GDPR and data protection training
Data protection training teaches employees what personal data is, how to process, share and store it lawfully, and what to do in a breach. ShieldWise courses cover both GDPR and Georgia's Law on Personal Data Protection.
- GDPR and Georgian law in one course
- Classification, minimisation and retention
- Redaction and classification simulations
- Breach response and incident reporting
Updated:
Who needs data protection training
Everyone who handles customer, patient or employee data: sales, HR, marketing, finance and customer service. Georgia's new Law on Personal Data Protection, in force since 1 March 2024, moves close to GDPR, so knowing either rulebook calls for the same habits.
What employees learn
The data protection courses and simulations cover:
- What is and isn't personal data, and the special categories
- Processing principles and data minimisation
- Classification, safe sharing and retention
- Redacting personal data in a document before sharing
- Recognising a breach and reporting it immediately
Training as compliance evidence
GDPR Article 39 lists awareness-raising and training of staff among the data protection officer's tasks. During an inspection or after an incident, an organisation has to show its staff were prepared. ShieldWise keeps the completion history and issues certificates you can hand to an auditor.
Related courses
- CoursePersonal data protection basicsWhat personal data is, a GDPR basics check, privacy settings and practical advice.
- CourseSafe data handling & disposalEveryday practice when working with data, and how to destroy what you no longer need.
- CourseProtecting your personal ID numberYour personal ID number is a digital key: what a fraudster can do with it and how to protect it.
- CourseSafe cloud sharingAccess levels and permissions in Google Drive and OneDrive, and what a hasty "anyone with the link" share costs.
- CourseCampaign confidentialityHow unannounced campaign details leak and how to protect them, digitally and in conversation.
- CourseData classificationThe four classification levels, the handling rules for each and a practical external-sharing scenario.
- CourseManaging sensitive informationThe CIA triad, the two-channel sharing principle, shadow IT and a scenario with an external auditor.
- CourseUnderstanding website cookiesWhat cookies are, which ones help and which ones track, and how to answer a cookie banner.
- CourseProtecting marketing dataCustomer lists and marketing material as assets: classification, safe transfer and tooling.
- SimulationData handling scenariosSimulation: choose the right action in data handling scenarios.
- SimulationData classification simulationSimulation: sort documents by confidentiality level.
- SimulationData redaction simulationSimulation: redact personal data before a document is shared.
Frequently asked questions
Does GDPR apply to a Georgian company?
It applies if the company processes data of people in the EU, for example by offering them goods or services. Otherwise Georgia's Law on Personal Data Protection applies, and it sets requirements similar to GDPR.
How long is a course?
Each course takes about 10 minutes; simulations take 5-6. A full topic is split into several short courses.
Is there a certificate?
Yes. A certificate is issued on successful completion, and anyone can verify it publicly.
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.