Practice area 05
Privacy Training and Awareness
Annual click-through training satisfies a requirement and changes almost nothing. Privacy incidents come from specific, repeated decisions: an export to a spreadsheet, a new tracking tag, a support agent verifying identity badly. Training worth running addresses those decisions in the vocabulary of the people making them.
Frameworks in scope
- GDPR Article 39
- HIPAA workforce training
- CPRA handler training
- Security awareness requirements
Curriculum built by role
One session for the whole company teaches the engineers nothing and overwhelms the sales team. We build a short core module everyone takes, then role-specific sessions that go deep on the decisions each function actually makes.
- All staff: what counts as personal data, the handling rules that apply to it, how to recognise an incident, and how to escalate one in the first hour.
- Engineering and product: data minimisation in design, retention and deletion in practice, test data, logging, third-party SDKs, and when a design decision requires an assessment.
- Marketing and growth: consent and preference management, tracking technologies, opt-out signals, audience building, and the rules governing purchased or enriched lists.
- Sales, support and operations: identity verification, rights requests arriving through the wrong channel, oversharing in tickets, and what may be promised in a customer security review.
- Leadership and board: the obligations that sit with them personally, the questions to ask before approving a launch, and what regulators expect of governance.
Delivered against your own examples
Generic scenarios invite generic attention. Sessions are built around your systems, your data, and incidents that have plausibly nearly happened at your company, with the policies your teams are actually expected to follow on screen. Where we have done the data mapping, the examples come straight from it.
Outcomes you can point to
Training is both a control and, in several regimes, an obligation with an evidentiary requirement attached. We design for both: people who make better decisions, and a record that shows who was trained, on what, and when.
- Measured change in the behaviours the training targeted, not just satisfaction scores.
- Completion records suitable for regulators, auditors and customer diligence.
- A refresher cadence tied to onboarding, role changes and material changes in the law.
- A named route for the questions that will come up afterwards, so people ask rather than guess.
AI use training
The fastest-moving risk in most companies is employees putting confidential and personal data into AI tools that were never approved. We deliver a session covering what may be used, what must never be entered, how outputs should be checked, and why the obligation does not disappear because the tool is convenient.
What you receive
Work product, dated and defensible.
Every engagement in this area is scoped to end in artefacts you can hand to a regulator, a customer or an acquirer without rewriting them first.
- Role-based curriculum and session materials
- Live or recorded delivery with a question route afterwards
- Practical scenarios drawn from your own systems
- Knowledge checks and completion records
- Manager guidance for reinforcing the rules in daily work
- Refresher schedule tied to onboarding and legal change
How the engagement runs
Four stages, agreed before we start.
- 01
Identify the decisions
Work out where privacy risk is actually created in your company, by role and by workflow.
- 02
Write the curriculum
Build a short core module and role-specific sessions around those decisions, using your systems as the examples.
- 03
Deliver
Run the sessions live where discussion matters, and record the modules that need to reach new joiners.
- 04
Reinforce
Knowledge checks, manager guidance, refresher scheduling, and a standing route for questions.
Common questions
Asked before most engagements.
How long are the sessions?
The core module runs around thirty minutes. Role-specific sessions are typically forty-five to sixty, because the discussion is where the value sits. Leadership briefings are shorter and more direct.
Can you train our team on the AI tools we have approved?
Yes. That session is usually built alongside the AI use policy, so people are trained on the rules that actually apply to them rather than on the technology in general.
Do you provide records for our auditors?
Yes. Attendance and completion records, the materials as delivered, and the date are provided in a form you can hand to an auditor or attach to a customer questionnaire.
Related practice areas
- 01
Data Privacy Compliance
GDPR, CCPA and CPRA, HIPAA and the widening set of US state privacy laws, mapped to how your company actually handles personal data.
Read more - 02
AI Governance and Ethics Consulting
Risk assessments, governance frameworks and policy for teams deploying machine learning, so responsible AI becomes a control rather than a statement of intent.
Read more - 03
Data Security and Breach Response
Incident response planning before an event, and counsel-led investigation, notification and regulator handling during one.
Read more
Train the decisions, not the policy document.
Tell us where things have gone wrong before, and we will build the curriculum around it.