Making it everyone's practice.
WHY IT MATTERS
Most breaches involve people, not technology.
WHAT COMMON HUMAN CAUSES LOOK LIKE
Email sent to the wrong recipient Attachments containing more than intended Data shared without authority Credentials disclosed to a caller Devices lost
WHAT TRAINING SHOULD COVER
What personal data is The principles, briefly What staff must do and not do How to recognise and report a breach How to handle a rights request Who to ask
WHAT TO EMPHASISE
Reporting immediately, without fear of blame.
WHY
The notification clock depends on it.
WHAT MAKES TRAINING FAIL
Annual sessions nobody remembers Generic content unrelated to their work No examples
WHAT WORKS BETTER
Short, role-specific, with realistic scenarios.
WHAT TO INCLUDE FOR SUPPORT STAFF
Verification before disclosure What may be shared with whom
WHAT TO INCLUDE FOR MARKETING
Consent rules Suppression lists
WHAT TO INCLUDE FOR TECHNICAL STAFF
Production data in test environments Logging of personal data
WHAT TO RECORD
Who was trained, when, and on what.
WHY
It is part of demonstrating accountability.
WHAT TO REPEAT
After incidents, and when practice changes.