Topics inside this course
Awareness and induction depth — not an accredited occupational qualification.
- Personal data and high-risk processing in daily work
- Data minimisation and purpose limitation in practice
- Recognising and escalating data subject requests
- Breach reporting channels for staff
- When EU rules may apply alongside local law
Built for the people who take the training
Employees in organisations that process EU resident data, including SA teams supporting EU customers or group companies.
What learners leave able to do
- Identify personal data and high-risk processing in daily work
- Apply data minimisation and purpose limitation in practice
- Handle access requests and incidents via the right channel
- Understand when EU rules may apply alongside local law
Modules you can expect
Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.
- 1Personal data at the keyboard
What staff process without noticing.
- 2Lawful bases, briefly
Enough for behaviour, not for drafting contracts.
- 3Rights requests
How to recognise a DSAR and who owns it.
- 4Incidents
What to escalate and how fast.
- 5Working across borders
When POPIA and GDPR both matter.
- 6Knowledge check
Scored assessment for dual-regulated teams.
Scored assessment for non-lawyer staff. Pair with POPIA awareness for SA/EU teams.
Written for the workplace, not for the statute book alone
Many SA organisations need both POPIA and GDPR awareness. This course covers GDPR essentials for non-lawyers: what personal data is, lawful bases at a high level, rights requests, and breach reporting — framed for staff behaviour, not for drafting contracts.
Support desks, sales ops and HR shared-service teams often touch EU resident data without sitting in the EU. They need to know when a request is a data subject request, when not to copy a whole mailbox into a ticket, and when to stop and escalate.
It is not a certification and not a substitute for DPO advice. Localise with your processing records when you build from source in Kre8AI so transfer rules and contact points match your group structure.
Offer as SCORM or HTML. Use alongside the free POPIA course in our library when you train dual-regulated teams. The optional coach stays grounded in the approved GDPR pack and stays off quizzes by default.
International groups often need one staff story that works in Johannesburg support centres and EU hubs alike. Keep the legal depth with your DPO; keep this module focused on what people do at the keyboard. Pair it with POPIA awareness when the same people serve both regimes.
Play the library demo, or generate GDPR essentials from your privacy notice and DSAR procedure in Kre8AI today.
What you would upload in Kre8AI
GDPR extracts, privacy notice, DSAR and breach procedures
- GDPR articles and EDPB guidance relevant to your processing
- Your privacy notice, DPIA summaries staff may see, and transfer rules
- Incident and DSAR procedures
Formats, coach and provenance
- Standalone HTML to play in the browser; SCORM 2004 for your LMS.
- Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
- Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
Get the SCORM package while you are here.
Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.
Request the package
SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

