TRAINING · WORKSHOPS · GDPR · CYBERSECURITY

Training and workshops based on real-world experience

I deliver closed training sessions for employees, management, and teams responsible for data protection and cybersecurity. I tailor the program to participants’ roles, organizational processes, and real situations they may encounter.

Training is delivered primarily online. In-person sessions are also available upon request.

TRAINING DESIGNED FOR YOUR ORGANIZATION

Closed participant group

Training delivered exclusively for one organization.

Scope tailored to roles and processes

Topics and examples correspond to participants and the organization’s operations.

Online or in-person

Delivery format determined according to the training’s purpose and nature.

Materials and attendance confirmation

Scope of materials, certificates, or certificates of attendance determined individually.

Most frequently delivered training

I always tailor the scope to the organization and participants. I most frequently deliver four types of training and workshops.

GDPR for employees

For individuals who work with personal data in their daily tasks. The training helps understand basic principles, respond appropriately to typical situations, and recognize situations requiring internal reporting or consultation.

GDPR for boards and management

For individuals responsible for oversight, decisions, and process organization. The training focuses on accountability, risk, and the information that leadership should expect from the DPO, IT, compliance, and process owners.

NIS2 for boards and leadership

For individuals managing the organization and overseeing cybersecurity. The training covers the board’s role, risk management, oversight of organizational activities, and information needed for decision-making.

Dedicated training and workshops

For specific teams, processes, projects, or problems. The program may combine data protection, information security, incidents, vendor collaboration, and the accountability of individuals involved in organizational processes.

Most common training needs

Training may result from organizational obligations, changes in operations, or the need to reduce recurring errors.

New employees

New hires should understand data protection principles, information security, and the accountability associated with their work.

Obligations related to GDPR or NIS2

The organization wants to support fulfillment of obligations related to data protection or cybersecurity and document actions that develop participants’ knowledge of processes.

Organizational or technological changes

New systems, processes, services, or requirements change the way work is done and the associated risks.

Recurring errors or incidents

Training helps translate lessons from real problems into safer behaviors and more effective responses.

Training designed for your organization

I tailor the training scope to participants, their responsibilities, processes, and real situations they may encounter. I draw on experience from DPO work, data protection, IT, cybersecurity, and incident response.

Tailored to roles and processes

Operational staff, management, boards, IT, DPO, or compliance receive different scopes.

Examples from real situations

Participants work with situations similar to their daily tasks, not just definitions and regulations.

Combining law, organization, and technology

Content shows the relationships between obligations, systems, processes, and accountability for decisions.

The same topic, a different scope

The bar shows how many areas the program has to cover — not how important the role is. Each level adds something to the one before it.

Operational staff

Their own tasks and the data they use every day.

Management

Additionally the process and the team they lead.

IT, DPO and compliance

Additionally the systems and obligations they run for the whole organization.

The board

Additionally oversight and accountability for the organization as a whole.

That is why I set the scope after identifying the participants, not before. The same topic — reporting an incident, for example — means something different for each of these groups.

I prepare each program for a specific organization.

1

First, we determine the expected training outcome

2

Then the scope, format, and materials

How does the collaboration work?

Collaboration is simple and structured.

STEP 1

Identifying needs

We determine the participant group, their roles, knowledge level, and training objective.

STEP 2

Tailoring the program

We select topics, examples, and a format appropriate for the organization.

STEP 3

Preparing materials

I develop the presentation, exercises, scenarios, or knowledge test according to the agreed scope.

STEP 4

Delivering the training

Training takes place online or in-person, with the opportunity to ask questions and discuss practical situations.

STEP 5

Summary

The organization receives the agreed materials, documents confirming participation, and, if included in the scope, recommendations for further actions.

The scope may include training materials, exercises, scenario analysis, knowledge tests, certificates, or certificates of attendance. We determine details individually.

OUTCOMES

What value should the training deliver?

The goal is not simply to convey information. Training should support participants’ operations and reduce risk arising from daily decisions.

Better understanding of obligations

Participants know what they are responsible for and when they need support from the DPO, IT, a supervisor, or another appropriate person.

Reducing the risk of recurring errors

Principles are related to daily tasks where mistakes and improper habits most frequently occur.

Faster recognition of risky situations

Participants can identify situations requiring a response and know where to report them.

Better collaboration

Employees, management, IT, DPO, and compliance more easily use common terminology and understand their roles.

How it went is not the effect

WHAT DESCRIBES HOW IT WENT

  • Attendance in the room or in the meeting
  • Duration and the number of topics covered
  • The final test score
  • A certificate of attendance

WHAT DESCRIBES THE EFFECT

  • The participant recognizes a situation that needs a response
  • Knows where to report it and whom to ask
  • Changes the way a daily task is done
  • The decision taken on the basis of the result is written down

The distinction comes from the article “How do you know that training produced a real effect?” — from the same set of materials this page links to below.

EXPERIENCE

Knowledge from practice

I deliver training based on experience gained working with organizations, not solely on presenting regulations.

Over 20 years of technology experience

Practical experience working with systems, processes, vendors, and real organizational problems.

DPO + IT + Cybersecurity

Combining legal, organizational, and technical perspectives.

Working with boards and complex organizations

I tailor content and delivery to decision-makers and teams executing activities.

Real situations and incidents

Examples come from audits, implementations, breach response, and team collaboration. They are generalized and stripped of confidential information.

Frequently asked questions

Is training delivered online or in-person?

I deliver training primarily online. In-person sessions are also available upon request, particularly for workshops, management meetings, or organizational events.

Is the program tailored to the organization?

Yes. I determine the participant group, their roles, knowledge level, organizational processes, and expected outcome. Based on this, I select the scope, examples, and training format.

How long does the training last?

Duration depends on the participant group, scope, and format. It may be a brief informational session, an extended board session, or a workshop on a specific process. I determine the recommended duration after identifying needs.

Do participants receive materials?

Yes, if included in the agreed scope. These may be summary materials, presentations, exercises, scenarios, or other content supporting knowledge application after training.

Are certificates of attendance or certificates issued?

Yes. The form of attendance confirmation is determined with the organization and depends on the type of training. A certificate or certificate of attendance is part of documenting participation, not the primary training outcome.

Can training help fulfill obligations related to GDPR or NIS2?

Yes. Training can be part of the organization’s actions related to developing knowledge, awareness, and accountability. However, training alone does not replace other organizational, technical, documentation, or supervisory measures required in a specific situation.

Related services

SERVICE

NIS2 and the KSC Act

Training for leadership is one of the obligations under the Act. Full preparation also covers qualifying the entity, a gap analysis, and implementation.

See NIS2 and KSC support →

SERVICE

External DPO

When the organization needs ongoing data protection support rather than a single training session for a team.

See DPO support →

Related reading

The questions that come back when training is being planned — answered from the wording of the GDPR and the KSC Act.

KNOWLEDGE BASE

How often should employees be trained on data protection?

The GDPR sets no interval — training is matched to risk and its adequacy must be demonstrable.

Read →

KNOWLEDGE BASE

What should NIS2 training for the board cover?

The training obligation of the head of the entity under Article 8e of the KSC Act.

Read →

KNOWLEDGE BASE

Who else needs NIS2 training besides the management board?

The Act names only one more role — for everyone else the obligation is built differently.

Read →

KNOWLEDGE BASE

How do you know that training produced a real effect?

Attendance and the final test score describe how the training went, not its effect.

Read →

DISCUSSION ABOUT TRAINING NEEDS

Let’s determine the appropriate scope for your organization

Initially, information about the organization, participant group, and expected objective is sufficient. During the first conversation, we will determine the recommended scope, format, and training delivery method.

Do not submit passwords or special categories of data. The form is for arranging a conversation, not for sending documents.

REQUEST CONTACT

The data controller for information provided in the form is Michał Rutkowski, operating LabLogic Consulting. I use the data to handle the inquiry and prepare a response or offer. Details are available in the Privacy Policy.

Scroll to Top