Training is the part of a privacy program people notice least until something goes wrong. A policy nobody has read doesn’t stop a support agent pasting a customer record into an AI tool, and it doesn’t help an engineer decide whether a new feature needs a Data Protection Impact Assessment. Training is how the policies your DPO writes turn into what your teams actually do.
Key takeaways
- GDPR Article 39(1)(b) lists awareness-raising and training of staff involved in processing operations among the tasks of the Data Protection Officer.
- Engage runs data protection and AI training for product, engineering, sales, and HR teams.
- Your DPO also builds an internal AI policy, setting out approved and non-approved uses of AI, as part of the documentation package.
- Privacy training is €750 per session at client rates on Privacy Advisory and DPO Foundation, and included in scope on DPO Partner and DPO Complete.
What the law says
GDPR puts training inside the DPO role. Article 39(1)(a) makes it the DPO’s task to inform and advise the controller or processor and the employees who carry out processing of their obligations. Article 39(1)(b) makes it the DPO’s task to monitor compliance with the Regulation and with the company’s own data protection policies, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits.
That’s why training materials and the privacy training program are both on the checklist of our privacy program audit: training is part of how you show the DPO role is working rather than sitting on paper.
Why AI is in it
Most teams now use AI tools every day, and the risk is ordinary rather than exotic: confidential or personal data going into a tool, or into large-language-model training, that your company never approved. The fix we recommend is an internal AI policy that sets out approved and non-approved uses of AI, and then making sure people actually know it. The AI policy is part of the documentation package your DPO builds, and training is how a policy gets used rather than filed.
Where your product itself uses AI, training sits alongside the rest of our AI work: EU AI Act readiness, AI risk assessments, and AI governance documentation. See EU AI Act compliance services.
Who it is for
- Product teams, who decide what personal data a new feature collects and why.
- Engineering teams, who build it and whose new products and features may need a DPIA.
- Sales teams, who field the privacy questions in enterprise deals and questionnaires.
- HR teams, who handle employee personal data every day.
How Engage Compliance helps
Data protection and AI training for product, engineering, sales, and HR teams is part of our outsourced DPO services, delivered by the same named DPO who writes your policies and knows your processing. Privacy training is €750 per session at client rates on Privacy Advisory and DPO Foundation, and it’s included in scope on DPO Partner and DPO Complete. The full plan list is on the pricing page.