
This lecture provides a concise 2026 update on the most important GDPR compliance priorities for employees, managers and organisations. It highlights current expectations regarding transparency, individual rights, artificial intelligence, data breaches, suppliers, international transfers and organisational accountability.
The session is designed to complement the main GDPR Awareness course by drawing attention to practical areas that organisations should review regularly. It also explains why EU GDPR and UK data-protection requirements should now be considered separately in relevant circumstances.
GDPR Awareness – European-Accredited Level 2 Certificate
Level 2 Training Certificate
The General Data Protection Regulation (GDPR) strengthened and harmonised data-protection requirements across the European Union and European Economic Area.
Every business or organisation that collects, stores, uses, shares or otherwise processes personal data must understand its responsibilities and regularly review its policies, procedures and working practices to ensure continued compliance.
This practical GDPR Awareness course provides a clear introduction to your main responsibilities and helps you identify the steps required to improve data-protection compliance within your workplace.
Particular attention is given to important areas such as obtaining valid consent, respecting the right to erasure—also known as the “right to be forgotten”—and understanding when the appointment of a Data Protection Officer may be required. The course also introduces essential GDPR terminology, individual rights, sensitive personal data, financial penalties and practical compliance measures.
Course Features
Developed and delivered by a qualified and authorised professional trainer
Accredited at Level 2 by SOS Professional Training Centre
Level 2 Training Certificate valid across Europe*
Fully online training and assessment
Study at your own pace, with no fixed completion deadline
Full professional audio voiceover throughout the course
Approximately 35 minutes of on-demand video training
Scope of the GDPR
The GDPR generally applies to personal data processed wholly or partly by automated means. It can also apply to manual processing where the information forms part of—or is intended to form part of—an organised filing system.
Personal data includes any information relating to an identified or identifiable natural person. This can include names, identification numbers, contact details, online identifiers, location information and other information that can be used to identify someone directly or indirectly.
The GDPR applies to processing connected with the EU, including where the organisation processing the data is established within the EU. It may also apply to organisations established outside the EU when they offer goods or services to individuals in the Union or monitor their behaviour within the Union.
The GDPR covers a wide range of operations involving personal data, including its collection, recording, organisation, storage, use, disclosure, alteration and deletion. Its requirements may apply to businesses, associations, charities, public authorities, other organisations and, in certain circumstances, private individuals.
Some exemptions and special rules apply. For example, processing carried out by an individual solely as part of a purely personal or household activity may fall outside the GDPR. Specific exemptions or derogations may also apply where personal data is processed in connection with freedom of expression, journalism, academic work, artistic expression or access to information