GDPR Training Courses 

London UK & Live Online

For tech & business users, from beginner to expert


Training on data privacy, GDPR compliance and responsible data handling

EDF logo Capita logo Sky logo NHS logo RBS logo BBC logo CISCO logo

Welcome to the GDPR course group.

This group contains JBI Training's GDPR courses, designed to help organisations and professionals understand their responsibilities when processing and protecting personal data.

Courses in this group cover UK GDPR principles, data protection legislation, lawful processing, data subject rights, privacy by design, Data Protection Impact Assessments (DPIAs), data breach management, compliance responsibilities, governance, and best practices for maintaining regulatory compliance.

Browse the courses in this group to find the training that best matches your experience level and learning goals.

JBI Training offers three GDPR and data privacy courses covering different audiences and levels of depth. The GDPR course is a four-day comprehensive programme covering all aspects of GDPR compliance for professionals who need an in-depth understanding of the regulation. GDPR for IT and Software Professionals is a two-day course tailored specifically to developers, architects, and technical teams who need to build GDPR compliance into the systems and software they design and build. GDPR for Non-EU Professionals is a two-day course designed for organisations and individuals outside the European Union who process the personal data of EU and UK residents and need to understand their obligations under GDPR. All courses are available as scheduled classroom sessions in London, as live online instructor-led training, or as customised onsite programmes for teams.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into force in May 2018 across the European Union. It sets out the legal requirements for how organisations collect, store, process, and share the personal data of individuals. Following Brexit, the UK adopted its own equivalent legislation — UK GDPR — which mirrors the EU regulation in most material respects and is enforced by the Information Commissioner's Office (ICO). GDPR matters for organisations because non-compliance can result in significant financial penalties — up to €20 million or 4% of global annual turnover, whichever is higher under EU GDPR — as well as reputational damage, regulatory enforcement action, and loss of customer trust. Any organisation that handles the personal data of EU or UK residents, regardless of where the organisation is based, is subject to GDPR obligations.
EU GDPR is the original regulation applicable across European Union member states, regulated and enforced by each member state's national supervisory authority. UK GDPR is the version of the regulation that was incorporated into UK law following Brexit, and is enforced by the Information Commissioner's Office (ICO) in the UK. In practice, UK GDPR and EU GDPR are very closely aligned in their core requirements — the lawful bases for processing, data subject rights, accountability obligations, and breach notification requirements are substantially the same. Key differences relate to international data transfer mechanisms, the role of the ICO versus EU supervisory authorities, and some specific provisions around research and national security. Organisations operating in both the UK and EU need to consider both regimes. JBI's GDPR courses cover both UK and EU GDPR.
The four-day GDPR course is a comprehensive programme covering the full scope of GDPR compliance. Topics include the history and context of data protection law, the scope and territorial reach of GDPR, the lawful bases for processing personal data, the rights of data subjects (including the right to access, rectification, erasure, portability, and objection), the obligations of data controllers and data processors, privacy by design and by default, data protection impact assessments (DPIAs), the role and responsibilities of the Data Protection Officer (DPO), data breach notification requirements, international data transfers, and the enforcement and penalty regime. It is suitable for data protection officers, compliance managers, legal and risk professionals, and senior managers who need a thorough working knowledge of the regulation.
The GDPR for IT and Software Professionals course is a two-day programme specifically designed for developers, software architects, database administrators, IT managers, and technical teams who need to implement GDPR compliance in the systems they build and maintain. It covers GDPR principles from a technical implementation perspective — including privacy by design and privacy by default, data minimisation and pseudonymisation techniques, encryption and security requirements, data retention and deletion in database systems, handling subject access requests from a technical standpoint, managing third-party processors and APIs, and the technical aspects of data breach detection and notification. It is a course for technical professionals who need to translate GDPR legal requirements into architectural and development decisions.
The GDPR for Non-EU Professionals course is designed for individuals and organisations based outside the European Union or United Kingdom who nonetheless process the personal data of EU or UK residents and are therefore subject to GDPR obligations. This commonly includes organisations in the United States, Asia-Pacific, Middle East, and other regions that operate websites, apps, or services accessible to EU and UK users, or that process EU and UK employee or customer data. The course covers the extraterritorial scope of GDPR, what obligations apply to non-EU data controllers and processors, the requirement to appoint an EU or UK representative, international data transfer mechanisms including Standard Contractual Clauses (SCCs) and adequacy decisions, and practical steps for achieving compliance from outside the EU.
A Data Protection Officer is a designated individual responsible for overseeing an organisation's data protection strategy and ensuring compliance with GDPR. Under GDPR, certain organisations are required to appoint a DPO — including public authorities, organisations that carry out large-scale systematic monitoring of individuals, and those that process special category data on a large scale. The DPO must have expert knowledge of data protection law and practices, operate independently, and act as the point of contact with the supervisory authority. The role, responsibilities, and statutory obligations of the DPO are covered in detail in the four-day GDPR course, making it appropriate preparation for individuals who are taking on or considering a DPO role.
GDPR requires that every processing activity involving personal data has a documented lawful basis. There are six lawful bases under GDPR: consent (the individual has given clear, informed, and freely given consent); contract (processing is necessary to perform a contract with the individual); legal obligation (processing is necessary to comply with a legal requirement); vital interests (processing is necessary to protect someone's life); public task (processing is necessary for a public authority to perform its official functions); and legitimate interests (processing is necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the individual's rights). Choosing and documenting the correct lawful basis for each processing activity is one of the most important practical aspects of GDPR compliance, and is covered in depth across all three JBI GDPR courses.
The use of AI systems — including large language models, automated decision-making tools, and data analytics platforms — raises significant GDPR considerations. GDPR Article 22 gives individuals the right not to be subject to solely automated decisions that have a significant effect on them, and requires transparency about automated processing. AI systems that process personal data must have a documented lawful basis, must comply with data minimisation principles, and must implement appropriate security measures. The use of personal data to train AI models raises additional questions around purpose limitation and consent. As AI adoption grows, understanding how GDPR applies to AI data processing is an increasingly important area for compliance, legal, and technical professionals. JBI's GDPR training addresses these considerations within the broader compliance curriculum.
Yes. All GDPR and data privacy courses at JBI can be delivered as customised closed-group programmes for corporate teams, onsite at your organisation's premises or online. Content can be tailored to your organisation's specific data processing activities, industry sector, existing compliance framework, and the roles of the delegates attending — for example, a programme for a financial services firm can focus on sector-specific regulatory requirements alongside GDPR, while a programme for a software development team can concentrate on technical implementation of privacy by design. JBI has delivered GDPR and compliance training for organisations including the BBC, NHS, RBS, Sky, EDF, and Capita.
Yes. Data protection law and its interpretation continue to evolve through ICO guidance, European Data Protection Board (EDPB) opinions, court judgements, and enforcement decisions. JBI's GDPR training content is continuously reviewed and updated to reflect these developments, including changes to international data transfer mechanisms, evolving guidance on consent and legitimate interests, ICO enforcement priorities, and the latest regulatory thinking on AI and data protection. Delegates learn the current state of GDPR compliance requirements rather than a static interpretation of the original 2018 regulation.

CONTACT
+44 (0)20 8446 7555

[email protected]

 

Copyright © 2026 JBI Training. All Rights Reserved.
JB International Training Ltd  -  Company Registration Number: 08458005
Registered Address: Wohl Enterprise Hub, 2B Redbourne Avenue, London, N3 2BS

Modern Slavery Statement & Corporate Policies | Terms & Conditions | Contact Us

POPULAR

AI training courses                                                                        CoPilot training course

Threat modelling training course   Python for data analysts training course

Power BI training course                                   Machine Learning training course

Spring Boot Microservices training course              Terraform training course

Data Storytelling training course                                               C++ training course

Power Automate training course                               Clean Code training course