1 of 40

GDPR Training

Storyboard

2 of 40

Overview

Course Title:

GRPD Training

Learning objective:

  • Explain GDPR and its key components
  • Identify personal data and what data needs to stay private
  • Take steps to keep personal data secure on your devices and in your workspace
  • Follow the GDPR Data Breach Protocol steps if a data breach occurs

Description Text

This course is designed to help learners identify the key components of the General Data Protection Regulation (GDPR), what personal data is, and what data needs to be kept confidential. They will explore scenarios and complete a quiz to apply their knowledge. Learners will also, know how to set up their workspace so it is secure. They will be able to judge if a workspace setup is secure.

Learners will need to receive a 80% pass rate on the quiz to complete this course.

Units

  • What is GDPR?
  • The core principles
  • Personal data confidentiality
  • Device and workplace security
  • Data breach
  • Quizzes
  • Job Aids

Client:

On point company (fictional)

Instructional Designer:

Samantha Howden

3 of 40

Units

Nr

Name

Content

Course Overview

Learning objectives

1

What is GDPR?

Definition

Personal Data

  • sorting activity
  • job aid

2

The core principles

The 7 core principles and definitions

  • Flash cards

3

Personal data confidentiality

Scenarios

  • Interactive choices

4

Device and workplace security

Importance of keeping a secure workspace/devices

Tips and examples for how to do this

5

Data breach

What to do in case of a data breach

Steps

Job Aid

Quiz

On information covered in all 5 lessons

6

Finish Line

Job Aids

4 of 40

Style Guide

Logo

N/A

Cover Photo

Someone working on their laptop

Custom colours

#f8d050

Fonts

Heading: Inter

Body: Inter

Additional Notes

80% pass rate complete the training

Templates

N/A

5 of 40

Lesson

COURSE OVERVIEW

BLOCK ID

BLOCK TYPE

Text

NOTES

CONTENT

What is the General Data Protection Regulation (GDPR) and how does it concern me?

As a new employee at On Point, you might be asking yourself these questions.

To help you understand GDPR, and your role in keeping data secure at On Point, you will complete this course as part of your onboarding.

By the end of the course you will be able to:

  • Explain GDPR and its key components
  • Identify personal data and what data needs to stay private
  • Take steps to keep personal data secure on your devices and in your workspace
  • Follow the GDPR Data Breach Protocol steps if a data breach occurs

It should take you around 15-30 minutes to complete this course. You will explore a mixture of information, activities, scenarios, and quizzes. To complete this course you will need to receive 80% on the final test.

Let's start and see the different ways you can keep personal data secure at On Point!

6 of 40

1: What is GDPR?

7 of 40

Lesson 1

What is GDPR?

BLOCK ID

BLOCK TYPE

Text

NOTES

CONTENT

By the end of this lesson, you will be able to:

  • Explain GDPR, identify personal data, and what data needs to stay private

The basics

The General Data Protection Regulation or more commonly known as GDPR, is considered the world's strongest set of data protection rules. It was established in the European Union (EU) to guide what data and information people can access about others, and gives limitations on what companies can do with personal data. It applies to all citizens in the EU and the companies that process their data.

At the heart of GDPR is personal data.

Personal data is information that allows a living person to be directly, or indirectly, identified from data that's available.

Working at On Point in the EU means you will also have to comply with the rules set out in the GDPR.

8 of 40

Lesson 1

What is GDPR?

BLOCK ID

BLOCK TYPE

Process - images with the personal data

NOTES

CONTENT

Each item will have a photo

Personal Data includes:

-Name (and examples)

-Identification numbers (and examples)

-Health information (and examples)

-Online Identification (and examples)

-Location data (and examples)

-Physical attributes (and examples)

-Economic, Cultural or Social Identity (and examples)

9 of 40

Lesson 1

What is GDPR?

BLOCK ID

BLOCK TYPE

Sorting - personal data / non-personal data

NOTES

CONTENT

Now that you know what counts as personal data have a go sorting some items of data into the categories of 'personal data' and 'non-personal data'.

Remember personal data can be used to directly or indirectly identify a living person.

�����

To download the above information about personal data click the file below: Job aid and download

Personal

Non-personal

Private phone number

Home address

Drivers license number

Date of birth

Gmail password

Your religion

Medical history

age range

data related to a deceased person

company email address such as: info@onpoint.com

A company registration number

Company address

10 of 40

2: The Core Principles

11 of 40

Lesson 2

The core principles

BLOCK ID

BLOCK TYPE

Text

NOTES

CONTENT

By the end of this lesson, you will be able to:

  • Explain GDPR's key principles

What are GDPR's key principles?

At the core of GDPR are 7 key principles, that have been designed to guide how people's data can be handled.

As an organisation within the EU, On Point and you as an employee have the responsibility to uphold these key principles.

GDPR's seven principles

Click on the + to read more about each principle.

12 of 40

Lesson 2

The core principles

BLOCK ID

BLOCK TYPE

Accordion

NOTES

CONTENT

Small image with each principle

Principle

Description

Lawfulness, Fairness and Transparency

Data is collected on a lawful basis and the individual is fully informed about how their data will be used.

Purpose Limitation

Data is collected for specified, explicit and legitimate purposes and not disclosed without permission.

Data Minimisation

Only data that is adequate, relevant, and limited to what is necessary, in relation to the purposes, can be collected.

Accuracy

Every reasonable step must be taken to ensure that personal data is accurate and kept up to date.

Storage limitation

Data cannot be kept for longer than is actually needed.

Integrity and Confidentiality (security)

Appropriate information security protections must be put in place to make sure information isn't accessed by hackers or accidentally leaked as part of a data breach.

Accountability

Requires you to take responsibility for what you do with personal data and how you comply with the other principles.

13 of 40

Lesson 2

The core principles

BLOCK ID

BLOCK TYPE

Knowledge check

NOTES

CONTENT

Your Turn

Match some of the principles to the correct example:

Small image with each principle

Principle

Example

Storage Limitation

Your employer keeps your personal data, for only the time it is needed.

Accountability

You are responsible for complying with all principles.

Data Minimisation

Your employer can only collect the information needed.

Accuracy

Your employer can ask for up to date contact information.

14 of 40

3: Personal Data Confidentiality

15 of 40

Lesson 3

Personal Data Confidentiality

BLOCK ID

BLOCK TYPE

Text

NOTES

CONTENT

By the end of this lesson, you will be able to:

  • Take steps to keep personal data secure

Keeping personal data private

Now that you have a basic understanding of GDPR and what counts as personal data.

It is important to be aware that you need to keep others' personal data private. Yes, they may have told you the reason they are off sick or shared their personal phone number with you, but they haven't given you permission to pass this information along.

Let's have a look at some scenarios and see if you can navigate what personal data you can and cannot share in the workplace.

16 of 40

Lesson 3

Personal Data Confidentiality

BLOCK ID

BLOCK TYPE

Scenario 1

NOTES

CONTENT

Scenario 1

You have just finished presenting your teams progress in a meeting. While it went ok, you know it would have been better if your colleague was here, you hope they are feeling better soon.

Hey, good presentation. Why isn't your colleague here today?

1

Hey, thanks! Oh they had a scheduling conflict and couldn't make it in today.

Way to go! Even if you know the reason someone is unwell you should never share it unless you have permission to do so.

CONTINUE

2

Hey, thanks! Oh they have been really sick and have gone to hospital for some tests. I hope they are better soon.

Oh no! You've shared someone else's personal data without their permission!

TRY AGAIN

17 of 40

Lesson 3

Personal Data Confidentiality

BLOCK ID

BLOCK TYPE

Scenario 2

NOTES

CONTENT

Scenario 2

You're having a conversation with your colleague and friend Jet during a coffee break about your weekends. You have told him you went to Louise's from accounting's house party.

Nice. Where about's does she live?

1

On New street. She has such a great view over the city and river.

You should never share someone's home address even if you are friends.

TRY AGAIN

She lives near the city. She has such a great view!

Well done, you didn't give away Luise's address!

CONTINUE

18 of 40

Lesson 3

Personal Data Confidentiality

BLOCK ID

BLOCK TYPE

Scenario 3

NOTES

CONTENT

Scenario 3

You are messaging a colleague about the deadline for a work project. They have suggested an ex-employee, Ahmed, would be a great help to get it finished in time.

I'll send him the details and see what he thinks! Do you happen to have his private phone number?

What a great idea! He would be a great help to get finish this before the deadline! I will send him the details.

Oops, although you have managed to keep Ahmed's number secure you have given him access to details of a project that is private company data.

TRY AGAIN!

He certainly would be a great help to get this project finished. However, I think we should see if Heidi from Finance can help us instead.

Well done! You've not only avoided sharing Ahmed's personal number but also kept details of a project within the company.

CONTINUE

19 of 40

4: Device and Workspace Security

20 of 40

Lesson 4

Device and Workspace Security

BLOCK ID

BLOCK TYPE

Text

NOTES

CONTENT

By the end of this lesson, you will be able to:

  • Take steps to keep personal data secure on your devices and in your workspace

Keeping data secure isn't limited to not sharing data in conversations. It is also about how you keep your workspace and your devices secure. This applies even if you are working from home.

You may be wondering how to do this, let's have a look.

Device Security

Keeping your device secure both at home and in the workplace is extremely important.

There are of course the usual ways to keep your devices safe, including updating and keeping passwords secure, updating malware and antivirus protection, and keeping data backups.

There are also some other things you may not have thought about before to ensure private data is kept secure:

21 of 40

Lesson 4

Device and Workspace Security

BLOCK ID

BLOCK TYPE

Labelled Graphic

NOTES

CONTENT

Image of office =

Lock your devices When you leave your desk do you remember to lock your device? If you leave your desk, and only minimise the windows but don't lock it, anyone passing can access personal data stored on your device. It is best to ensure you lock your device every time you leave your desk.

Screen direction Where does your computer screen face? If you have a window behind you, on the ground floor or within the building, people walking past might be able to see any personal data you have open on your computer. It is best to position your devices so that passersby cannot see your screen.

Pop Up Notifications Are your pop up notifications turned on? Your messages or emails with private data could appear while you are presenting from your computer or while someone comes to have a chat at your desk. It is best to have pop up notifications for emails and messages turned off.

22 of 40

Lesson

Device and Workspace Security

BLOCK ID

BLOCK TYPE

Text / Numbered list

NOTES

CONTENT

Workspace

Keeping your workspace clean and tidy isn't just to look good.

It is important just as important that your documents are kept secure and stored in a secure location, even if you may be working from home.

Here are some tips to do this:

Click the cards to reveal the tips.

23 of 40

Lesson 4

Device and Workspace Security

BLOCK ID

BLOCK TYPE

Flip cards

NOTES

CONTENT

Image and question on one side info on the other.

DOCUMENTS Are there documents and notes on your desk? When you are away from your desk it is best to put away any documents from your desk.

LOCK IT AWAY Are important documents in a secure location?

It is also important to ensure any important documents are locked away it is best to have a locked drawer or cabinet where you can store them securely.

24 of 40

Lesson 4

Device and Workspace Security

BLOCK ID

BLOCK TYPE

Knowledge check

NOTES

CONTENT

Your Turn

Match the item to the action to make your workspace secure:

Principle

Example

Documents

Put away and locked in a drawer.

Device screens

Ensure they are placed in a way so passers by can not see them.

When leaving your desk

Tidy up documents, lock devices, and any drawers or cupboards where.

Turn off

Pop up notifications for emails and messages.

25 of 40

5: Data Breach

26 of 40

Lesson 4

Data Breach

BLOCK ID

BLOCK TYPE

Text

NOTES

CONTENT

By the end of this lesson, you will be able to:

  • Follow the GDPR Data Breach Protocol steps if a data breach occurs

What is a data breach?

A data breach is a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

In the workplace breaches most often fall into the unauthorised disclosure or access to personal data category.

What do you need to do if you notice a breach of data?

Although everyone should keep personal data confidential, breaches and accidents do happen. It is not something you should stress over but it is important in these instances to remember to follow the GDPR data breach protocol.

27 of 40

Lesson 4

Data Breach

BLOCK ID

BLOCK TYPE

Text / Interactive Image (job aid)

NOTES

CONTENT

What to do if you notice a breach of data

Although everyone should keep personal data confidential, breaches and accidents do happen. It is important in these instances to follow the GDPR data breach protocol.

JOB AID with hoover buttons detailing the 4 step protocol

  1. Step 1 Data breach happens. This starts the first moment it is noticed that a data breach has happened.
  2. Step 2 Compile a record of the data breach The record must include; the nature of the breach, categories, the number of concerned data subjects, possible consequences of the breach, and taken/ proposed actions.
  3. Step 3 Within 72 hours. Notify without undue delay with a description of the breach within 72 hours and IF more than 72 hours detail why.
  4. Step 4 Notify your GDPR supervising authority. At each workplace there is a designated supervising authority for data breaches, your company will notify you about who holds this position.

28 of 40

Lesson 5

Device and Workspace Security

BLOCK ID

BLOCK TYPE

Knowledge check

NOTES

CONTENT

Your Turn

Match the action you must take to the correct step number:

�������To download the above information about the GDPR Data Breach Protocol click the file below: JOB AID download

Principle

Example

Data breach happens

Step 1

Compile a record

Step 2

Within 72 hours

Step 3

Notify your GDPR supervising authority

Step 4

29 of 40

QUIZ

30 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

text

NOTES

CONTENT

Here is a short 7 question quiz to check if you are able to:

  • Explain GDPR and its key components
  • Identify personal data and what data needs to stay private
  • Take steps to keep personal data secure on your devices and in your workspace
  • Follow the GDPR Data Breach Protocol steps if a data breach occurs

You will need to achieve 80% to pass.

Good luck!

31 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

Multiple choice

NOTES

CONTENT

What is GDPR?

A European law obliging major online browser companies to comply on the use of personal data, making sure they only collect the data needed.

A European Union regulation that aims to standardise the governance of personal information, particularly in terms of the security and protection of personal data. (correct)

A European law obliging employers to comply with the use of personal data, ensuring they do not keep data longer than 7 years.

32 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

Multiple choice

NOTES

CONTENT

Who does GDPR apply to?

All citizens in the EU and companies processing their data.(correct)

All EU Employers and Employees.

Online companies that operate in the EU.

33 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

Multiple choice

NOTES

CONTENT

How does the GDPR define personal data?

Physical identifiable items: name, appearance, phone number, address, etc.

Online identifiable items: usernames, email address, IP address, etc.

Other: health information, economic, cultural or social Identity.

All of the above. (correct)

34 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

Multiple choice

NOTES

CONTENT

Which of the follow is considered personal data?

Company email

IP Address(correct)

Age bracket

35 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

Multiple choice

NOTES

CONTENT

When is it ok to share someone's personal data?

It is never ok to share someone's personal data.

Once you have asked the person if it’s ok to share their data. (correct)

It's only ok if you know they know each other.

36 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

Multiple choice

NOTES

CONTENT

In which of these times is it ok to share personal data?

Your colleague would like an unwell coworker's mobile number to wish them the best.

You share a colleague's home address with another, after checking it is ok with them. (correct)

Your employer distributes a list of work email addresses and personal phone numbers, without consent.

37 of 40

Lesson QUIZ

QUIZ

BLOCK ID

BLOCK TYPE

multiple choice

NOTES

CONTENT

How quickly should you report a data breach?

- 7 days

-72 hours (correct)

-24 hours

-2 days

38 of 40

6: Finish line

39 of 40

Lesson 6

Finish Line

BLOCK ID

BLOCK TYPE

text / image

NOTES

CONTENT

Well done

You've made it!

You now know how to:

  • Explain GDPR and its key components
  • Identify personal data and what data needs to stay private
  • Take steps to keep personal data secure on your devices and in your workspace
  • Follow the GDPR Data Breach Protocol steps if a data breach occurs

You are ready to apply your new knowledge while working with personal data at On Point.

If you have any further questions or are faced with a data question or challenge, you are always welcome to speak to or email the On Point GDPR supervising authority.

GDPRinfo@OnPoint.com

40 of 40

Lesson 6

Finish Line

BLOCK ID

BLOCK TYPE

images

NOTES

CONTENT

To download the job aids on Personal Data and the GDPR Data Breach Protocol click the files below:

Job aids PDF downloads