# GDPR and security awareness training: what is mandatory in 2026?

> The GDPR contains no literal training obligation, but without demonstrable awareness you do not meet Article 32. Here is how training works under the GDPR.

- Canonical: https://cyberpulse.it/en/gdpr-security-awareness-training
- Dutch version: https://cyberpulse.it/avg-security-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

No: the GDPR contains no article that literally makes security awareness training mandatory. But that does not settle it: Article 32 requires appropriate technical and organisational measures, and training counts as an expected organisational measure. On top of that, your data protection officer supervises it under Article 39. This page explains what the GDPR does and does not ask, and how to make awareness demonstrable.

## Does the GDPR require security awareness training?

The honest answer: the GDPR names no mandatory course, but without demonstrable awareness you do not meet Article 32. The regulation works with open norms: what is 'appropriate' is for you to determine, based on risk. Anyone who reads that openness as 'training is optional' is reading it wrong.

Two articles form the basis together:

| Article | What it says | What it means for training |
|---|---|---|
| Art. 32 | Appropriate technical and organisational measures | Training counts as an expected organisational measure |
| Art. 32(4) | Staff process personal data only on instruction | Instructions only work if employees know and understand them |
| Art. 39(1)(a) | The DPO monitors, among other things, awareness-raising and training of staff | The legislator assumes a training programme exists |

Article 32(4) is the most concrete foothold: staff with access to personal data process it only on instruction from the controller. Such an instruction is only worth something if employees know what is expected of them: when a phishing email lands, when someone calls asking for data, when a customer export is shared. That knowledge element is not something you arrange on paper; it takes training and repetition.

And note the word demonstrable. In a data breach or a complaint, you want to be able to show which measures you had in place. A policy document with no evidence that employees were trained on it does not convince.

## What a supervisory authority expects

In the Netherlands the Dutch Data Protection Authority supervises compliance with the GDPR; every EU member state has its own supervisory authority. What an authority may expect of you follows directly from the regulation itself, and two things in there are relevant to training.

First, Article 32: can you show which appropriate technical and organisational measures you have taken, matched to your risks? Staff awareness belongs in that list. An organisation that can produce nothing after an incident about how its people were prepared stands weaker than one with a documented programme.

Second, Article 39, on the role of the data protection officer (DPO):

> The data protection officer monitors, among other tasks, "awareness-raising and training of staff".
> – art. 39(1)(a) GDPR

So the legislator assumes there is something to supervise. If your organisation has a DPO, they should be able to report whether staff are actually being trained, and without a programme there is nothing to report.

One point of honesty: the GDPR prescribes no specific course, format or frequency, and you should not read requirements into the above that are not there. What is appropriate depends on your risk profile: an organisation processing health data or financial data is in a different position from a small consultancy. But doing nothing is not appropriate under any risk profile.

## Training as an 'appropriate organisational measure' under art. 32

Article 32 asks for appropriate technical and organisational measures. Technology (encryption, access management, back-ups) is the visible half. The organisational half is about people and processes, and training sits there: it counts as an expected appropriate organisational measure.

'Appropriate' is deliberately open. How do you make it concrete? Look at what established standards ask; they turn the GDPR's open norm into something practical:

- [ISO 27001](/en/iso-27001-awareness-training) asks in control 6.3 for appropriate awareness, education and training with regular updates, relevant to the job function, and in clause 7.2(d) for documented evidence of competence.
- For organisations in scope of the Dutch Cybersecurity Act, training is even part of the statutory duty of care; read more about that in [NIS2 security awareness training](/en/nis2-security-awareness-training).

Measure your awareness programme against that yardstick and you arrive at the same building blocks: everyone with access to personal data takes part, the content fits the job function, it is repeated regularly, and understanding is tested. That is both your line of defence and your evidence. Record these elements and you can show your DPO or a supervisory authority concretely what you have arranged under Article 32: instead of pointing at good intentions.

## Fines and data breaches caused by human error

The GDPR carries substantial maximum fines. For infringements of the security obligations, among others, Article 83(4) applies: a maximum of €10 million or 2% of worldwide annual turnover, whichever is higher. For an SME the absolute figure is rarely the realistic scenario, but the message is clear: weak security is not a minor matter.

It does not even have to get that far for the damage to be real. A data breach means notification work, investigation, communication to the people affected and reputational harm: quite apart from any enforcement or claims.

And the pattern is stubborn: many data breaches start with a human action. An email containing personal data to the wrong recipient. A phishing link clicked in the rush. An export to a private mailbox 'to carry on at home'. Against precisely this kind of incident, technology is only half a match; employee behaviour decides the other half. That is why awareness is not a paper exercise but a direct reduction of your data breach risk.

For comparison: where the GDPR expects training implicitly, the Dutch Cybersecurity Act (Cbw) (the Dutch implementation of NIS2, in force from 15 August 2026) makes it explicit. Its duty of care, following NIS2 Article 21(2)(g), literally covers "basic cyber hygiene practices and cybersecurity training". Other EU member states have their own NIS2 implementing laws. If you fall under both frameworks, the requirements point the same way and one demonstrable programme is enough.

## How to make it demonstrable

'We take privacy seriously' is not evidence. This is:

- A training plan: who is trained in what, and why that fits the risk profile.
- Participation records per employee, with dates.
- Test or quiz results showing that the material was understood.
- Certificates on completion of modules.
- Periodic phishing simulations that measure whether behaviour actually changes.
- Reports with which your DPO can carry out the supervisory task from Article 39.
- Repetition: not a one-off session, but a continuous programme.

### The role of the data protection officer

Does your organisation have a data protection officer (DPO)? Then awareness is literally part of their statutory remit. Article 39(1)(a) of the GDPR tasks the DPO with monitoring compliance with the regulation, and explicitly names "awareness-raising and training of staff". In practice that means the DPO may, and should, ask which training programme is running, who took part and what the results were.

For you as an organisation that is an opportunity rather than a burden. A DPO who can demonstrate that training happens structurally has a stronger story towards a supervisory authority: when handling a breach notification, for example. The reverse holds too: a DPO who finds that awareness is missing and reports it internally has thereby recorded that the organisation knew about the risk. So make sure the answer to "what do we do about awareness?" is never a shrug.

### A step-by-step plan for SMEs

Want to go from nothing to demonstrable? This works in practice:

1. **Put it in policy**: a short paragraph in your information security or privacy policy: everyone who processes personal data takes awareness training periodically.
2. **Choose a continuous format**: short, regular training moments keep knowledge current and produce evidence continuously; one annual session does neither.
3. **Register participation per employee**: who, what, when, with what result. This is exactly the documentation that separates "we think privacy is important" from an accountable measure under art. 32.
4. **Include joiners immediately**: new employees often process personal data from day one; make the training part of onboarding.
5. **Evaluate and adjust**: review annually whether the topics still match your processing activities and incidents, and record that evaluation too.

That sounds like a lot of administration, but it need not be manual work. CyberPulse automatically records training participation, quiz results, certificates and phishing outcomes per employee: the file with which you can show your DPO, a client or a supervisory authority exactly which organisational measures you have taken. [Start a free trial](/trial) and build that evidence from week one.

Curious how the GDPR relates to other training obligations: from the Dutch Cybersecurity Act to ISO 27001 and sector standards? You will find the full overview in [is security awareness training mandatory?](/en/security-awareness-training-mandatory)

## Frequently asked questions

### Is security awareness training mandatory under the GDPR?

Not literally: the GDPR contains no article prescribing a course. But Article 32 requires appropriate technical and organisational measures, and training counts as an expected organisational measure. In addition, under Article 32(4) staff process personal data only on instruction, and under Article 39 the DPO monitors awareness-raising and training of staff. In short: no mandatory course, but without demonstrable awareness you do not meet Article 32.
### What does Article 39 mean for our data protection officer?

Article 39(1)(a) GDPR makes the DPO responsible for monitoring, among other things, awareness-raising and training of staff. That presupposes a programme to supervise. So make sure your DPO has visibility of who has been trained and with what results: through reports from your training platform, for example. That way the DPO can carry out this statutory task and show that awareness is embedded.
### How high can a GDPR fine for inadequate security be?

For infringements of the security obligations, among others, the maximum in Article 83(4) applies: €10 million or 2% of worldwide annual turnover, whichever is higher. Alongside any fine, a data breach also brings notification duties, investigation costs and reputational damage. Demonstrable measures, including a trained team, reduce both the chance of an incident and your exposure when it is assessed.
### How often should I train my employees?

The GDPR names no frequency; 'appropriate' is the yardstick. Established frameworks do give direction: ISO 27001 asks in control 6.3 for regular updates, and PCI DSS for training on joining plus at least annually. In practice, a continuous programme of short, frequent moments works better than one annual session: knowledge fades and threats such as phishing keep changing.
### Does an e-learning with registration count as evidence towards a supervisory authority?

Records are exactly what demonstrability calls for: who took which training, when, and with what result. Combine participation records with test results (evidence of understanding), certificates and phishing simulation measurements (evidence of behaviour). With those you can show concretely, after a breach or during an audit, which organisational measures you had taken under Article 32: far stronger than a policy document alone.
### How does this differ from the training requirement under NIS2?

The GDPR expects training implicitly, as an appropriate organisational measure under Article 32. The Dutch Cybersecurity Act (the Dutch implementation of NIS2, in force from 15 August 2026) makes it explicit: the duty of care covers cybersecurity training, and members of the management body must demonstrably acquire knowledge and skills, with a certificate from a training course. If you fall under both frameworks, one demonstrable awareness programme serves them both.

## Sources

- [EUR-Lex, GDPR (Regulation (EU) 2016/679)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
- [EUR-Lex, NIS2 Directive (Directive (EU) 2022/2555)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
