Example videos

GDPR training

Data protection basics, subject access rights, reporting incidents.

0:00/0:00
Use case

How this training video is used

This video is used as mandatory data protection training for new employees. Everyday actions create more risk than rare specialist cases: an email sent to the wrong recipient, a customer list left visible, or a conversation overheard by an unauthorised person.

The training connects core GDPR principles with concrete workplace situations. Employees learn to recognise personal data, use it only for an authorised purpose, and report a suspected incident immediately through the designated internal channel.

Knowledge check

Example quiz for this training

These questions were created with the same quiz workflow that Vidancy provides after a training video is finished.

Question 1 of 3

When is information considered personal data?

Script

You're sitting at your desk. In front of you on the screen is a customer list. You look at your phone. In the background, you're talking to a colleague about a current case. All part of a normal workday. And that's exactly why it's easy to overlook. In each of these moments, you are working with personal data. This is data about people, about customers, about employees, about contacts, about people who trust us. And data protection means we handle this data in a way that keeps it protected. Not just the legal department, not just the Data Protection Officer, but all of us. The GDPR states in Article 4(1) that personal data is any information relating to an identified or identifiable natural person. Simply put, as soon as a person can be identified directly or indirectly, it's personal data. This isn't just a name. It's also a phone number, an email address, a customer number, a contract number, a conversation note, a photo, or a piece of information that, together with other details, reveals who the person is.

The GDPR lists several principles in Article 5, for example, lawfulness, purpose limitation, data minimization, and confidentiality. For everyday work, this means we only use personal data when we are allowed to, only for the intended purpose, only as much as is necessary, and only in a way that prevents unauthorized persons from accessing it. This sounds abstract. But in everyday life, it usually shows up in very simple situations. The first situation: the wrong recipient. You're writing an email. The program automatically suggests an address. You click 'send' quickly, and suddenly personal data ends up with someone who was not supposed to receive it. This can be a personal data breach under Article 4(12) of the GDPR, for example, an unauthorized disclosure. That's why you should stop briefly before sending, check the recipient, check the attachments, check the content. These two seconds can prevent a data protection incident.

The second situation: the wrong place. Personal data belongs on the company's approved systems. Not on private USB sticks. Not in private email inboxes. Not in private messengers. Not in cloud services that are not approved. Article 32 of the GDPR obliges companies to protect personal data with appropriate technical and organizational measures. If data moves to places that are not intended for it, this protection can be lost. That's why, when you store, share, or forward data, you should ask yourself briefly: is this the right and approved place for it? The third situation: the open view. A screen that is visible to others. A phone call with customer data in a café. Documents left open on a desk. This is also about confidentiality. Article 5(1)(f) of the GDPR states that personal data must be protected against unauthorized access. Simply put, not everyone is allowed to see or hear everything. That's why you should lock your screen, not discuss personal data in public, and not leave documents lying open.

If you're unsure, a simple question helps. Am I allowed to use this data for this specific purpose, and is the other person allowed to see this information? If you hesitate, don't just proceed. Ask your manager or the Data Protection Officer. You can find the contact details on the learning platform. And what if something does go wrong? An email went to the wrong recipient. A device was lost. A document was visible to unauthorized persons. Someone had access who shouldn't have had access. Then one rule applies: Report it immediately. Don't wait. Don't cover it up. Don't spend a long time investigating it yourself. Don't stay silent out of shame. Article 33 of the GDPR states that if a personal data breach occurs, the controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

In the case of a likely high risk, notification of the data subjects may also be required under Article 34 of the GDPR. For you in your daily work, this means: report a potential incident internally immediately. Preferably by phone to the Data Protection Officer or via the designated reporting channel. You can find further information on our learning platform and in the self-service portal. The sooner the incident is known, the better the company can react. In the end, it's about a simple mindset. Personal data is not just any information. It's information about people. Anyone who works with it bears responsibility. In everyday work, data protection means checking briefly, acting consciously, and reporting immediately if something goes wrong. If everyone has this reflex, personal data will remain where it belongs: protected.

Turn your own material into training?

Use a script, document, or topic to create an on-brand training video with narration, captions, and an optional quiz.

Try it for free