Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
Training records serve best as evidence when they make it possible to establish the person, the content and the day of training that took place before the event examined by the authority. I recommend basing the record on a programme with references to the procedures and their versions together with the materials, a named list of participants with the date and the result of the check and a link to the authorisation, because such a record also helps the data controller demonstrate compliance with the principles of processing (Article 5(2) GDPR). The participation in training of the head of an essential or important entity and of the person entrusted with the head’s duties in the area of cybersecurity has to be documented regardless of the content of internal documentation (Article 8e(3) of the Act on the National Cybersecurity System, the KSC Act). An important entity that is a public entity also documents the training set out in its system compliant with Annex 4 (Part I point 17 and Part IV), and essential and important entities outside the banking and financial market infrastructure sectors in my assessment document training in the security of the information system used in the process of providing the service if their normative documentation provides for it (Article 10 of the KSC Act).
Why this question arises at all
The Act on the National Cybersecurity System (KSC) expressly addresses the documenting of training in Article 8e(3). The provision states that participation in training is documented. It concerns the training of the head of an essential or important entity and of the person entrusted with the head’s duties in the area of cybersecurity (Article 8e(1)). An important entity that is a public entity also documents the implementation of the actions set out in its system, which include training (Annex 4, Part I point 17 and Part IV). The GDPR contains no similar provision.
The other provisions on training, staff awareness and accountability describe an outcome or a measure, not a training document. For example, the controller must be able to demonstrate compliance with the principles of processing (Article 5(2) GDPR). The head of an essential or important entity ensures that personnel are aware of the obligations in the area of cybersecurity and know the entity’s internal rules in that area (Article 8d(4) of the KSC Act). None of these provisions specifies what a document confirming training should look like.
In practice training is usually documented from the perspective of the day on which it took place. The result is an attendance list, a certificate or a report from a platform. The authority asks later and from a different perspective. After a breach or an incident the question may concern one person and one procedure on the day of the event. A record reading “GDPR training, March, 40 people” does not provide such an answer.
What has to be established before a decision
What training records consist of
I recommend a set of five elements, because each answers a different question from the authority.
| Record element | Which question it answers | What it does not show on its own |
|---|---|---|
| Training programme with references to the procedures and their version numbers | What the participants were taught | Whether the participants understood it |
| Named list of participants with the date, the form of the session and the role of each person | Who completed the training and when | What the training covered |
| Materials given to participants | What the participant can use after the session | Whether they use them |
| Form and result of the knowledge check | What the participant remembered | Whether their behaviour changed |
| Link to the person’s authorisation or tasks and to the date access was granted | Why the training concerned this person and whether it took place before they were admitted to the data or the system | What the scope of the training was |
An attendance list on its own shows that people attended the session. It does not show what they were taught.
Remember
It is advisable for the programme to be the core of the records and for the list to be an annex to it.
Programme and procedure versions. The name “information security training” does not make it possible to establish what the person learned on a given day. A programme with a reference to the procedure and its version number makes that possible. This works only when procedures have versions. Under the KSC regime marking successive versions of documents is part of the supervision of documentation (Article 10(6)(3)).
List of participants and date. A record generated by the system at the time of the training is usually stronger evidence than a list completed later, because it shows the situation on the day of the training. A report generated from the platform only after an incident or a breach can in turn be misleading. It may show the current version of the module instead of the version from the day of the training. It is advisable to archive the programme and the list of participants on the day the training ends and to collect the participant’s signature with the date and the programme version number at in-person sessions. It is advisable to record absence in the same way as participation, together with the date of the make-up training. It is worth requiring the provider of external training to supply the programme and the list of participants with the date, not just a certificate bearing the name of the training.
Knowledge check and effectiveness. The result of a test after the session shows primarily what the participant remembered. That is not enough to assess effectiveness. I recommend recording the training objective as the expected behaviour, the result of measurement before and after the session, the conclusion from the comparison and the decision taken on that basis together with its date. The basis lies in the provisions on assessing the effectiveness of measures. The GDPR lists regularly testing, assessing and evaluating the effectiveness of measures for ensuring the security of the processing among the measures implemented where appropriate (Article 32(1)(d)). The KSC Act requires an essential or important entity to have policies and procedures for assessing the effectiveness of technical and organisational measures within the information security management system (Article 8(1)(2)(h)). This does not apply to entities that implement a system compliant with Annex 4 instead of Article 8(1) (Article 8(3)) or to the banking and financial market infrastructure sectors (Article 8i(1)). Indicators of effect and the timing of measurement are described in How do you know that training produced a real effect?.
Link to the authorisation. I recommend recording the date of the training next to the date on which the authorisation or access was granted. After a breach this comparison shows whether the person worked with the data before the training. Article 29 GDPR covers any person acting under the authority of the controller or of the processor who has access to personal data. The authorisation is therefore a natural key by which the organisation will find a given person’s training. Under the KSC regime the starting point may be the list of persons performing the tasks referred to in Article 8 or Article 11, supplemented by the other users of the system. Before starting those tasks the person who is to perform them as a rule presents to the entity information from the National Criminal Register confirming that they have not been convicted of offences against the protection of information (Article 8f(1)). The starting list may be a list of the persons admitted to those tasks, without the content of the information from the register itself.
How to document the participation of the head of the entity
The head of the entity and the person entrusted with the head’s duties in the area of cybersecurity undergo training once per calendar year (Article 8e(1)). Article 8e(3) does not specify who documents participation or in what form. The scope of the training covers the performance of the obligations under the provisions listed in Article 8e(2). I therefore recommend that the programme for the head of the entity refer to those obligations, not to personnel procedures. It is advisable to keep the record of the head of the entity in the same register as the personnel records. Article 8e does not require a knowledge test. The effect of the head’s training is visible rather in their decisions under Article 8d, such as planning financial resources and assigning tasks.
In my assessment the absence of a record of participation means that the obligation under Article 8e has not been fulfilled. The head of the entity may then be subject to a financial penalty if the duration, scope or nature of the infringement justifies it (Article 73a(1)(4)). The head may also be subject to it in the case of a one-off omission (Article 73a(2)). On the same terms the head of the entity may be subject to a penalty for failure to fulfil the obligations under Article 10(1) and (6) to (8) (Article 73a(1)(8)). For failure to fulfil the obligations under Article 10(1) the entity is subject to a penalty (Article 73(1)(4)). Penalties relating to Article 10 concern the obligations under that Article, so the absence of training records can be a basis for them only where those records form part of the documentation under Article 10(2). Penalties under Article 73(1) to (4) and Article 73a may be imposed for the first time two years after the amendment entered into force (Article 35 of the amending act). Entities from the banking and financial market infrastructure sectors apply Articles 8c to 8f accordingly (Article 8i(2)).
When training records become operational documentation
The KSC Act divides documentation on the security of the information system used in the process of providing a service into normative and operational documentation (Article 10(2)). Operational documentation consists of records attesting to the performance of activities required by the provisions of the normative documentation (Article 10(4)). Normative documentation includes the documentation of the information security management system (Article 10(3)(1)). In non-binding answers to questions about the amendment the Ministry of Digital Affairs states that the documentation of that system should cover all the elements listed in Article 8. One of them is cybersecurity education for the entity’s personnel (Article 8(1)(2)(i)).
The provision on personnel education does not itself mention a document. In my assessment the requirement to keep a record follows indirectly from Article 10, because training records become operational documentation. On that reading the condition is that the normative documentation provides for training and that the record attests that it took place. On that reading the second condition is a link between the training and the security of the information system used in the process of providing the service, because the documentation under Article 10(1) concerns only that system. Training in personal data protection alone that is unrelated to that system does not meet that condition. Personnel education under Article 8(1)(2)(i) included in the documentation of the information security management system meets it, because the Act classifies the documentation of that system as normative documentation and normative documentation as documentation on the security of the information system used in the process of providing the service (Article 10(2) and (3)(1)). Where training records are operational documentation, the entity establishes supervision over them that ensures access only for persons authorised in line with their tasks (Article 10(6)(1)). Supervision also covers the protection of documents against inter alia destruction and loss of integrity and the marking of successive versions (Article 10(6)(2) and (3)). The documentation may be kept on paper or in electronic form (Article 10(5)).
An important entity that is a public entity does not apply Article 8(1) and implements a system that meets the requirements of Annex 4 (Article 8(3)). The system required by that provision covers at least the elements of Part I of the Annex, including training of persons involved in processing information (Annex 4, Part I point 17). That entity documents the implementation of the actions set out in the system (Annex 4, Part IV), so for that entity the obligation to document training follows from the two parts of the Annex read together. In my assessment the same applies to the part of important entities from higher education and science indicated in Article 8(3) as regards public tasks carried out using information systems.
Entities from the banking and financial market infrastructure sectors do not apply the provisions of the Act concerning the information security management system, with the exceptions listed in Article 8i(1). In my assessment Article 10 is among the excluded provisions at least as regards the documentation of the system, and therefore also training records. It covers the documentation of the information security management system (Article 10(3)(1)) and is not among the exceptions in Article 8i(1).
The entities listed in Article 8b(1) (among others DNS service providers, cloud computing service providers and managed service providers) apply within their system the measures set out in Commission Implementing Regulation (EU) 2024/2690. In my assessment trust service providers also apply them, because Article 8b(2) refers to acts adopted under Article 21(5) of Directive 2022/2555 and that Regulation is such an act and covers them in Article 1. The Annex to the Regulation requires an awareness raising programme for employees, including members of management bodies, which is tested in terms of effectiveness where appropriate (points 8.1.1 to 8.1.3). It also requires a training programme and an assessment of the effectiveness of training for roles relevant to security (points 8.2.1 to 8.2.3).
Entities that on 3 April 2026 met the conditions for being recognised as an essential or important entity fulfil the obligations under Chapter 3 of the KSC Act by 3 April 2027 (Article 33(1) and Article 49 of the amending act). That chapter includes Article 8e, Article 8f and Article 10. An entity that meets the conditions later has 12 months from the day it meets them (Article 16(1) of the KSC Act). An entity recognised by a decision counts that period from the delivery of the decision (Article 7l(7) and Article 7m(6)).
Where and for how long to keep training records
A provider of an e-learning platform that processes personnel data on behalf of the organisation is a processor (Article 4(8) GDPR). The data processing agreement or other legal act stipulates that after the end of the provision of services relating to processing the provider deletes or returns the data at the choice of the controller and deletes existing copies. The exception is a situation in which Union law or Member State law requires storage of the data (Article 28(3)(g)). It is advisable to decide on the return of data and the export format already in the agreement, because otherwise the training history may disappear together with the account on the platform.
The GDPR does not set a retention period for training records. Personnel data may be kept in them in a form which permits identification for no longer than is necessary for the purposes of processing (Article 5(1)(e)). The same provision allows the data to be stored for longer only where they are processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to appropriate safeguards. In this situation the purpose of storage is usually to demonstrate compliance, so it is from that purpose that the organisation derives the period. It is advisable to record the period with its justification in the retention policy and in the record of processing activities, which contains the envisaged time limits for erasure where possible (Article 30(1)(f)). The exemption from the obligation to maintain the record for an enterprise or an organisation employing fewer than 250 persons does not apply inter alia to processing that is not occasional (Article 30(5)). Training records are kept continuously, so that exemption usually does not cover them.
Under the KSC regime a record that is operational documentation is kept for at least two years from its withdrawal from use or from the end of the provision of the service. The provision adds that the retention period of the documentation is “counted from 1 January of the year following the year in which its retention period expires” (Article 10(7)). It is safer to count two years from 1 January of the year following the year of withdrawal or of the end of the service, because this gives a longer period than counting from the day of withdrawal. The retention provision does not apply to entities subject to the Act on the National Archival Resource and Archives (second sentence of Article 10(7)). The destruction of withdrawn documentation is confirmed by a disposal report, which is kept permanently (Article 10(8)). Entities applying Regulation 2024/2690 also specify in their security policy the documentation to be kept and its retention period (Regulation 2024/2690, Annex, point 1.1.1(h)).
To whom and under what procedure training records have to be shown
Training records are sometimes read first by the data protection officer. The officer monitors compliance with data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the training of staff involved in processing operations (Article 39(1)(b) GDPR).
As part of its investigative powers the supervisory authority may order the controller and the processor to provide any information it requires for the performance of its tasks (Article 58(1)(a) GDPR). In Poland this authority is the President of the Personal Data Protection Office, the UODO (Article 34(2) of the Act on the Protection of Personal Data). In an inspection conducted by the President of the UODO the inspector has access to documents and information directly related to the subject matter of the inspection. To the extent necessary to establish the facts the inspector may request explanations and hear witnesses (Article 84(1)(2) and (4) of the Act on the Protection of Personal Data). A witness may be an employee of the inspected entity, a term that also covers a person working under a civil law contract (Article 86(1) and (2) of that Act).
The competent authority for cybersecurity may request from an essential entity access to documents and the presentation of evidence of compliance with the requirements of Article 8(1) (Article 53(2)(5) and (6)). In relation to an important entity these powers apply in ex post supervision (Article 53(3)(2) and Article 53(17)). At the authority’s request an essential or important entity provides the data, information and documents necessary for supervision and inspection (Article 53c(1)). The request specifies the documents and the period they concern. It also specifies a deadline appropriate to the scope of the request, not shorter than 7 days (Article 53c(2)(3) and (5)).
The inspector establishes the facts on the basis of the evidence collected. It includes in particular documents and objects, visual examinations and explanations and statements. This is provided for in Article 87 of the Act on the Protection of Personal Data and, in an inspection of an entity that is an entrepreneur, also in Article 57 of the KSC Act. A training document may therefore be set against other evidence, including the account of the trained person, and a record that contradicts that account may lose its evidential value.
Common mistakes
- An attendance list instead of a programme. A record reading “GDPR training” does not show which procedure and which version of it the record concerned.
- No link to the person’s authorisation or tasks. Years later it is then difficult to establish why a given person was on the list or why they were missing from it.
- Training history held only by the platform provider. Without a decision on the return of data it may end together with the agreement.
- Training not described in the normative documentation. Under the KSC regime the record then has no provision whose performance it attests (Article 10(4)).
- No deletion rule. Records disappear by accident or are kept indefinitely. Where they are operational documentation under the KSC Act, they are sometimes destroyed without a disposal report.
Conclusions and next steps
Training records have to answer a question that may be asked years later and may concern one person. That is why it is worth designing them from the perspective of the programme and its link to the procedures, not from the perspective of an attendance form. I recommend the following steps.
- Check whether the documentation of the information security management system or the data protection policy specifies training, its audience and its cycle.
- For each training session keep a programme with references to the procedures and their versions. Attach the named list of participants with the date and role, the materials and the result of the check to the programme and archive them on the day the training ends.
- Link the record to each person’s authorisation or tasks and to the date access was granted.
- Document the participation in training of the head of the essential or important entity and of the person entrusted with the head’s duties in the area of cybersecurity in each calendar year together with a programme linked to the obligations under the provisions listed in Article 8e(2).
- Place the records under supervision covering access, integrity and versions.
- In the agreement with the platform provider settle the return of data and the export format.
- Set the retention period and record its justification. Where the records are operational documentation under the KSC Act, confirm their destruction with a disposal report.
- Choose one person and one procedure. Check whether the records make it possible to reconstruct what that person learned before a chosen date.
Related materials
- How often should employees be trained on data protection? — how to set the rhythm of training and what triggers training outside the schedule.
- What should NIS2 training for the board cover? — the scope of training for the head of the entity set by Article 8e(2).
- Who else needs NIS2 training besides the management board? — how to define the group of persons to be trained beyond the management board.
- How do you know that training produced a real effect? — indicators of effect that complement the record of participation.
Sources
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), consolidated version — Article 4(8), Article 5(1)(e) and (2), Article 28(3)(g), Article 29, Article 30(1)(f) and (5), Article 32(1)(d), Article 39(1)(b) and Article 58(1)(a) — eur-lex.europa.eu.
- Act of 5 July 2018 on the National Cybersecurity System, consolidated text as at 18 August 2026 — Article 7l(7), Article 7m(6), Article 8(1) and (3), Article 8b(1) and (2), Article 8c, Article 8d(2) to (4), Article 8e, Article 8f(1), Article 8i(1) and (2), Article 10, Article 11, Article 16, Article 53(2), (3) and (17), Article 53c(1) and (2), Article 57, Article 73(1) to (4) (including (1)(4)), Article 73a (including (1)(4), (1)(8) and (2)) and Annex 4, Parts I and IV (in Polish) — isap.sejm.gov.pl.
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Article 33(1), Article 35 and Article 49 (in Polish) — dziennikustaw.gov.pl.
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 — legal basis (first subparagraph of Article 21(5) of Directive 2022/2555), Article 1 and Annex, points 1.1.1(h), 8.1.1 to 8.1.3 and 8.2.1 to 8.2.3 — eur-lex.europa.eu.
- Act of 10 May 2018 on the Protection of Personal Data, consolidated text as at 18 August 2026 — Article 34(2), Article 84(1)(2) and (4), Article 86(1) and (2) and Article 87 (in Polish) — isap.sejm.gov.pl.
- Ministry of Digital Affairs, Q&A on the amendment of the KSC Act, update of June 2026 — question 3.5 (in Polish) — gov.pl.
Let us agree how training should be recorded in your organisation
If training records in your organisation today are mainly attendance lists, the first step is to identify the roles and procedures the programme should refer to. Training and workshops tailored to roles and processes start with that diagnosis.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: September 2026.