Proof that staff have read data protection statement

We have date protection training that has to be done, different depending on what your job is.

Having a test also shows some level of understanding which others have pointed out is pretty important especially if you want to hold people to account should something happen. It's also always handy if the ICO come knocking to have all that evidence sitting there.
 
If it's the same thing they need to read each month, then people won't read it. You may get signatures etc, but humans won't see the value in that and so will go straight to the ok/sign.

If you're ok with that because the root motivation is covering requirements (such as what the auditors have asked for) rather than actually getting people to be data savvy, then don't over complicate it, but be aware of the root reason of your motivation.
 
Back
Top Bottom