Short answer
The GDPR does not specify training frequency — there is no provision in it that would indicate “once a year” or any other interval. The controller’s obligation is to ensure that individuals processing data know how to proceed in their processes and to demonstrate this state with evidence. An annual cycle is often a reasonable benchmark for the entire organization, but the actual rhythm is set by changes in processes, employee turnover, conclusions from incidents, and test results. It is different in the cybersecurity regime: the amended Act on the National Cybersecurity System (KSC) directly specifies the training frequency for the entity’s manager.
Why this question arises at all
The question of frequency usually arises at two moments: when an organization is building a training schedule for the coming year and needs to enter a number, and when an auditor or authority asks when the last training took place and who it covered. In both cases, a single number is expected, but the regulations do not provide one.
The source of doubt is the structure of the GDPR itself. The Regulation does not impose a training obligation as an end in itself — it builds requirements around the result. The controller must implement technical and organizational measures appropriate to the risk and be able to demonstrate this (Art. 24 sec. 1), ensure that persons acting under its authority process data only on its instructions (Art. 29 and Art. 32 sec. 4), and regularly test, measure, and evaluate the effectiveness of these measures (Art. 32 sec. 1 lit. d). Training is one of the tools by which these requirements are met, not a separate obligation with its own deadline.
This difference has practical consequences. An organization that asks “is once a year enough” is asking something that cannot be resolved in isolation from its processes. An organization that asks “what needs to happen for us to train people before a change” is asking a question for which an answer exists.
It is worth separating training from technical security. The Provincial Administrative Court in Warsaw, in a case discussed by the UODO, ruled that a controller’s limitation to training alone, without technical safeguards, does not constitute the implementation of appropriate measures. Training changes how people act — it does not replace encryption, access control, or procedures.
What needs to be determined before making a decision
Who we are actually training
“All employees” is a category that most often dilutes the training program and means that no one receives content useful in their work. The starting point is a division into groups that process data differently and bear different risks: newly hired and changing positions, process owners, high-exposure teams (HR, customer service, sales, marketing, recruitment), IT and security departments, management staff, and the Data Protection Officer.
This division determines frequency more than the calendar. A team where one-third of the members change during the year needs ongoing induction training, not a single event in November.
What has changed since the last training
The training cycle should respond to changes that genuinely alter how data is processed. In practice, this involves four types of events: launching or significantly redesigning a processing operation, implementing a new system or changing a vendor with access to data, changing the legal status or regulatory body’s position affecting organizational obligations, and organizational change — a new structure, acquisition, or centralization of services.
If none of these events occurred in a given year, repeating the same training “because a year has passed” provides proof of attendance but changes little in behavior. If three occurred, the annual schedule is already outdated at the time of approval.
What incidents and reports say
The most reliable indicator of training needs are events that actually occur in the organization. Incorrect addressing of correspondence, sending to multiple recipients in the “cc” field, handing over documents to the wrong person, opening an attachment from a phishing email, using private tools to process work data — each of these indicates a specific group and a specific topic.
In practice, it is worth linking the register of breaches and internal reports with the training plan as a constant input, rather than as an ad hoc reaction after a more prominent event. If the organization is only just organizing the process of identifying and assessing such events, assessing incidents and breaches is an earlier step than planning training.
How do we measure effectiveness
Article 32 sec. 1 lit. d of the GDPR requires regular testing, measuring, and evaluating the effectiveness of measures. Since training is an organizational measure, this requirement also applies to it. Organizations use knowledge tests after training, controlled phishing simulations, review of suspicious message reports, analysis of the repeatability of the same errors in subsequent periods, and short checks as part of internal audits.
The measurement result is what justifies changing the frequency. A group that repeats the same mistake in a test needs a shorter cycle and a different form of activity — not another presentation on general principles.
How do we prove that training took place
The accountability principle (Art. 5 sec. 2) shifts the burden of proof to the controller. In practice, this means that a set of documents has evidential value: the scope and program of activities, a list of participants with the date, materials provided to participants, the result of a test or other form of verification, and the link between training and data processing authorizations. A mere attendance list shows that people were present — it does not show what they were taught.
This is evident in supervisory practice. In decision DKN.5131.34.2023 of June 13, 2026, the President of the UODO found that the controller conducted employee training only after a breach, and the submitted training reports were from the period following the incident. Evidence created after an event does not replace evidence from the period to which the proceedings relate.
What other regimes cover the same organization
Some organizations are subject to both the GDPR and cybersecurity regulations, and the latter treat frequency differently. The amended KSC Act stipulates that the manager of a key or essential entity and the person entrusted with the manager’s cybersecurity duties must undergo training once per calendar year (Art. 8e), and participation in the training must be documented. The Ministry of Digital Affairs indicates the manager’s training obligation as one of the changes introduced by the amendment. For personnel, the act does not specify an interval — it requires ensuring knowledge of cyber threats and cyber hygiene principles as part of the information security management system.
The ISO/IEC 27001:2022 standard remains a voluntary reference point, which in Annex A provides for control 6.3 concerning information security awareness, education, and training. Applying the standard is not a legal obligation, but certified organizations must expect an auditor’s question about the cycle and effectiveness.
In practice, this means one thing: an organization covered by both regimes does not need two independent training programs, but one plan where the strict KSC deadline sets the rhythm for managerial roles, and the GDPR criteria define the scope for other groups.
Variants by role
The following summary is a practical assessment based on the typical organizational structure of a medium to large organization. It does not stem from regulations and requires confrontation with the risks of specific processes.
| Group | What triggers training | Rhythm applied in practice | How to demonstrate |
|---|---|---|---|
| Newly hired and changing positions | Granting data access, change of responsibilities | Before allowing processing, not on an annual cycle | Linking training to authorization and date of access grant |
| High-exposure teams (HR, customer service, sales) | Process change, recurring errors, conclusions from incidents | Shorter formats more frequently than once a year, tailored to the process | Thematic program, test results, incident report summary |
| Process owners | Process launch, DPIA, vendor change | Upon change and periodically | Workshop notes, process decisions, trace in process documentation |
| IT and security departments | Architecture change, new threats, post-breach conclusions | Continuous competence development, regardless of the general cycle | Competence development plan, certificates, exercises |
| Management staff | Managerial responsibility, KSC obligations | Statutory requirement under KSC — once per calendar year; under GDPR determined by the organization | Certificate, program, participation documentation |
| Data Protection Officer | Legal changes, regulatory guidelines, supervisory practice | Continuous knowledge updating | Participation in training and conferences, provided resources |
Guidelines for Data Protection Officers (WP243 rev.01), approved by the European Data Protection Board, indicate continuous training as a resource that the controller should provide to the officer. This requirement applies to the DPO role, not personnel — if the organization is also considering how to fill this function, the appropriate starting point is support from an external DPO.
Most common mistakes
- Treating the annual cycle as a legal obligation. The annual interval is an organizational practice. Referring to it as a GDPR requirement misleads management and makes it difficult to defend one’s position in case of an inspection.
- One training for all roles. Material general enough to fit every department usually does not change behavior in any of them.
- Stopping at the attendance list. Proof of participation without scope, materials, and knowledge verification shows that training took place, but not what it covered.
- Training as the only response to an incident. After a breach resulting from human error, training is one of the corrective actions, not a substitute for process change or technical security.
- Lack of connection with the register of processing activities and authorizations. Without this connection, it is impossible to demonstrate that individuals processing data in a specific process have been trained in its scope.
Conclusions and next steps
The question “how often” leads to a schedule that ages faster than the organization. It is more practical to establish two things at once: a minimum baseline rhythm that maintains awareness throughout the organization, and a list of events that trigger training outside the schedule. The first part provides predictability, the second — a reaction to change.
The sequence of actions that works well when organizing this area:
- Map target groups by processes and risk, rather than by organizational structure.
- Name training triggers outside the cycle: new process, new system or vendor, legal change, organizational change, conclusions from an incident.
- Establish a baseline rhythm for each group and document its justification — this justification, not just the date, is the essence of accountability.
- Choose a method for measuring effectiveness for each group and determine what result triggers a cycle correction.
- Link training documentation to processing authorizations and the register of processing activities.
- If the organization is subject to KSC, include the statutory deadline for management in the plan and treat it as a fixed point around which you arrange the rest.
After going through this sequence, the answer to the title question ceases to be a number and becomes a principle that the organization can justify and demonstrate.
Related materials
- How to determine if an organization must appoint a DPO? — who in the organization is responsible for activities increasing personnel awareness and training.
- Does every data breach need to be reported? — how to assess events whose conclusions should be included in the training plan.
Sources
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), consolidated text — EUR-Lex: eur-lex.europa.eu (accessed: 2026-08-17)
- Act of January 23, 2026, amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Dziennik Ustaw: dziennikustaw.gov.pl (accessed: 2026-08-17) (in Polish)
- Amendment to the Act on the National Cybersecurity System — Ministry of Digital Affairs, Gov.pl Portal, published 2026-04-14: gov.pl (accessed: 2026-08-17) (in Polish)
- Obligations of controllers related to personal data breaches, version 1.0 (June 2019) — Personal Data Protection Office: uodo.gov.pl (accessed: 2026-08-17) (in Polish)
- WSA: an employee cannot replace the controller in fulfilling their obligations, communication of 2022-04-11 — Personal Data Protection Office: uodo.gov.pl (accessed: 2026-08-17) (in Polish)
- Decision of the President of the UODO DKN.5131.34.2023 of June 13, 2026 (not final) — UODO rulings database: orzeczenia.uodo.gov.pl (accessed: 2026-08-17) (in Polish)
- Guidelines for Data Protection Officers (WP243 rev.01), approved by the European Data Protection Board, translation on the UODO website: uodo.gov.pl (accessed: 2026-08-17) (in Polish)
- ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements: iso.org (accessed: 2026-08-17)
Let’s determine what the training cycle in your organization should look like
If your organization’s training program currently relies on a single annual event, the first sensible step is to define target groups, triggers, and how to demonstrate effectiveness. Training and workshops tailored to roles and processes begin with this diagnosis.
This material is general and educational in nature. It does not constitute individual legal advice or recommendations for a specific organization. The scope of obligations should be assessed taking into account its specific situation.
Legal status: August 2026.