GDPR and ISO training for organisations
Data protection, information security and management systems
Global Protection Group delivers practical training in GDPR, ISO 9001, ISO/IEC 27001 and internal management-system auditing, tailored to the requirements of international corporations, public-sector bodies and other organisations.
Our programmes support organisations in reducing regulatory and operational risk, developing staff competence and applying legal requirements, international standards and internal procedures consistently in day-to-day operations.
Training combines expert guidance with case studies, practical exercises and, where appropriate, work based on the organisation’s own processes and documentation.
Training areas
Depending on the organisation’s requirements, training may cover:
- personal data protection in accordance with the General Data Protection Regulation (GDPR);
- the role, responsibilities and independence of the Data Protection Officer (DPO);
- data protection risk assessment, Data Protection Impact Assessments (DPIAs) and privacy by design and by default;
- assessment and management of personal data breaches, including notification and communication requirements;
- requirements of the ISO 9001 Quality Management System;
- requirements of the ISO/IEC 27001 Information Security Management System;
- planning, conducting and documenting internal audits, including principles and methods set out in ISO 19011;
- identifying nonconformities and planning corrective and continual improvement actions.
Training may focus on a single specialist area or combine data protection, information security, quality management and internal auditing within a programme tailored to the organisation.
Training tailored to participant roles
Programmes can be prepared for employees, senior management, Data Protection Officers, compliance personnel, quality and information-security teams, internal auditors, process owners and management-system coordinators.
The level of detail is adapted to the participants’ responsibilities. Awareness training for employees focuses on practical rules and expected behaviour, while programmes for specialists and auditors address risk assessment, documentation, governance, auditing and management-system oversight in greater depth.
Practical application
Training goes beyond presenting legislation and standard requirements. Participants work with realistic incidents, documents, audit findings, nonconformities and situations that may occur during the organisation’s normal operations.
Depending on the agreed scope, practical exercises may include:
- assessing data protection and information-security risks;
- preparing or reviewing a DPIA;
- assessing a personal data breach and determining the appropriate response;
- planning an internal audit and preparing audit questions;
- collecting and evaluating audit evidence;
- documenting findings, nonconformities and corrective actions.
This approach helps participants apply the acquired knowledge in their professional roles and strengthens organisational preparedness for incidents, internal reviews and external audits.
Supporting compliance and management systems
Well-designed training helps organisations establish a consistent understanding of responsibilities, improve the application of internal policies and strengthen cooperation between compliance, data protection, quality, information-security and operational teams.
Programmes may also support preparations for internal and external audits, the implementation or development of management systems and the improvement of arrangements for responding to incidents and nonconformities.
The content is always adapted to the organisation’s sector, operating model, applicable requirements and existing level of management-system maturity.
Delivery and completion
Training can be delivered at the client’s premises, at another agreed location or remotely. Courses are available in Poland and internationally.
The duration, level of advancement and delivery methods are agreed individually. Selected programmes may conclude with a knowledge assessment or practical assignment.
Participants receive a named certificate confirming completion of the agreed training programme.
Discuss your training requirements
Each programme is prepared individually, taking into account the organisation’s profile, participant group, applicable management systems, internal procedures and expected training outcomes.
Based on the information provided, we will recommend an appropriate programme, delivery format and level of advancement.
Every enquiry is assessed individually and handled in confidence.


