What does good data protection training actually look like?
You may have seen the news last week about Addenbrooke’s Hospital, where around 40 members of staff accessed the medical records of a three-year-old boy injured in a crocodile attack. The hospital is still investigating whether all of them had a legitimate reason to do so.
It follows similar stories from Aintree Hospital, where 48 staff accessed the records of Southport attack victims, and Nottingham University Hospitals, where up to 150 staff accessed the records of the 2023 stabbing victims. In all three cases, the standard response has included a familiar line: “we will be reviewing our training.”
Which raises an obvious question. If training is always the answer, why does this keep happening?
The short answer is that most data protection training — not just in the NHS, but across many sectors — is designed to achieve compliance, not to change behaviour. There’s a difference. And it matters.
What most data protection training gets wrong
Think about the last time you, or someone in your organisation, completed a data protection training module. Chances are it involved reading through a summary of GDPR principles, answering a handful of multiple-choice questions, and receiving a completion certificate. Job done.
The problem is that this approach tells people what the rules are without ever helping them understand why those rules exist, what breaking them actually looks like in practice, or what happens when they get it wrong.
Most people who inappropriately access patient records aren’t doing it because they’ve forgotten that patient confidentiality exists. They know. They’ve ticked the box. They’ve signed the policy. In the moment, they make a different calculation — usually because curiosity feels low-risk, and because nobody has ever made the consequences feel real.
Training that just recites legislation doesn’t change that calculation. Training that brings the consequences to life — through realistic scenarios, genuine examples, and clear answers to the question “what would actually happen to me?” — stands a much better chance.
What good training looks like instead
Good data protection training starts with the ‘why’, not the ‘what’. Before you get into the six lawful bases or the rights of data subjects, people need to understand what’s actually at stake when personal data is misused — for the individual affected, and for the person who caused the breach.
It uses real-world scenarios. Not abstract hypotheticals, but the kind of situations people actually encounter: a colleague asking you to look something up on their behalf, a patient whose case has been in the news, a request that feels routine but isn’t quite right. Scenarios that make people stop and think rather than click through.
It’s proportionate to the role. A receptionist, a nurse, and a data protection officer all need to understand GDPR — but they need to understand different parts of it, applied to different situations. One-size-fits-all training tends to be too generic to be useful for anyone.
And critically, it’s reinforced over time. A single annual module is better than nothing, but it’s not enough on its own. The organisations that build genuine data protection cultures are the ones where managers talk about this stuff regularly, where incidents are discussed openly rather than quietly filed away, and where people feel confident raising concerns without fear of being seen as difficult.
This isn’t just an NHS problem
It’s easy to look at these headlines and assume this is a large-organisation problem, or a public sector problem. But inappropriate access to personal data happens in smaller settings too — GP surgeries, care homes, independent clinics, and any business that handles health information about clients or staff.
The stakes are just as high. The legal obligations are identical. And in smaller organisations, where there may not be a dedicated data protection officer or an HR team to manage disciplinary processes, the risk of getting it wrong — and not having the systems in place to catch it — is arguably greater.
The good news is that good training doesn’t have to be expensive or time-consuming. It does have to be practical, relevant, and actually engaging — which is a higher bar than most compliance modules clear.
Where to start
If you’re responsible for data protection in a health or care setting — or in any small organisation that handles sensitive personal information — and you’re not confident that your current training goes beyond the basics, it’s worth taking a look at what you’re actually delivering.
Our Introduction to Data Protection course covers the essentials of GDPR in plain English, with practical examples that go well beyond reciting the legislation. Our Data Protection for SME Owners and Directors course is designed specifically for managers and business owners who need a genuine working understanding of what’s required — not just enough to tick a box, but enough to make good decisions when the situation isn’t straightforward.
Because the NHS story isn’t really about forty people who forgot the rules. It’s about what happens when training stops at the rules and never gets as far as the judgement.
Related posts:
Is it a breach, a complaint, or a quality issue? Why getting that wrong matters
Safeguarding Guest Privacy: How RiskReady’s Data Protection training Supports Hotel Chains
When Data Protection Training Doesn’t Work — and Why It Matters
How One Local Authority Transformed Loggist Training with a Cost-Effective 3-Year Licence
