Training

🔏 GDPR Basics

What staff who handle EU personal data need to know.

Talking points
  • Collect only the personal data you actually need, and only use it for the purpose it was collected for.
  • Individuals have real, enforceable rights to access, correct, or request deletion of their data — know who to route these requests to.
  • A data breach involving EU personal data may need to be reported to regulators within 72 hours — report any suspected exposure to your Incident Lead immediately, don't wait to investigate first.
  • Before using a new tool or vendor that will touch personal data, check whether it needs a Data Processing Agreement in place.
  • "Consent" under GDPR has to be clear and specific — pre-checked boxes or buried terms don't count.
Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →