GDPR & Cyber Defence

Data protection and cyber resilience in one track, for every team that handles personal data and every organisation that has to keep running when an attack comes.

The General Data Protection Regulation applies to everyone handling personal data. The cyber rules under NIS2 and DORA are now in force across the EU.

GDPR & Cyber Defence

Protecting personal data, and staying standing when it is attacked

Two duties sit side by side for almost every organisation. The General Data Protection Regulation (GDPR) governs how you collect, use and protect personal data, and it reaches every company that touches it. The cyber rules, the Network and Information Security Directive (NIS2) and the Digital Operational Resilience Act (DORA), add security, governance and incident-reporting obligations for a wide range of sectors.

They protect the same thing from two directions: the GDPR sets the standard for handling data, and the cyber rules make sure you can defend it and recover when something goes wrong. Training your people on one without the other leaves a gap.

These courses close that gap. They are self-paced and scenario-based, supported by an AI Tutor, and each ends with a certificate you can show an auditor.

Talk to us

Courses in this program

One course covers the GDPR for everyone. Two more cover the cyber-resilience rules, from the practical steps a smaller company needs to the deeper duties under DORA and NIS2. Select a course to see what it covers.

GDPR: a practical guide for every employee

The course everyone can take. It covers the six principles of the GDPR, the eight rights it gives people, and how the law shows up in everyday work, from cookie banners to marketing email. Staff finish able to recognise personal data, handle it correctly, and know when to escalate.

EU Cybersecurity Compliance for SMEs

A practical route through the rules for smaller organisations: the Network and Information Security Directive (NIS2), the Cybersecurity Act and the Cyber Resilience Act. It covers how to secure your information and communications technology (ICT) supply chain, manage high-risk suppliers, and put the required protections in place without a large security team.

Cyber Resilience: DORA and NIS2

Resilience is about more than keeping attackers out. This course covers anticipating, withstanding and recovering from incidents under the Digital Operational Resilience Act (DORA) and NIS2: how resilience differs from perimeter security, how to spot common attacks such as phishing, and what the rules expect when something does get through.

Self-pacedStart any time, learn at your own speed.
AI Tutor, 24/7Ask questions and get answers as you go.
Scenario-basedReal situations, not abstract theory.
CertificateProof of completion for every course.

New to this? What these rules are

The GDPR is the European law on personal data. It has applied since 2018 and covers any organisation that collects or uses information about people in the EU. It sets out principles for handling data, gives people rights over their own information, and requires you to keep that data secure.

NIS2, the Network and Information Security Directive, is the EU’s baseline for cybersecurity. It requires organisations in a range of important sectors to manage their security risks, secure their supply chains, and report serious incidents. National laws putting it into effect have been rolling out since late 2024.

DORA, the Digital Operational Resilience Act, focuses on the financial sector. It requires firms and their technology providers to withstand, respond to and recover from disruption, and it has applied since January 2025.

Why together. The GDPR sets the standard for protecting data; NIS2 and DORA make sure you can defend it and keep operating. Most organisations carry duties under more than one, which is why the training covers them as a set.

Get your teams trained

Tell us how many people you need to train and which teams they sit in, and we will put together a quote. For smaller teams you can subscribe directly.

Also using AI systems? They process personal data too. See AI Ethics & Compliance →