Workplace

GDPR Training Online Course

Understand your legal obligations when handling personal data with this CPD accredited GDPR training course, covering the UK General Data Protection Regulation and the Data Protection Act 2018 in full. Data protection compliance is a legal requirement for every organisation that processes personal data, and the Information Commissioner's Office (ICO) can impose significant fines for breaches. This course provides a thorough grounding in UK data protection law, explaining the seven data protection principles, the lawful bases for processing personal data, and the rights of data subjects including the right of access, rectification, erasure, and data portability. You will learn how to handle personal and sensitive data securely, understand when and how to obtain valid consent, draft appropriate privacy notices, and recognise and report data breaches within the required timeframes. The course also covers the roles of data controllers and data processors, the responsibilities of Data Protection Officers, and the requirements for Data Protection Impact Assessments. Whether you work in an office, healthcare, education, hospitality, or any other sector, understanding UK GDPR and data protection is essential to your role. Upon completion, you will receive a CPD accredited certificate that demonstrates your awareness of data protection principles and ICO compliance requirements — recognised by employers across all industries in the UK.

2-3 hours CPD Accredited Included in the £35 licence

Your Data Protection and UK GDPR certificate is included in the £35 Chefs Bay Academy licence, along with 130+ other CPD accredited courses. One payment, 12 months of access, no subscription.

GDPR Training at a glance

GDPR Training is a CPD accredited online course from Chefs Bay Academy, taking 2-3 hours to complete. The certificate is ready to download as soon as you pass.

Duration 2-3 hours, self-paced
Certificate CPD Accredited, instant download
Price £35 licence covering all 130+ courses
Access 12 months, any device, unlimited retakes

Chefs Bay Academy is run by Chefs Bay Hospitality Limited (Company No. 13588811), a UK hospitality and care staffing agency based in Merseyside. Your £35 licence covers this course and 130+ others, all CPD accredited, with 12 months of access.

What this course costs elsewhere

Comparison Typical single certificate Chefs Bay Academy licence, all 130+ courses
Price £10-£40 per course, usually + VAT £35 once, VAT included
Covers One course All 130+ courses
Access Typically 60-90 days 12 months, one person
Retakes Often charged again Unlimited, any course
Refunds Varies by provider Full refund within 14 days, if no certificate downloaded

Market range from provider price lists, checked August 2026. £35 is the whole licence, covering all 130+ courses for 12 months, not a per-course price.

Get Full Access for £35 14-day money-back guarantee

What You'll Learn

  1. Introduction to UK GDPR and the Data Protection Act 2018
  2. The Seven Data Protection Principles
  3. Lawful Bases for Processing Personal Data
  4. Individual Rights Under UK GDPR
  5. Data Handling, Storage, and Retention
  6. Consent and Privacy Notices
  7. Recognising and Reporting Data Breaches
  8. Your Responsibilities as a Data Handler

Who Needs This Course

Essential for all employees, managers, HR professionals, and office workers who handle personal data and need to understand their legal obligations under UK GDPR and the Data Protection Act 2018.

About this course

What is the difference between UK GDPR and the Data Protection Act 2018?

They work together rather than compete. UK GDPR sets the principles, the rights and the obligations that apply when personal data is processed. The Data Protection Act 2018 supplements it, applies the exemptions, and covers what the regulation leaves to national law, including law enforcement processing.

Compliance means meeting both, which is why this course treats them as one subject across its eight modules.

What are the seven data protection principles?

UK GDPR sets seven: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The first six describe how personal data has to be handled. Accountability is the one that catches organisations out, because it requires you to demonstrate compliance rather than simply achieve it.

Records, policies and training logs are what that demonstration looks like when the ICO asks to see it.

What are the lawful bases for processing personal data?

Six bases exist under UK GDPR: consent, contract, legal obligation, vital interests, public task and legitimate interests. You pick one before processing begins, record the choice, and set it out in your privacy notice. Swapping basis part way through is difficult, so the decision belongs at the start.

Consent is the most misused of the six. It has to be freely given, specific, informed, unambiguous, and as easy to withdraw as it was to give. A pre-ticked box fails that test, and so does making a service conditional on consent to processing the service does not actually need.

How quickly does a data breach have to be reported?

A personal data breach that is likely to pose a risk to people’s rights and freedoms must be reported to the Information Commissioner’s Office within 72 hours of the organisation becoming aware of it, where feasible. Every breach gets documented internally either way, and where the risk is high the affected individuals have to be told without undue delay too.

Most staff will never file that report themselves. Recognising that a lost laptop, a misdirected email or an unlocked filing cabinet might be a breach, and flagging it quickly so the right person can judge the risk, is the part that depends on training.

What rights do people have over their data?

Eight rights: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision making and profiling. A subject access request can arrive by email, over the phone or inside a complaint letter. The one-month response clock runs from receipt, though it can pause while identity is confirmed or a reasonably required clarification is answered.

Most requests land on an ordinary member of staff long before they reach anyone with data protection in their job title.

Who should take a UK GDPR course?

Anyone who handles personal data at work: HR, finance, reception, marketing, care and support staff, and the managers deciding what gets collected and how long it is kept. The ICO expects staff training as part of an organisation’s accountability measures and can ask what training was in place after an incident.

The course takes two to three hours and ends with a CPD accredited certificate. If you are arranging this for a whole team, the guide to GDPR training for employees covers frequency and record keeping.

Your Certificate

Pass the assessment and your certificate is ready to download as a PDF the same day, with your name and the course title on it. Print it, email it to a manager, or attach it to a CV.

  • PDF download, same day you pass
  • CPD accredited by The CPD Certification Service
  • Retake the assessment as often as you need

These are training courses, not Ofqual-regulated qualifications. Read how our accreditation works.

Certificate of achievement

Your name

has successfully completed

Data Protection and UK GDPR

Chefs Bay Academychefsbayacademy.co.uk CPD Certified, The CPD Certification Service Issue dateThe day you pass
Your certificate, as a PDF, the same day you pass. Sample layout, your name and course are printed on it.

Want the background before you start? Read our guide: GDPR training for employees: what UK law requires

Start Learning in 2 Minutes

  1. 1

    Buy Your Licence

    One payment of £35 for all 130+ courses, 12 months. No subscriptions, no hidden fees.

  2. 2

    Get Instant Access

    Login details arrive by email, and the confirmation page has a set-up link so you can start straight away.

  3. 3

    Complete Courses

    Work at your own pace on any device. All 130+ courses unlocked.

  4. 4

    Download Certificates

    CPD accredited certificates ready for your employer or CV.

Frequently Asked Questions

The UK GDPR and the Data Protection Act 2018 require organisations to make sure staff who handle personal data understand their responsibilities. Training is the practical way employers meet that duty and reduce the risk of a breach.

Anyone who handles personal data as part of their job: office and admin staff, HR, marketing, customer service, healthcare and care staff, and managers. In practice that covers most employees in most organisations.

It covers the data protection principles, the lawful bases for processing, individual rights such as access and erasure, how to recognise and report a data breach, and the role of the Information Commissioner's Office.

There is no fixed legal interval, but an annual refresher is common practice and is often expected by auditors and clients, especially after any change to how an organisation handles data.

Get Full Access for £35

Data Protection and UK GDPR plus 130+ more courses, all CPD accredited. One person, 12 months, no subscription.

Get Full Access for £35
14-day money-back guarantee
£35All 130+ courses, 12 months
One person. VAT included
Start This Course