Data protection training: Obligation, content and evidence according to Art. 39 GDPR
Data protection training is not HR folklore, but rather a supervisory measure that requires documentation in accordance with Article 39 (1) (b) GDPR. This guide shows mandatory content, frequency, verification and how CIVAC maps the entire life cycle in an audit-proof manner.
Art. 39 Para. 1 lit. b GDPR obliges the data protection officer to sensitize and train employees who process personal data. German supervisory practice specifies this standard in two directions. Firstly, in Short Paper No. 12, the Data Protection Conference (DSK) calls for verifiable training measures with proof of content, participants and time. Secondly, current activity reports from the state data protection authorities point to a noticeably increasing density of audits relating to training documentation. Anyone who only presents an Excel list here will not only fail in the fine proceedings, but also in the order processing audit of a demanding major customer or in the onboarding of a new data protection supervisory board.
This article describes what content a data protection training must contain according to the GDPR and BDSG, at what frequency it should be repeated, how the proof should be structured and which typical error patterns supervisory authorities have sanctioned in the last 18 months. You will also learn how the CIVAC compliance platform and officer-as-a-service constellation combines training requirements, attendance tracking, content versioning and the data protection officer's appointment certificate into a single, closed compliance workflow. The auditor calls, the evidence is ready. There are 490 ready-to-use audit templates, a versioned reporting line and EU data residency running in the background. Licence the workspace for your internal representatives, or have our representatives order it.
Key Takeaways
- The training obligation results from Article 39 Paragraph 1 Letter b GDPR and Section 38 BDSG; it affects the person responsible, not the DPO alone.
- Reliable evidence consists of a table of contents, list of participants, date, duration and a learning success check per person.
- Recommended cycle: Onboarding within 30 days, then annual refresh, as necessary in the event of new processing or data breaches.
Legal basis: Why data protection training is mandatory
The obligation to provide data protection training is not contained in a single paragraph, but rather results from the interaction of several standards. Art. 39 Para. 1 lit. b GDPR is central: The data protection officer monitors compliance with the GDPR, including awareness-raising and training of employees involved in processing operations. This indirectly results in the duty of the person responsible to enable the DSB to carry out such training in terms of organisation, time and budget. Without budget allocation and without a mandate for compulsory participation, Art. 39 GDPR remains an empty shell and therefore vulnerable.
In addition, there is Art. 32 Para. 4 GDPR, which obliges the person responsible to ensure that every person under his control only processes personal data on instructions. Without training, these instructions cannot be justified plausibly. Section 53 BDSG supplements the requirement for non-public bodies to maintain data secrecy, which in practice is part of the training and is stored in the personnel file. § 5 BDSG remains effective for public bodies and requires analogous proof of training.
Finally, § 130 OWiG requires the owner of a business to properly supervise people who are commissioned to commit administrative offenses. A documented training landscape is one of the most effective arguments against a § 130-OWiG accusation in fine proceedings by the supervisory authorities. The role of the data protection officer changes from an internal consultant to an active trainer with a documentation mandate. CIVAC maps these tasks in parallel in the compliance platform and officer-as-a-service constellation, so that the appointment certificate, training plan and reporting line come from one data model and do not have to be reconstructed from three file folders. Audit-proof, documented, Section 39-proof. Additionally relevant: Recital 39 of the GDPR emphasizes the obligation for transparent processing, which is practically impossible to achieve without training employees.
Mandatory content: What a complete data protection training covers
An exam-proof data protection training covers eight content blocks that are derived from the GDPR, the BDSG and previous supervisory practice. First: Basic principles of the GDPR according to Article 5 (legality, purpose limitation, data minimization, accuracy, storage limitation, integrity, accountability). Second: Legal bases according to Art. 6 and for special categories of personal data according to Art. 9 GDPR including consent, legitimate interest and employee data protection according to Section 26 BDSG. Third: rights of those affected in accordance with Articles 12 to 22, i.e. information, correction, deletion, restriction, data portability, objection and automated individual decision-making.
Fourth: reporting obligations in the event of data breaches, in particular the 72-hour deadline under Article 33 of the GDPR and the notification of those affected under Article 34. The deadline expires as soon as we become aware of it. Fifth: order processing according to Art. 28 with contractual obligations, TOMs and subcontractor regulations. Sixth: Third country transfers according to Art. 44 ff. GDPR including standard contractual clauses and transfer impact assessment according to the Schrems II requirements. Seventh: technical and organisational measures according to Art. 32 with specific role reference, i.e. what IT, HR, sales and accounting have to implement.
Eighth: role and department-specific in-depth information. Sales needs different examples than HR, IT needs different examples than marketing, finance needs different examples than research. The CIVAC audit templates contain 37 modular building blocks that can be put together to form role-based training paths. Others run compliance like a filing cabinet. We run it like software. Each module version is versioned in the DSB reporting line and stored with a validity date so that it can still be traced in three or five years which employee received which content version in which language version and with which test result. If you work in multiple languages, store German and English versions with identical version numbers so that the auditor can check that the content is congruent without comparing translations.
Frequency: Onboarding, annual refresher, event-related
The GDPR itself does not specify a fixed training cycle. However, German supervisory practice and ISO/IEC 27001:2022 Control A.6.3 (Information Security Awareness, Education and Training) converge on a three-stage pattern that has become established in audit practice and which is also regularly cited by the BfDI in consultations as a minimum standard. Anyone who falls short of this pattern has a significant gap in the burden of proof in the audit and in the fine proceedings.
Stage one is the initial training in onboarding. It must take place within 30 days of starting work and cover at least the eight mandatory blocks mentioned above. The employee may not process any personal data on their own responsibility before completing the initial training. In sensitive areas (HR, medicine, finance, research), a de facto processing ban is enforced organizationally until training is completed, for example via temporary reading authorizations in the CRM or HR system.
Stage two is the annual refresher. It repeats the core content, updates it with new supervisory decisions, ECJ rulings (e.g. on the amount of damages according to Art. 82 GDPR) and internal company incidents and concludes with a learning success review. A tried and tested 45 to 60 minute online format plus a 10-question test with an 80 percent pass mark and an opportunity to repeat the test. Anyone who fails on the second attempt will be listed as an open item in the reporting line.
Stage three is the event-related training. It is triggered by new processing activities, new systems, data breaches, complaints from those affected or requests for information from authorities. Deadline begins as soon as we become aware of it. In CIVAC, all three levels are mapped via a single training plan that shows the current status, the next due date and the latest evidence for each employee, filtered by department, role and language. Licence the workspace for your internal representatives, or have our representatives order it.
Verification: Which documents will stand up in the audit
A common mistake in audits: Training was carried out, but the evidence consists of an Excel list without versioning, without learning success monitoring and without a clear reference to the content. That is not enough in front of a supervisory authority. Nor before a demanding client audit. A reliable proof of training consists of seven components that must be kept in parallel in the data protection officer's reporting line.
First: the exact table of contents of the training with version number and date of validity. Second: the list of participants with first and last names, department, function and date of entry. Third: the training date and the actual training duration in minutes. For online training, the effective processing time must be recorded, not just the registration duration. Fourth: the participant's confirmation that he or she has understood the training, ideally with a qualified electronic signature according to eIDAS or at least with a verifiable, identified login.
Fifth: the learning success control with questions, answers and results. Sixth: the role and qualifications of the trainer or the training body, in the case of external training with reference to the appointment certificate of the external data protection officer and his proof of qualification (TÜV, udis, IHK, GDDcert, comparable). The appointment certificate, signed, filed, verifiable. Seventh: the retention regime. The supervisory authorities assume a retention period analogous to the DPIA documentation of three to six years, for security-relevant training under the NIS 2 scope of at least five years from the last effect.
CIVAC stores all seven components per training event in the reporting line, linked to the directory of processing activities and to ISO/IEC 27001:2022 Control A.6.3. EU data residency is a prerequisite so that the proof itself does not trigger a third country transfer and thus does not become a GDPR incident of its own. The auditor calls, the evidence is ready., filtered by person, validity date and module, without IT or HR having to actively search.
Training requirement for processors and service providers
The training obligation does not end at the company borders. Article 28 (3) (b) GDPR obliges the processor to ensure that the persons authorised to process the data have committed themselves to confidentiality or are subject to an appropriate legal obligation of confidentiality. In supervisory practice and in the EU Commission's standard contractual clauses, this is interpreted in such a way that the processor's employees must also be trained if they process the controller's data. A mere NDA is not enough.
For those responsible, this means an obligation to check as part of supplier selection and ongoing supplier monitoring. The order processing contract should expressly require that the service provider submits proof of training once a year or at least confirms its existence in writing, ideally with the right to take samples. For security-critical services (data centre operations, managed detection and response, identity providers, cloud providers, external payroll accounting), a specific right to inspect the training documentation is also agreed, which can be taken up by the client audit.
It becomes more complex with sub-processors. Art. 28 Para. 4 GDPR extends the obligations to the entire chain, without the controller knowing each subcontractor directly. CIVAC does this via a supplier auditor module, which collects training certificates from processors and their subcontractors in a structured manner, converts them into a four-stage risk classification and links them to the list of processing activities. The CIVAC SLA for the initial setup of a supplier audit is two working days instead of the traditional two to six weeks. Audit-proof, documented, Section 28-proof. Licence the workspace for your internal representatives, or have our representatives order it. In practice, it is advisable to explicitly set the retention period for training certificates in the order processing contract to at least three years and to agree on annual reporting by the order processor.
Common mistakes and how regulators sanction them
The fine practice of the German supervisory authorities shows recurring patterns. In the 2024 activity report of a northern German state data protection officer, a medium-sized company was fined a five-figure fine because HR employees without documented training had processed applicant data in a cloud system that was not listed in the register of processing activities. The lack of training was not the main violation, but it was decisive evidence that there was no effective supervision within the meaning of Article 5 (2) GDPR. It is precisely this combination that we are observing in more and more procedures at CIVAC.
Mistake one: training as a purely compulsory exercise in onboarding without a refresher. Mistake two: uniform training without role reference, so that IT, HR and sales receive identical material and no one really knows the examples relevant to their own work. Error three: missing or purely symbolic monitoring of learning success (three trivial questions, each answer is counted as correct). Error four: no proof of content, just a list of signatures. Error five: no versioning of the training documents, so that the audit cannot reconstruct which version was valid when and which employee completed it.
Error six: Trainer without proven qualifications. The supervisory authorities accept external trainers with DSB qualifications or comparable evidence (TÜV, udis, IHK, GDDcert). Mistake seven: no training for significant changes, such as when introducing new AI systems according to the EU AI Act or when migrating to a new cloud region. The obligations from the EU AI Act significantly increase the need for training for affected high-risk systems. CIVAC automatically recognises such triggers and suggests event-related follow-up training in the reporting line, including template text for management and escalation path.
Data protection training and NIS-2: double obligation from October 2024
With the NIS 2 directive and the German NIS2UmsuCG, data protection training for around 29,500 affected companies in Germany is supplemented by a second mandatory dimension: training on information security. Article 21(2)(g) of the NIS 2 Directive requires basic cyber hygiene practices and cybersecurity training. The German implementation draft requires management to personally take part in appropriate training courses, with documented confirmation of participation. Anyone who underestimates this detail loses an essential line of defence in the supervisory process.
In practice, both training obligations can be combined sensibly. Topics such as phishing, password hygiene, handling USB media, detecting social engineering and responding to suspicious emails are relevant to both data protection and security. The reporting obligations partially overlap: 72 hours for data breaches according to Art. 33 GDPR, 24 hours early warning and 72 hours follow-up report according to NIS-2. An integrated training must clearly show which deadline runs when and to which office is reported (state data protection supervision versus BSI as the federal central office).
CIVAC combines the roles of data protection officer and information security officer in a common training matrix with 93 controls according to ISO/IEC 27001:2022 as a structural grid. The management receives its own module with documented participation, which can be presented as evidence during an NIS 2 supervisory examination. Fines of up to 10 million euros or 2 percent of group sales for essential facilities and up to 7 million euros or 1.4 percent for important facilities make the need for proof measurable. The platform logs every training session attended by management with date, content and duration in a separate, non-deletable recording layer. When it comes to double reporting, a clear separation is important: data breach reports to the state supervisory authority and security reports to the BSI may overlap in terms of content, but must be documented procedurally independently so that deadlines remain individually verifiable.
Effort, costs and realistic benchmarks
How much does data protection training cost per employee? Market benchmarks from the last 18 months show the following range: Classic face-to-face training by an external law firm 180 to 350 euros per person per training event, plus travel costs and lost working hours. Online training with a pure awareness provider costs 12 to 45 euros per person per year, often without integrated learning success monitoring, without role suitability and without connection to the internal directory of processing activities. Self-developed in-house training courses often cause hidden costs in HR and IT (maintenance, updates, exam creation, hosting) of around 80 euros per person per year.
The actual cost driver is not the training itself, but the documentation in the event of a dispute. If a fine procedure is ongoing three years after a data breach and the supervisory authority demands all training certificates from the affected team, the quality of the documentation determines the amount of the fine to an extent that is far higher than the training costs. Art. 83 Para. 2 lit. d GDPR expressly lists the measures to reduce the damage and prevent future violations as reducing the fine. Documented, versioned and role-related training is one such measure and is recognised in practice by supervisory authorities.
CIVAC bundles content, implementation and evidence in the compliance platform and makes Officer-as-a-Service available as an ordering option. Licence the workspace for your internal representatives, or have our representatives order it. In the workspace model, depending on the size of the company, the costs are between 4 and 18 euros per employee per year, including the 490 audit templates, training management and versioning of the content. In the officer-as-a-service model, the appointment of the external DPO with a full reporting line is also taken over, including direct communication with the responsible state supervisory authority.
From reading to implementation: setting up a training strategy
Effective data protection training does not begin with a set of slides, but with an inventory. What processing activities are there according to the list according to Art. 30 GDPR? Which roles process which data categories? Which training courses were carried out in the last 24 months and which versions were valid and when? What evidence exists and in what quality? Where are there gaps in role, time or content? These answers result in a training matrix with mandatory modules per role and a reliable 12-month plan.
In the second step, the training plan is converted into an audit-proof process. This includes versioning of the content with a validity date, learning success checks with a defined passing threshold, escalation paths in the event of non-participation after 30 and 60 days, connection to the HR department's onboarding system and a clear language strategy for multilingual workforces. In the third step, the proof of training is embedded in the directory of processing activities and in the ISO/IEC 27001:2022 control landscape so that an audit finds the complete context and does not have to switch between three systems.
CIVAC provides ready-made building blocks for each of these three steps: training matrix templates, version management in the reporting line and connection to the data protection officer's appointment certificate. The platform works in two modes: licence the workspace for your internal representatives, or have our officers appointed it. In both models, the CIVAC SLA of two working days applies to the initial setup and the ongoing evidence base with EU data residency.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de/faq. We will send a specific training schedule for your company within two working days, tailored to the industry, number of employees, existing representative structure and the supervisory authority responsible for you.
FAQ
Who is obliged to carry out data protection training?
The person responsible within the meaning of the GDPR is obliged, i.e. the company as a legal entity, represented by the management. The data protection officer monitors and supports implementation in accordance with Article 39 Paragraph 1 Letter b of the GDPR, but is not himself the recipient of the training requirement. Management has ultimate responsibility in accordance with Section 130 OWiG for establishing effective supervisory measures, which include training.
How often does data protection training have to be repeated?
The GDPR itself does not specify a fixed cycle. German supervisory practice and ISO/IEC 27001:2022 Control A.6.3 require initial training in onboarding within 30 days, followed by at least an annual refresher with learning success monitoring as well as event-related training for new processing activities, data breaches, new systems or official requests for information. Anyone who works for more than twelve months without a refresher will have a problem with the fine procedure.
What content must be included in a GDPR training?
At least eight mandatory blocks: basic principles according to Art. 5, legal bases according to Art. 6 and 9, rights of those affected according to Art. 12 to 22, reporting obligations according to Art. 33 and 34, order processing according to Art. Employee data protection in accordance with Section 26 BDSG supplemented to be mandatory for HR functions.
What does an audit-proof proof of training look like?
Reliable evidence contains seven components: table of contents with version number and date of validity, list of participants with function and entry date, training date and actual duration in minutes, confirmation of the participant ideally with eIDAS signature, learning success control with questions and results, qualification of the trainer and retention period of at least three years, under NIS 2 scope of at least five years from the date of effect.
Do external service providers also have to be trained?
Yes, if you process the controller's personal data as a processor in accordance with Art. 28 GDPR, training and a confidentiality obligation are required. The order processing contract should expressly require proof of training or written confirmation of the training of the people deployed, and in the case of security-critical services, a specific right of inspection and annual reporting. A mere NDA without documented training is not sufficient in supervisory practice.
What fines are there for lack of training?
A lack of training is rarely punished in isolation, but is viewed as an indication of a lack of supervision in accordance with Article 5 (2) GDPR and Section 130 OWiG. In combination with a specific data protection violation, fines of up to 20 million euros or 4 percent of global group sales are possible in accordance with Art. 83 Para. 5 GDPR. Supervisory authorities use the training documentation as an essential assessment feature in Article 83 Paragraph 2 Letter d.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.