Obligations & standards

Which part of your obligations you can tick off with me.

Awareness is required by several sets of rules — and expected in contracts. Choose your context and see openly which requirements secureIT’s training and phishing simulations cover, where you need to add something, and what deliberately stays outside.

GDPR

EU regulation

The GDPR requires appropriate technical and organisational measures to protect personal data. An aware, well-trained team is one such organisational measure – and the factor that prevents most data breaches from happening in the first place.

4 of 5 requirements you cover with me · 1 stay with your IT
In short
General Data Protection Regulation – Regulation (EU) 2016/679
Minimum requirement
Appropriate organisational measures with aware, reliable staff – documented so they can be proven (accountability).
Basis

Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) – in particular Art. 32 (security of processing), Art. 39(1)(b) (awareness-raising and training by the data protection officer) and Art. 5(2) and Art. 24 (accountability).

The requirements in detail

✓ covered
Organisational measures with aware staff to protect personal data. · Art. 32(1)

Awareness courses and phishing simulations are an appropriate organisational measure within the meaning of Art. 32.

✓ covered
Awareness-raising and training of staff involved in processing operations. · Art. 39(1)(b)

This is exactly the awareness-raising and training the offer provides – including documentation.

◐ partly
Staff with access to data handle it consciously and in line with instructions. · Art. 32(4)

Content on data handling and social engineering; the formal confidentiality undertaking is something you arrange yourself.

✓ covered
Proof of the measures taken (accountability). · Art. 5(2) / Art. 24

Proof of participation and completion with a timestamp documents the awareness measures.

– your IT
Technical measures (encryption, pseudonymisation, backup, access control). · Art. 32(1)(a)–(d)

Not part of awareness – to be implemented by you or your IT.

ℹ️ The GDPR applies to almost every business that processes personal data – regardless of size or sector.

Proof at the push of a button

Businesses generate confirmation of the training carried out in the Cockpit — with time stamp and reference to the chosen context.

Get started now

This overview is meant to create transparency and is not legal advice. Whether, and to what extent, a standard or obligation applies to you depends on your sector, your size and your contracts. What is covered in each case is the awareness part (training, simulation, proof) – not the technical measures.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first