
For many companies, a learning management system (LMS) is the central way to organize, carry out, and prove legally required instruction. Selecting one is therefore not only a software decision but above all a compliance decision: the system must reflect the requirements that occupational health and safety law places on instruction.
The key points are set out in Section 12 of the Occupational Health and Safety Act (ArbSchG): instruction is given with reference to the workplace, during working hours, upon hiring, and when changes occur. Section 4 DGUV Regulation 1 adds the rhythm – repeated where necessary, at least annually – and the obligation to document. A suitable LMS translates exactly these requirements into functions. The following seven criteria help with a structured assessment, regardless of the provider.
The term "mandatory training" covers the instruction that an employer is legally required to carry out – an integral part of workplace occupational health and safety. The basic obligation follows from Section 12 ArbSchG and Section 4 DGUV Regulation 1; which topics are specifically necessary follows from the risk assessment. Typical areas are general occupational health and safety, fire safety instruction and first aid topics, hazardous substances, electrical safety, or the handling of certain work equipment.
For an LMS, it is important to understand: this is not about "one course for everyone" but about a bundle of different, partly role-specific instruction topics, each with its own rhythm. Anyone assessing a system should therefore check whether it can map this variety – different topics, target groups, and intervals – in parallel and clearly. This is exactly what decides whether the LMS eases the workload in everyday practice or creates additional maintenance effort.
The following table assigns each criterion to its legal anchor and names what to look for when assessing a system. The detailed sections below explain the points.
| Criterion | Legal anchor | What to look for when selecting an LMS |
|---|---|---|
| Deadlines & repetition | Section 4 DGUV Regulation 1 (at least annually), Section 12 ArbSchG (event-driven) | Automatic due dates per person and topic, reminders, overdue items visible |
| Documentation, proof & reporting | Section 4 DGUV Regulation 1 | Automatically documented, exportable records, audit trail, fulfillment overview |
| Check of understanding | DGUV Rule 100-001 (06/2025) | Assessment (questions/quiz) with documented result, opportunity to ask questions |
| Workplace relevance & up-to-date content | Section 12 ArbSchG, Sections 3 and 5 ArbSchG | Role-/area-based assignment, content that can be updated when standards change |
| Data protection | Art. 6 and 28 GDPR | DPA, EU hosting, deletion concept, role and permission concept |
| Technology & accessibility | DGUV Rule 100-001 ("understandable form and language") | SCORM/xAPI compatibility, multilingual support, low-barrier design |
| Integration & scalability | Section 12 ArbSchG (initial instruction before starting work) | HR interface/SSO, tenants/locations, growing number of users |
Mandatory training thrives on rhythm. Section 4 DGUV Regulation 1 requires repetition at least once a year; in addition, there is event-driven instruction, for example when new work equipment is introduced or after an accident. For an LMS, this means: it should automatically calculate due dates per person and topic, send reminders in good time, and make overdue assignments visible.
Of practical value are a calendar or traffic-light overview of upcoming and overdue instruction, automatic reminders to employees and managers, and the option to trigger an ad hoc assignment at short notice when an occasion arises. This turns the annual obligation into a controllable process instead of a manual hunt for dates in spreadsheets.
Documentation is anchored in law: Section 4 DGUV Regulation 1 expressly requires that instruction be documented, and Section 6 ArbSchG requires documents on the result of the risk assessment, the measures laid down, and the result of their review. In the event of a dispute or an inspection, what counts is what can be proven. An LMS should therefore record, for each instruction and without gaps, who completed which content and when.
The template from DGUV Rule 100-001 serves as a guide to the information a record should contain: company, work area, person giving the instruction and their function, date, type of instruction (initial, repeat, or event-driven instruction), the content of the instruction, and participation. Important: DGUV Regulation 1 prescribes no specific form and no signature – however, individual state regulations such as Section 14 GefStoffV can impose stricter requirements. A good system covers both worlds: automated digital proof plus optional confirmation.
For audits, what counts are exportable records (for example as a PDF or spreadsheet) and an audit trail that makes subsequent changes traceable. Equally helpful is a reporting layer that condenses the fulfillment status: how many employees in a department are currently instructed, and what is overdue? Such an overview makes internal management easier, as well as providing information to the supervisory authority or the accident insurance institution. This keeps record-keeping robust even with many employees and topics.
The revised DGUV Rule 100-001 (edition 06/2025) makes clear what applies to every form of instruction – including digital ones: the persons responsible must satisfy themselves that the content has been understood. It must be possible to ask questions, and merely handing over content for pure self-study is not sufficient. In practice, this means: simply distributing a file or a link – without a learning path, without an assessment, without a channel for questions, and without documented proof – will, as a rule, not meet these requirements. If electronic aids are used, practical teaching may also be required. The critical point therefore lies less in the digital format itself than in the structure in which it is embedded.
For LMS selection, this specifically means: the system should support an assessment or check of understanding – for example comprehension questions or a short quiz with a pass threshold – and document its result. Just as important is an opportunity to ask questions, for example via a supervised phase, a contact person, or a comment function. An LMS that only lets users "click through" instruction does not meet the standard set by the rule.
Section 12 ArbSchG requires instruction related to the workplace and the task. The topics follow from the risk assessment – and it changes when new work equipment, procedures, or hazards are added. An LMS should therefore allow role- or area-specific instruction to be assigned to employees instead of giving everyone the same standard course.
Helpful are flexible assignment by department, activity, or location as well as content that can be kept up to date when the legal situation or hazards change. Especially for legally driven topics, what matters is how quickly updated versions – for example after a revision of standards such as DGUV Rule 100-001 in 2025 – reach the system and can be rolled out again. The more closely course assignment and actual activity can be interlinked, the more robust the instruction.
Instruction data is employee data. As a rule, its processing can be based on Art. 6 (1) lit. c GDPR because occupational health and safety law requires documentation. It should be noted that, following the case law of the European Court of Justice (judgment of March 30, 2023, C-34/21), Section 26 of the Federal Data Protection Act (BDSG) is no longer suitable without restriction as an independent legal basis; processing should therefore be based on the legal grounds of the GDPR. This is not an LMS feature, but it is the framework in which the system is operated.
When selecting a cloud-based LMS, the checklist should therefore include: a Data Processing Agreement under Art. 28 GDPR, hosting in the EU or documented safeguards for transfers to third countries, a deletion concept with configurable retention periods in the spirit of data minimization (Art. 5 GDPR), and a clean role and permission concept so that only authorized persons can view records. These points should be clarified early in the selection process – they are difficult to renegotiate later.
To keep content portable and track progress cleanly, open standards are useful: SCORM and the newer standard xAPI (with the cmi5 profile) govern how course content communicates with the LMS. Anyone who wants to keep content provider-independent in the long term should look for corresponding compatibility – this way, courses can later be transferred to another system without data loss.
Because instruction must be given "in an understandable form and language" (DGUV Rule 100-001), multilingual support and a low-threshold, easily understandable presentation – for example with images and videos – are a real criterion, especially in companies with mixed workforces. Low-barrier design is advisable from a professional standpoint; whether and to what extent the Accessibility Strengthening Act (BFSG, applicable since June 28, 2025) applies to a specific, internally provided LMS for instruction depends on the individual case and should be examined separately.
Section 12 ArbSchG requires initial instruction before work begins. To make sure this succeeds reliably in everyday practice, an LMS should automatically provide new employees with the appropriate mandatory training – ideally triggered from the onboarding or HR process. An interface to the HR system, or at least a clean import, prevents joiners, transfers, and leavers from having to be updated manually and instruction from being overlooked.
For larger organizations, single sign-on and clear role logic are also helpful so that managers can see the status of their team without gaining insight into other people's records. It pays to look at scalability early: whether several locations or companies can be managed separately and whether the system remains performant as the number of users grows determines whether an LMS that fits at the start will also hold up as the organization grows. The better the LMS is embedded in existing processes, the lower the ongoing maintenance effort.
An LMS carries the instruction process from assignment through the check of understanding to proof – but it does not relieve the employer of the legal responsibility for selection and delivery. Some instruction cannot be handled purely digitally: for hazardous substances, for example, Section 14 GefStoffV requires instruction to be given orally and with reference to the workplace; according to DGUV Rule 100-001, electronic learning media may only supplement such instruction, not replace it. An LMS should support such cases by allowing blended learning – the combination of e-learning and a documented classroom or practical part. Which instruction is needed in which form is therefore not decided by the system: the course is set by the company's risk assessment.
Anyone assessing an LMS for mandatory training can work through the criteria as a short list:
You can find further articles on instruction obligations in our knowledge hub on Occupational Safety & Fire Protection. How far a system covers these criteria differs from provider to provider; the legal bases cited do not tie you to any particular product.
A note on our own behalf: Bridgly provides ready-made instruction with integrated proof for standardized mandatory topics in occupational safety and fire protection. If you do not want to build these topics yourself but would rather use them fully rolled out and documented, you can find an overview on our page on occupational health and safety and fire protection training courses.
Yes, provided there is a reference to the workplace, a check of understanding, and an opportunity to ask questions. DGUV Rule 100-001 (06/2025) generally treats electronic aids as a regular form of instruction but ties them to exactly these conditions. Pure self-study without an assessment is not sufficient; an appropriately equipped LMS, on the other hand, firmly anchors assessment, the opportunity to ask questions, and proof in the process. Where specialist law requires oral or practical instruction – for example Section 14 GefStoffV for hazardous substances –, electronic learning media may only supplement it, not replace it; in that case, a documented practical or classroom part is also required.
Under Section 4 DGUV Regulation 1, at least once a year, and additionally when there is a specific occasion – for example with new work equipment, changed activities, or after an accident. An LMS with deadline management makes these repetitions plannable.
DGUV Regulation 1 prescribes neither a specific form nor a signature. However, individual state regulations – for example Section 14 GefStoffV – can impose stricter requirements on documentation. A documented confirmation makes proof easier.
A Data Processing Agreement under Art. 28 GDPR, hosting in the EU or safeguards for transfers to third countries, a deletion concept with retention periods, and a role and permission concept. As a rule, instruction data is processed on the basis of Art. 6 (1) lit. c GDPR.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.