This clause requires employees and contractors to receive training on how to handle personal data safely and follow data protection laws. Training is mandatory under UK GDPR and strongly recommended under US law because human error (like sending an email to the wrong person) causes most data breaches. For example, staff need to know they cannot share customer lists with unauthorized people or leave laptops unlocked. This clause typically specifies how often training must happen (usually annually) and may require you to keep records proving staff completed it. Regulators view training as evidence that you took data protection seriously.

💡
Key Recommendation

Negotiate for reasonable frequency—annual training is standard, but don't agree to quarterly unless the clause specifies why. Clarify whether the other party will provide training materials or whether you must create them yourself (and pay for them). Request that the clause allows online training rather than in-person, as it's more cost-effective and flexible. ---

Frequently Asked Questions

What does this clause mean in simple terms?

This clause requires employees and contractors to receive training on how to handle personal data safely and follow data protection laws.

Why should I care about this clause?

Training is mandatory under UK GDPR and strongly recommended under US law because human error (like sending an email to the wrong person) causes most data breaches.

What are my options?

For example, staff need to know they cannot share customer lists with unauthorized people or leave laptops unlocked.

How does this affect small businesses?

This clause typically specifies how often training must happen (usually annually) and may require you to keep records proving staff completed it.

✅ Action Checklist