To get the best help for your situation, first answer the questions on the guide's start page.
- Guide's start page
- Introduction to digital security risk management
- Risk management
- Safety and security management
- Continuity management and preparedness
- Information security
- Data protection
- Checklist
Provide training and assess the implementation of data protection
The management is responsible for ensuring adequate training and monitoring the implementation of data protection
It is the senior management’s responsibility to ensure that sufficient training on data protection and data protection risks is available for the staff. The management is also responsible for ensuring that the implementation of data protection is planned and documented and that its implementation is also monitored in a documented manner.

Ensure adequate training for the entire organisation
Management and employees must be familiar with their own roles and areas of responsibility in the processing of personal data and data protection. Training is one of the organisational means mentioned in data protection regulation that ensures that data protection is implemented.
Therefore, ensure that the management and employees of the organisation
- have received sufficient training on data protection and data protection risks
- are aware of up-to-date instructions related to data protection and data protection risks.
Assess success and develop activities
By assessing and measuring the development of data protection work, you can identify data protection risks to which the organisation must primarily allocate resources. The development of data protection and its assessment must be documented and the documentation maintained appropriately.
Data protection poses risks to the organisation the same as all other functions. Processes related to data protection should therefore be regularly
- planned
- documented
- implemented
- assessed and
- updated.