It’s eight years since GDPR came into force, and the ICO has finally come up with a tool to help SMEs understand it. Was it worth the wait? The short answer is yes – if you're the person making data protection decisions in a small organisation.

The Data Protection Essentials programme is the ICO’s training and assessment product for SMEs, and it fills a crucial gap between the text of GDPR, DPA 2018 and PECR, and what small organisations should actually do to comply.

It’s a practical starting point rather than a compliance guarantee: it won’t replace role-specific staff training or specialist advice, but it will help the right person identify and document gaps in how the organisation handles personal information.

Data Protection Essentials – at a glance

DPE is a two-part programme. The first part is a free data protection training course made up of 13 modules. The ICO describes them as taking 10–15 minutes each, but completing the material properly took me about five to six hours. Ignore some of the suggested timings – there are modules which claim to take one minute and then drop a three-minute video in the middle. The second part is an organisational self-assessment, and completing this gets your organisation a digital certificate and an optional place on the Data Protection Essentials public register.

  • It’s designed for organisations with fewer than 250 employees, without a Data Protection Officer and which are not undertaking high-risk processing.
  • You can invite up to two other people from your organisation to complete the training.
  • Individuals receive digital certificates for completing the training; the organisation receives its certificate after completing the self-assessment.
  • The training and self-assessment must be refreshed annually to keep the certificates valid.

Who should complete it

I wouldn’t use it as the only data protection training for your entire team – and this is worth calling out, as the ICO explicitly says it is for employees. Most of the first three quarters of the training is governance and regulatory focused, and asks the learner to understand things like:

  • lawful bases,
  • special category conditions,
  • data sharing decisions,
  • international transfers,
  • retention,
  • ROPA construction.

This is too broad for the bulk of your employee population. But it does tackle these areas in a really operational way, and as a result this is a really good training for anyone who is going to rub up against them. Anyone who could be described as a decision-maker, data owner or operational lead is probably already making decisions here and neither documenting them nor making them with the full facts.

The DPE platform has a surprisingly good learner-management area to help manage this and evidence training compliance.

So, this is good for anyone in the organisation making data protection decisions. For people who simply need to know what to do in their daily jobs, you should be looking at shorter, role-specific training instead.

The gaps DPE will dig up

Maintaining a ROPA (Record of Processing Activities) is a GDPR requirement that in many small organisations goes straight into the too-difficult pile.

I regularly find that it either doesn’t exist, or where it does, isn’t fit for purpose. The most common mistake is to simply treat it as an inventory of database fields – name, email, phone – with a lawful basis inappropriately shoehorned against it.

The DPE training includes a ROPA template and encourages you to complete sections as you cover the relevant areas in the course. This is genuinely useful – I reworked my own ROPA into the template and it’s well worth doing. It also means you can give the relevant question on the self-assessment a big yes without worrying.

I suspect that the course’s focus on ROPA is an acknowledgement that many small organisations simply haven’t had access to the support needed to do this themselves. For most SMEs without formal data protection support, the GDPR frequently gives them just enough rope to hang themselves – the ‘risk to the rights and freedoms’ wording in particular is vague enough to give the impression of a flexibility that doesn’t exist.

The simplification is sometimes misleading

This isn’t supposed to be a specialist training course – and that does mean some modules don’t properly explain the interplay between different legislation. This is particularly apparent in the Direct Marketing lessons.

The lesson initially distinguishes limited companies and LLPs from sole traders, but it does not carry that distinction through when it turns to named business contacts. Instead, it says that if the person can be identified, both data protection law and PECR apply. Because this follows material about marketing to individuals, a lay reader could easily infer that identifying an employee makes them an individual subscriber – and therefore brings PECR’s consent or soft opt-in requirements into play.

The statement is defensible as shorthand, but it conceals the fact that the two laws ask different questions.

Under data protection law, the question is whether the communication involves personal information. A named business address such as [email protected] identifies Jane, so the UK GDPR applies.

Under PECR, however, the important question isn’t whether Jane is identifiable. It’s whether the subscriber is an individual or a corporate body.

Take the recruitment-agency example used in the lesson. If Caroline sends an unsolicited email to the named HR director of a limited company, the email address is personal information. She therefore needs a lawful basis for using it – probably legitimate interests – and must use it fairly and transparently. The HR director also has an absolute right to object to its use for direct marketing.

But the subscriber is the limited company that provides the email account, not the employee reading the message. It’s therefore a corporate subscriber. The PECR requirements for consent or the soft opt-in do not apply, despite the email identifying a particular person.

This isn’t just a technical interpretation. The ICO’s own detailed B2B marketing guidance gives essentially the same example: a recruitment company emailing a named HR director at a limited company. It confirms that consent and the soft opt-in do not apply because the address belongs to a corporate subscriber.

The position would be different if the recipient were a sole trader or certain types of partnership. These are treated as individual subscribers, so unsolicited electronic marketing would normally require consent or compliance with the soft opt-in.

A more reliable decision process is therefore:

  1. Is this direct marketing sent by electronic mail?
  2. Is the subscriber corporate or individual?
  3. Am I using personal information to select or contact the recipient?

The subscriber type determines whether PECR requires consent or a soft opt-in. The use of personal information determines whether the UK GDPR also applies. Collapsing those questions into “named” and “unnamed” contacts is easier to teach, but it can produce the wrong answer in practice.

What it doesn’t replace

I completed the Data Protection Essentials training shortly after finishing the IAAP’s CIPP/E training material – and in practical areas it really shines. As would be expected, professional-level training provides much greater understanding of the legal and governance architecture behind the relevant legislation. But DPE’s strength is in the operational – what do I need to know before I do this?

As before, this isn’t a professional-level course, and it’s built for accessibility, so some areas are overly simplified. But it does translate some of the biggest gaps I regularly see in organisations into manageable actions.

Is Data Protection Essentials just Cyber Essentials for data?

The ICO is very clear that Data Protection Essentials isn’t an accredited certification scheme, unlike Cyber Essentials. DPE is completely self-assessed, whereas CE includes an independent assessor’s audit of your answers (and CE+ adds technical testing).

The same applies to the public register. It shows that an organisation has completed the training and self-assessment, but the ICO is explicit that inclusion is not an endorsement and does not confirm compliance with data protection law.

There isn’t an obvious accredited certification for Data Protection currently available for SMEs (the ICO does have a list of approved certifications, but all those currently on the list are for specific sectors or products).

Final verdict

Data Protection Essentials is currently the best regulator-authored benchmark that an organisation can test itself against. For a small organisation without a DPO and which is not undertaking high-risk processing, my verdict is yes: it is worth completing. Give it to the person who makes operational decisions about personal information, use the ROPA template properly and treat the self-assessment results as an action plan. Continue to provide role-relevant training to the wider team, and get specialist advice where the risks or decisions go beyond the course.

It’s a strong starting point, but it’s not the finish line.