Articles

When GDPR Training Gets Skipped, the Damage Isn’t Just a Fine

The Information Commissioner’s Office (ICO) has issued the Metropolitan Police Service with an enforcement notice and a reprimand following two serious data breaches. Neither breach was a one-off mistake by an unlucky individual. Both traced back to the same root cause: staff who hadn’t completed mandatory data protection training, and no system in place to catch it before harm was done.

For any UK SME handling personal data — which is effectively all of them — that’s the lesson worth taking seriously. Not the specifics of policing, but the training and oversight gap that made two preventable breaches possible.

What is UK GDPR?

UK GDPR (General Data Protection Regulation) is the UK’s data protection law. It sets out how organisations must collect, use, store and protect personal information, and it’s enforced by the ICO. Every employer holding staff or customer data — from job applications to payroll — is in scope.

What happened

A stalking victim’s new address, disclosed to her alleged stalker. During legal proceedings for a Stalking Protection Order, officers served documents that hadn’t been properly redacted, including the victim’s new home address and phone number, plus contact details for three witnesses. The defendant then used the exposed number to contact her. The ICO found the officers involved hadn’t received the specialist training required for these cases, and that quality checks that should have caught the unredacted information simply weren’t there.

One email, eighteen people exposed. During a high-profile investigation, an officer emailed a group about a change to a bail date using “To” instead of “BCC,” exposing every recipient’s name and email address to each other. The officer responsible hadn’t completed mandatory data protection training in over four years. Neither had their line manager.

Why the ICO didn’t call this “human error”

The ICO’s investigation looked wider than the two incidents and found low completion rates for mandatory data protection training across the organisation, plus weak monitoring of who had and hadn’t completed it. Its own conclusion: both incidents were “foreseeable and preventable.”

Regulators are increasingly asking “does this organisation’s whole compliance framework hold up?” — not just “what went wrong in this one incident?” A single breach can trigger a review of training records, management oversight and governance.

What this means for UK SME employers

Any SME holding employee records, candidate data, or customer information is exposed to the same failure pattern: training gets assigned once, nobody checks it’s completed, and gaps go unnoticed until something goes wrong. Worth asking:

  • Is mandatory data protection training tracked to actual completion — not just “assigned” — for every employee?
  • Do you know who’s overdue for refresher training, and by how long?
  • Is training targeted at the roles handling the most sensitive data?
  • Do line managers have visibility of their team’s completion rates?
  • Is there a review step for sensitive outgoing communications?

A quick GDPR training checklist for SMEs

  1. Map who handles sensitive data — prioritise HR, recruitment, finance and customer-facing teams
  2. Set a completion deadline, not just an assignment date
  3. Track completion automatically via an LMS rather than a spreadsheet
  4. Give managers visibility of their team’s completion rate
  5. Refresh training regularly rather than “set and forget”
  6. Build in a second pair of eyes for high-risk communications

How PeopleFirstHR can help

PeopleFirstHR supports UK SME HR teams with GDPR and data protection training through Astute, VinciWorks’ learning management platform. It tracks completion automatically, flags who’s overdue, and gives managers real visibility of their team’s compliance status.

See how Astute’s completion tracking works, or speak to our partners at WorkNest about wider employment law and data protection support.

PeopleFirstHR have been working on Human Resource Information Systems for over 20 years and with People Inc. and YouManage since 2011. Our experience means we can provide a common-sense approach to providing you with a comprehensive HR system to help you record and maintain your employee data.

If you would like to learn more about how we can help your organisation please contact us on 0330 223 6180 or via email enquiries@Peoplefirsthr.co.uk.