S2 Ep27: Creating Training Which Changes Behaviour

Hosted by Caine Glancy and Amber Sivill

Caine Glancy and Amber Sivill discuss why generic data protection training often fails to change behaviour. They explain how role-based content, practical examples, open conversations and ongoing guidance can help staff apply their training at work.

Creating Training That Changes Behaviour (3)

Creating Training Which Changes Behaviour

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Data protection training should do more than record attendance. It should help people recognise risks, understand their responsibilities and know what action to take.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss why generic training often fails to engage staff. They explore how organisations can make training practical, relevant and easier to apply during everyday work.

Why Generic Training Often Falls Short

Training can be technically accurate without being effective.

A presentation may explain the law correctly, but staff are unlikely to remember it if the content does not relate to their role. Long presentations, legal language and broad examples can make data protection feel more complicated than it needs to be.

Amber explained:

“Poor training for me is where organisations design training and it may be very well researched, but it is not tailored.”

Training should connect data protection requirements to real decisions. Staff need to understand how the subject affects their work, their customers and the personal data they handle.

Make Training Relevant to Each Role

Different teams use personal data in different ways.

Human resources teams, senior managers, IT staff and customer service teams may face very different risks. Giving everyone exactly the same training can leave important gaps.

Amber said:

“Tailoring it to different departments and different scenarios, and bringing some sort of personal element in, really makes people think.”

Role-based training allows an organisation to focus on the situations each team is likely to encounter. This could include recognising a subject access request, reporting a personal data breach or handling sensitive information securely.

Build Trust Rather Than Fear

Training should make people feel able to ask questions and report mistakes.

Using fear to encourage compliance can have the opposite effect. Staff may become less willing to report an incident if they believe they will automatically be blamed or disciplined.

Amber explained:

“Leading by fearmongering can push people towards being less open and honest about the things they may be doing wrong or the difficulties they are facing.”

A supportive approach does not remove accountability. It helps staff understand that mistakes should be reported quickly so the organisation can assess the risk and respond appropriately.

Caine highlighted the importance of education alongside formal training:

“Education is also the time spent with people to help them understand an element of the law that is relevant to them and their role.”

Make Training Conversational

People often learn more when they can ask questions and discuss realistic examples.

A conversational session gives the trainer an opportunity to understand where staff are struggling. It also helps employees connect data protection principles with situations they have experienced.

Amber said:

“It needs to be more conversational and more on a case-by-case basis.”

Quizzes, practical exercises, visuals and group discussions can all help. A mixture of formats also supports different learning styles.

Support Staff After the Session

Training should not end when the presentation closes.

Staff need somewhere to find clear information when they face a data protection question. This could be a company handbook, an intranet page or a central collection of practical guidance.

Amber explained:

“It is always good to have some sort of central archive, a company handbook or an intranet, where people can easily access that information.”

Resources should answer practical questions, including:

  • How to recognise a potential personal data breach
  • Who to contact when something goes wrong
  • How to recognise a request for personal information
  • Where to find the organisation’s policies and procedures
  • What responsibilities apply to a particular role

Create a Culture of Accountability

Effective training needs support from across the organisation.

The Data Protection Officer cannot build a strong data protection culture alone. Senior leaders, line managers, IT teams and other key employees all have a part to play.

Amber described accountability as the overarching principle:

“Ultimately, it is about accountability. You look at what has gone wrong, what you could do better next time and what you can put in place.”

When leaders take training seriously, staff are more likely to do the same. This helps turn data protection from an annual exercise into part of everyday decision-making.

Key Takeaways

Effective data protection training should:

  • Relate directly to the employee’s role
  • Use clear language rather than legal jargon
  • Include practical examples and realistic scenarios
  • Encourage questions and open conversations
  • Help staff feel confident reporting mistakes
  • Use different formats to support different learning styles
  • Provide guidance that remains available after the session
  • Receive visible support from senior leaders and managers

Good training does not simply tell people what the law says. It helps them understand what good data protection looks like in practice.

Watch or Listen to the Full Episode

Watch the full conversation on YouTube or listen through Spotify.

Explore Data Protection Training

Data Protection Made Easy provides training designed to help organisations understand their responsibilities and apply data protection requirements in practice.

View Training Courses