Form

Checklist Training Selection

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a practical checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations plan, deliver and monitor data protection training for staff. It is a self-assessment tool rather than a binding rule, intended to support compliance with data protection law and demonstrate accountability. It does not cover training for Data Protection Officers, who require more specialist, role-specific training.

  • Governance and planning: Identify a training lead, align training with organisational risk, and schedule refresher training with records kept of attendance, content and assessment.
  • General awareness training: Ensure all staff understand data protection law, principles, personal/special category data, data subject rights, breach reporting and good practice such as phishing awareness and secure disposal.
  • Role and specialist training: Provide enhanced training for higher-risk roles (e.g. HR, IT, Marketing) covering lawful basis, DPIAs, data sharing, international transfers, retention and security controls, with competency assessed.
  • Delivery and records: Choose suitable delivery formats, tailor content to the organisation, and maintain version control and training archives.
  • Monitoring and review: Maintain training logs, monitor completion and effectiveness, gather feedback, and escalate gaps.
  • Wider integration: Align training with related policies (breach, retention, DPIA), information security programmes, and incident response.
  • When general training is insufficient: Provide additional training for high-risk or large-scale processing, profiling/AI, procurement, IT development, and remote/hybrid working.

The checklist is a voluntary self-audit resource; it does not itself impose new legal obligations but reflects JOIC's expectations for demonstrating a compliant, risk-based approach to staff data protection training.

Applies to

data controllers, organisations processing personal data

Topics

Version history

2026-07-30

source file (current)