The Information Commissioner’s Office has launched a new, free training programme built specifically for small and medium-sized organisations: Data Protection Essentials. Announced earlier this month, it’s a self-paced, bite-sized online course aimed at businesses and sole traders who don’t have a dedicated data protection officer, which describes the overwhelming majority of UK SMEs. It ends with a short self-assessment that gives you a clear picture of where your organisation’s data handling is solid and where it needs work.
This matters because most SME data protection failures aren’t dramatic breaches, they’re small, everyday gaps: a shared spreadsheet with no access control, customer emails kept indefinitely with no retention policy, a privacy notice copied from a template three years ago and never updated. The ICO’s own enforcement pattern shows it’s these basics, not sophisticated attacks, that trip up small businesses most often. A free, official course that walks through exactly what “good enough” looks like is a genuinely useful thing to have arrived.
What the course actually covers
Data Protection Essentials is built around real working scenarios rather than abstract legal theory, and includes sector-specific examples for education and childcare, health and social care, professional services, retail, and property. It’s designed to fit into normal working hours in short sessions rather than requiring a training day, and you can invite up to two other people from your organisation to complete it alongside you, useful if you want your office manager or a co-founder across the basics too. Finishing it earns a digital certificate and, more usefully, a practical self-assessment showing your specific gaps.
Why it’s worth an hour of your time this week
It’s a genuine baseline, not a sales funnel. Plenty of “free GDPR training” online exists to sell you a compliance product afterwards. This is the regulator’s own material, built to help you avoid the mistakes it actually sees and fines for, which makes it a rare case of free training worth taking at face value.
It’s useful evidence if you’re ever asked. If a customer, insurer, or public sector buyer ever asks what data protection training your team has had, “completed the ICO’s own Data Protection Essentials programme” is a genuinely strong answer, backed by a certificate rather than a vague assurance.
It pairs well with getting your actual paperwork in order. Training tells you what good practice looks like, but you still need the documents that put it into practice: a compliant privacy notice, a data processing agreement with your suppliers, an employee data handling policy. Smallprint has ready UK legal templates for exactly this, so the gaps the self-assessment flags can be closed the same day rather than sitting on a to-do list.
The takeaway
Free, official, and built specifically for businesses without a compliance team, the ICO’s new training removes the usual excuse of “we don’t have time to properly learn this.” Get the founder or whoever handles customer data to complete it this week, use the self-assessment honestly, and treat the gaps it surfaces as your actual to-do list rather than a box-ticking exercise.