WorkplaceHero
All mini courses

Data protection and GDPR basics

The everyday version of UK GDPR: what counts as personal data, the habits that keep you compliant, and what to do in the first hour of a breach. Logs to your CPD.

0.5h CPD on completion - free
What you'll get from this course
  • Recognise personal and special category data in your own work
  • Apply the handful of principles that cover most daily decisions
  • Respond correctly in the first hour of a suspected breach
About 30 minutes - logs 0.5h to your CPD on completion.

What counts as personal data

Personal data is any information that can identify a living person, directly or with a bit of joining up. A name, an email, a staff number, a photo, a note about someone, an IP address.

Special category data needs extra care: health, ethnicity, religion, sexual orientation, trade union membership, biometrics, political opinions. Safeguarding notes and sickness records fall in here more often than people realise.

The principles that do most of the work

You do not need the statute. Five questions cover most decisions:

  1. Do I have a reason to hold this? If not, do not collect it.
  2. Am I using it for what it was collected for? Repurposing needs a rethink.
  3. Is it the minimum? The whole spreadsheet is rarely the minimum.
  4. Is it accurate and current? Old data causes real harm.
  5. Is it kept securely, and only as long as needed? Downloads, inboxes and desktops are the weak points.

People also have rights: to see their data, correct it, and in some cases have it deleted. Pass those requests to your data protection contact the day they arrive, because the clock starts immediately.

Scenario

You need to send a course update to 40 learners quickly. What is the right way?

The first hour of a breach

A breach is not only hacking. It is an email to the wrong person, a lost USB stick, a file left on a printer, a screen share showing a spreadsheet.

What to do:

  1. Contain it. Recall the email, retrieve the paper, revoke the link.
  2. Report it internally, immediately. Your organisation may need to notify the Information Commissioner's Office within 72 hours, and that clock starts when the organisation becomes aware.
  3. Write down what happened, including times.
  4. Do not quietly hope it goes unnoticed. Late reporting is what turns a small incident into a serious one.
Knowledge check

5 questions. Pick an answer to see whether it is right and why.

1.Which of these is special category data?

2.The deadline for an organisation to notify the ICO of a reportable breach is:

3.You are asked for a report and could send the full learner spreadsheet or a filtered extract. You should:

4.Someone asks to see all the data you hold about them. You should:

5.Emailing 40 learners with addresses in Cc is:

Reflect

Where does personal data sit in your work that probably should not be there any more?

Your reflection is saved to your CPD log when you mark the course complete.

Finish and log to CPD

Sign in to mark this course complete and add 0.5h to your CPD log. Don't have a log yet? We'll create one for you - free.