GDPR Training Records: What UK Employers Must Keep

๐Ÿ“… 2025-06-24 โฑ 6 min read

The ICO expects every UK organisation to demonstrate that staff have received data protection training. Here is exactly what records you need and how long to keep them.

Since the UK GDPR came into force, the Information Commissioner's Office has made clear that data protection training is not optional. Article 39 of the UK GDPR requires Data Protection Officers to oversee staff training, and Recital 39 emphasises that employees handling personal data must be made aware of the risks involved. In practice, this means all UK employers โ€” not just those with a DPO โ€” should be running and recording GDPR training.

What training records must you keep?

There is no single prescribed format, but the ICO expects organisations to demonstrate accountability under Article 5(2) of the UK GDPR. Practically speaking, your training records should capture:

How long must you keep GDPR training records?

The UK GDPR does not specify a mandatory retention period for training records, but most UK data protection advisors recommend retaining them for the duration of the employee's employment plus at least two years after they leave. This ensures you can demonstrate compliance during an ICO investigation even if the complaint is raised after someone has moved on.

Some organisations retain records for up to six years to align with general limitation periods under the Limitation Act 1980, particularly where personal data processing touches on financial or contractual matters.

When should staff re-complete GDPR training?

The ICO does not set a mandatory refresh interval, but best practice guidance from the DCMS and ICO suggests:

What an ICO audit looks like

If the ICO investigates a data breach or responds to a complaint about your organisation, one of the first things they will ask for is evidence that your staff received data protection training. A common and expensive mistake is discovering that your training records exist in a dozen different places โ€” an email here, a spreadsheet there, a PDF on someone's hard drive โ€” and cannot be produced quickly.

Organisations that have a single, auditable record of all training completed โ€” with timestamps, certificate attachments, and expiry dates for roles requiring annual renewal โ€” are far better placed to demonstrate compliance and avoid enforcement action.

Practical steps to get compliant

  1. Audit your current GDPR training records: who has completed training, when, and do you hold the evidence?
  2. Identify gaps โ€” new starters who haven't been trained, and staff who completed training more than two years ago.
  3. Book or deliver refresher sessions and record completion with dates and evidence.
  4. Centralise all records in one system โ€” not a spreadsheet. You need to be able to produce records at short notice.
  5. Set calendar reminders (or use software that does it automatically) for upcoming renewals.
  6. Review your records policy so departing employees' training histories are retained for the required period.
TrainTrack stores training certificates alongside their expiry dates, sends automatic renewal reminders, and gives you a complete audit trail โ€” everything the ICO expects to see. Try it free at trackmytraining.co.uk.