Our data protection and information security portfolio covers all essential training, from GDPR fundamentals to the latest requirements under NIS-2, DORA, and the AI Act, as well as practical IT awareness training.
All training courses shown are available both as a package and individually.
Anytime, anywhere thanks to adaptive e-learning
Multimodal with learning objectives, video sequences, and knowledge quizzes
Audit-proof issuance upon successful completion of the assessment
Between 20 minutes and 3 hours, depending on the training
+50 available
Content regularly reviewed by subject matter experts for maximum legal compliance
Every training topic is designed and vetted by renowned subject matter experts who possess both sound theoretical knowledge and extensive practical experience.










Here you will find the most important answers regarding GDPR training obligations, NIS-2 requirements, and protection against the most common cyber threats in the workplace.
Yes – data protection training for employees is effectively mandatory under the GDPR, even if the regulation does not explicitly formulate a training obligation for all staff. Art. 39 (1) lit. b GDPR explicitly obliges the Data Protection Officer to raise awareness and train employees involved in processing operations. Furthermore, Art. 32 GDPR requires appropriate technical and organizational measures – training is considered a key organizational measure here. The accountability principle under Art. 5 (2) GDPR also requires the controller to be able to demonstrate compliance with data protection principles – without documented training, this proof is almost impossible to provide in practice. Supervisory authorities therefore regularly assess a lack of employee training as an independent data protection violation.
The most common cyber threats that employees need to be trained against today almost always target the human factor. According to the BSI situation report and the Verizon Data Breach Report, the biggest risks are: phishing and spear-phishing (targeted emails to obtain login credentials), CEO fraud or business email compromise (fake instructions from supposed superiors), ransomware (often introduced via infected attachments or links), social engineering (manipulation of employees via phone or chat), identity theft, and insecure passwords, as well as risks from mobile devices, USB sticks, and public Wi-Fi networks. Effective training sensitizes employees to typical warning signs, teaches secure behavior when handling emails, passwords, and data, and establishes clear reporting channels for security incidents.
Missed data protection training can significantly exacerbate the legal and financial consequences for a company in the event of a data breach. Supervisory authorities view a lack of training as a violation of the accountability principle under Art. 5 (2) GDPR and the obligation to implement organizational measures under Art. 32 GDPR. When calculating fines under Art. 83 GDPR – up to 20 million euros or 4% of the total worldwide annual turnover – a lack of training documentation regularly acts as an aggravating factor. In addition, there are civil claims for damages by affected parties under Art. 82 GDPR, potential criminal proceedings for intentional violations, and significant reputational damage. In practice, the central question after an incident is almost always: "Can you prove that you trained your employees?" – those who cannot provide this proof are in a difficult position.
The NIS-2 Directive (Network and Information Security Directive 2) explicitly obliges affected companies to train their employees in cyber security on a regular basis. Art. 21 (2) lit. g NIS-2 lists "cyber hygiene practices and cybersecurity training" as one of the central risk management elements. Particularly strict requirements apply to management: under Art. 20 NIS-2, they must participate in training themselves and are personally responsible for implementation. In Germany, this affects around 30,000 companies across 18 sectors, including energy, health, finance, digital infrastructure, and manufacturing, once they exceed certain size thresholds. Implementation into German law is carried out via the NIS-2 Implementation Act (NIS2UmsuCG); violations can be punished with fines of up to 10 million euros or 2% of the total worldwide annual turnover.
Data protection and IT security training should generally be repeated at least once a year – even though neither the GDPR nor NIS-2 specifies a concrete interval. Supervisory authorities and industry standards such as ISO 27001 and the BSI IT-Grundschutz consistently recommend an annual rhythm. The reason: threat landscapes, attack methods, and legal requirements are constantly changing, meaning one-off training sessions quickly become outdated. In addition, event-based training is mandatory – for example, when introducing new IT systems, after security incidents, in the event of significant changes in the law, or during the onboarding of new employees. For staff in particularly sensitive areas such as IT administration, HR, or accounting, shorter intervals and more in-depth modules are recommended.
GDPR training for general staff and training for Data Protection Officers (DPOs) have different objectives and differ accordingly in depth, scope, and target audience. Employee training is about awareness: in 20 to 45 minutes, it covers the most important principles of the GDPR, data subject rights, handling personal data in everyday work, how to act in the event of a data breach, and who to contact internally. DPO training, on the other hand, is a professional qualification: it spans several days according to established standards (e.g., BvD or TÜV) and provides in-depth knowledge of legal foundations, technical and organizational measures (TOMs), data protection impact assessments, data processing agreements, international data transfers, and communication with supervisory authorities. While employee training is mandatory for all staff annually, the DPO qualification is a professional requirement under Art. 37 (5) GDPR, coupled with a continuous obligation for further education.
Mandatory training and professional development from GDPR to NIS-2 – audit-proof and practical.
Get in touch now
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.