, so a delay in telling your manager or DPO uses up time.
  5. Recognise requests and complaints. A customer asking "what do you hold about me?" or complaining about how their data was used has triggered a legal process, even if they never mention GDPR.

How often should GDPR training be refreshed?

The law does not set a fixed interval. Many organisations refresh it every year, and also when roles change, after an incident or near miss, or when the law changes. With the Data (Use and Access) Act changes, the new complaints duty and the move to the Information Commission all taking effect in 2026, this is a sensible year to retrain staff whose last course predates them.

Common questions

What is the difference between the UK GDPR and the Data Protection Act 2018?
The UK GDPR sets out the core rules: the principles, lawful bases, rights and duties. The Data Protection Act 2018 sits alongside it, adding UK-specific exemptions and conditions, covering law enforcement and intelligence processing, setting the fine levels and creating criminal offences. Both are now amended by the Data (Use and Access) Act 2025, and organisations must comply with all of them.

Is a GDPR course a legal requirement?
No law names a specific course. However, the UK GDPR requires organisations to be able to demonstrate compliance and keep personal data secure, and training staff is the standard way of doing both. Our GDPR training guide covers this in more detail.

Do we need consent to send marketing emails?
To individuals, yes, unless the soft opt-in applies to existing customers who bought, or negotiated to buy, similar products or services and were given a clear chance to opt out. Corporate bodies such as limited companies can be emailed without consent, but you must identify yourself and offer an easy way to unsubscribe. Sole traders and some partnerships are treated as individuals.

Does every organisation need a data protection officer?
No. Under Article 37 of the UK GDPR, a DPO is mandatory for public authorities, and for organisations whose core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special category or criminal offence data. Other organisations can appoint one voluntarily, but should still make someone responsible for data protection.

How long can we keep personal data?
Only as long as you need it for the purpose you collected it for. That is the storage limitation principle. The UK GDPR does not set fixed periods, so organisations should create a retention schedule based on their legal obligations and business needs, then delete or anonymise data when the period ends.

What should I do if I think there has been a data breach?
Tell your manager or data protection lead immediately, and do not try to investigate or fix it alone. The organisation must assess the risk and, if the breach is notifiable, report it to the regulator within 72 hours of becoming aware. People affected must be told directly if the risk to them is high, and every breach must be recorded.

Is the ICO still the regulator?
Since 30 September 2026, the Information Commission has carried out the functions previously held by the Information Commissioner. Its powers and responsibilities are unchanged, and you still report breaches and find guidance through ico.org.uk. Training that refers to "the ICO" is not wrong in substance, but up-to-date courses should explain the change.

How long does a GDPR course take and how much does it cost?
The learndirect GDPR Compliance Training takes around 60 minutes and Data Protection Training around 1.5 hours. Each costs GBP 25 per learner, with volume pricing from 10 learners and an instant CPD-accredited certificate.

Get your team trained

Anyone who handles personal data needs to understand the principles, recognise a rights request or complaint, and know what to do when something goes wrong, under the law as it stands in 2026. Start with the CPD-accredited learndirect GDPR Compliance Training, or choose Data Protection Training for staff who handle personal data every day. Each costs GBP 25 per learner and comes with an instant certificate recognised by UK employers. Explore the full range in the learndirect HR and compliance category.

Frequently asked

What is the difference between the UK GDPR and the Data Protection Act 2018?

The UK GDPR sets out the core rules: the principles, lawful bases, rights and duties. The Data Protection Act 2018 sits alongside it, adding UK-specific exemptions and conditions, covering law enforcement and intelligence processing, setting the fine levels and creating criminal offences. Both are now amended by the Data (Use and Access) Act 2025, and organisations must comply with all of them.

Is a GDPR course a legal requirement?

No law names a specific course. However, the UK GDPR requires organisations to be able to demonstrate compliance and keep personal data secure, and training staff is the standard way of doing both.

Do we need consent to send marketing emails?

To individuals, yes, unless the soft opt-in applies to existing customers who bought, or negotiated to buy, similar products or services and were given a clear chance to opt out. Corporate bodies such as limited companies can be emailed without consent, but you must identify yourself and offer an easy way to unsubscribe. Sole traders and some partnerships are treated as individuals.

Does every organisation need a data protection officer?

No. Under Article 37 of the UK GDPR, a DPO is mandatory for public authorities, and for organisations whose core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special category or criminal offence data. Other organisations can appoint one voluntarily, but should still make someone responsible for data protection.

How long can we keep personal data?

Only as long as you need it for the purpose you collected it for. That is the storage limitation principle. The UK GDPR does not set fixed periods, so organisations should create a retention schedule based on their legal obligations and business needs, then delete or anonymise data when the period ends.

What should I do if I think there has been a data breach?

Tell your manager or data protection lead immediately, and do not try to investigate or fix it alone. The organisation must assess the risk and, if the breach is notifiable, report it to the regulator within 72 hours of becoming aware. People affected must be told directly if the risk to them is high, and every breach must be recorded.

Is the ICO still the regulator?

Since 30 September 2026, the Information Commission has carried out the functions previously held by the Information Commissioner. Its powers and responsibilities are unchanged, and you still report breaches and find guidance through ico.org.uk.

How long does a GDPR course take and how much does it cost?

The learndirect GDPR Compliance Training takes around 60 minutes and Data Protection Training around 1.5 hours. Each costs GBP 25 per learner, with volume pricing from 10 learners and an instant CPD-accredited certificate.

Sources and further reading

  1. UK GDPR Article 5: principles (legislation.gov.uk)
  2. UK GDPR Article 37: designation of the data protection officer (legislation.gov.uk)
  3. Data Protection Act 2018, section 157: maximum penalties (legislation.gov.uk)
  4. Data (Use and Access) Act 2025 (legislation.gov.uk)
  5. Data (Use and Access) Act 2025, section 103: complaints by data subjects (legislation.gov.uk)
  6. Data (Use and Access) Act 2025 (Commencement No. 9) Regulations 2026 (legislation.gov.uk)
  7. Information Commission succeeds the ICO as UK's data protection regulator (GOV.UK)
  8. Statement on the commencement of the Data (Use and Access) Act (ICO)
  9. DUAA summary of the changes: data protection (ICO)
  10. A guide to subject access (ICO)
  11. Personal data breaches: a guide (ICO)
  12. Electronic mail marketing under PECR (ICO)
  13. Capita fined GBP 14m for data breach affecting over 6m people (ICO)
  14. TikTok withdraws appeals and accepts GBP 12.7m fine (ICO)
  15. British Airways fined GBP 20m over data breach (BBC News)
  16. Marriott fined GBP 18.4m over data breach (BBC News)

Rated by our learners

Rated Excellent by our learners

4.5 out of 5

Based on 32,432 Trustpilot reviews

Read all reviews →
Verified

Spoke to Hayden and he was very…

Spoke to Hayden and he was very helpful. I had a positive experience. absolutely happy with the service.

IM 5 Oct 2026
Verified

Clodagh is super helpful and amazing

Clodagh is super helpful and amazing. Thank you so much for the support

Em 5 Oct 2026
Verified

i was on the phone with jacob and he…

i was on the phone with jacob and he was very helpful and helped me get all the information i needed to start with learn direct

Alfie L. 5 Oct 2026
Verified

I had the best experience with Wesley…

I had the best experience with Wesley Marais.He was very patient and helpful ,explained every detail ,very friendly.

Otilia S. 5 Oct 2026
Verified

Thank you to Harley for your customer…

Thank you to Harley for your customer service and helping me start a Trinity Cert Tesol online course at Learn direct. You helped me navigate the application process. Looking forward to doing my course.

Mary 4 Oct 2026
Verified

I had some difficulties navigating my…

I had some difficulties navigating my way through the process of adding a top up course onto my account, I had previously been told conflicting information about how I go about this from previous customer services advisors at learn direct, fortunately I spoke to Sam, who was very helpful on the process, he also followed this up with an email after, which was greatly appreciated. He was efficient with his information and time and it allowed me to add my top up course, after some previous teething issues.

Charlotte 4 Oct 2026
Ready when you are

Take the next step in your learning journey

Course tips, career advice and exclusive offers, straight to your inbox. No spam, just guidance.

Accredited & trusted

Working with the UK's leading awarding bodies

Call us
today