Organisations should treat both as necessary, but the first priority is reducing the chance of accidental disclosure through technical and procedural controls. Training matters because human error is a dominant breach factor, yet the article shows that weak measures and poor awareness together create the failure. Effective programmes combine clearer workflows, better safeguards, and regular awareness training.
Why technical controls come first for breach reduction
The best first move is to reduce the chance that a mistake becomes a reportable breach. For GDPR, that usually means tightening data handling paths, limiting access, and making disclosure harder to do accidentally. Training is still necessary, but it works best when people are operating inside safer workflows rather than relying on memory alone.
That is why technical and procedural controls deserve priority. They shape the default state of the environment, whereas training depends on consistent human performance under pressure, interruptions, and ambiguity. If the underlying process still makes accidental disclosure easy, awareness alone will not reliably prevent it.
For privacy and data handling controls, see the Identity Data Privacy and Consent Guide, which focuses on minimisation, lawful handling, and retention discipline. The same logic appears in the EU General Data Protection Regulation (GDPR), especially where security of processing and data protection by design shape how organisations should build the control environment.
Why training still matters, but cannot carry the programme alone
Staff training is most valuable where judgement is required: spotting unusual requests, pausing before sending data, escalating exceptions, and understanding what counts as personal data. It helps reduce risky behaviour, but it does not remove risky conditions. A well-trained user can still make a mistake if the system is poorly designed, the process is unclear, or the approval path is too easy to bypass.
Training also degrades if it is treated as a one-time compliance exercise. In practice, the highest value comes from short, repeated reinforcement tied to real workflows, not from broad awareness messaging detached from the tasks people actually perform. That is especially true where staff handle customer records, exports, shared mailboxes, or exceptions to normal access.
Organisations should therefore align awareness with the real failure points in handling personal data, then support it with stronger baseline controls. The CIS Controls v8 are useful here because they emphasise account management, access control, audit logging, and data protection as practical safeguards that reduce avoidable exposure.
How to decide the sequence in practice
The right sequence is usually: first, remove the easiest paths to accidental disclosure; second, train staff on the remaining judgement points; third, monitor for repeat mistakes. If a process allows large exports, broad visibility, or uncontrolled sharing, training should not be the only compensating measure. If the workflow is already constrained, training becomes more effective because staff are making fewer high-risk decisions.
A useful test is whether a breach could still happen even if the person involved knew the policy. If the answer is yes, the organisation needs stronger controls before it relies on awareness alone. That includes clearer permissions, safer defaults, fewer manual handoffs, and stronger review points for outbound sharing and data movement.
For structured control selection and audit-ready governance, the NIST SP 800-53 Rev 5 Security and Privacy Controls offers a control catalogue that supports access control, audit, and system integrity decisions. For organisations building to a formal management system, ISO/IEC 27001:2022 Information Security Management gives a governance model for combining policy, implementation, and review.
Risk and Threat Considerations
GDPR breach reduction fails when organisations overestimate how much awareness can compensate for weak handling paths. The material risk is accidental disclosure through ordinary work, such as misdirected email, overbroad access, or unsecured sharing, especially when the process makes mistakes easy and detection slow.
Failure mechanism: Human error becomes a breach when users operate inside a workflow with excessive access, weak approval friction, or poor data handling safeguards. Training may reduce the odds, but it does not reliably prevent a mistake that the system is structurally set up to permit.
Impact: The result can be unauthorised disclosure, loss of confidentiality, incident response overhead, regulatory exposure, and repeated operational error. If the same weak process is used across many teams, the breach risk scales faster than training can compensate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 25 — Data protection by design and by default | Breach reduction depends on building safer default handling into the process. |
| Art. 32 — Security of processing | Directly supports prioritising technical and organisational measures against accidental disclosure. | |
| Recommendation — Design workflows so personal data exposure is limited by default. Implement appropriate technical and organisational measures to reduce processing risk. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Excess access is a common root cause of accidental disclosure and overexposure. |
| AU-2 — Audit Events | Monitoring helps detect repeat handling mistakes and weak processes. | |
| Recommendation — Restrict access rights to only what users need for their tasks. Log relevant data access and sharing events for review and investigation. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Reducing breach likelihood starts with controlling who can reach sensitive data. |
| Recommendation — Manage access rights tightly and remove unnecessary permissions. | ||
| ISO/IEC 27001:2022 | A.8.12 — Data leakage prevention | Directly addresses accidental disclosure risk through technical controls. |
| A.5.15 — Access control | Access control is central when staff handling drives breach likelihood. | |
| Recommendation — Apply data leakage prevention controls to limit unintended disclosure. Define and enforce access rules that limit unnecessary data exposure. | ||
Practitioner Guidance
What to prioritise: Start with the highest-frequency disclosure paths, especially shared inboxes, exports, cross-team handoffs, and broad access rights. Those are the places where technical friction removes the most risk fastest.
Decision rule: If a breach can occur without anyone intentionally bypassing policy, fix the workflow first; if the risk depends on a person recognising a subtle exception, reinforce it with training and supervision.
What good looks like: Staff can complete routine work with fewer manual judgment calls, less data moved by default, and clear escalation points when they need to share something outside the normal path.
Practitioner takeaway: Training is necessary, but breach reduction improves most when organisations make the safe action the easy action, then train people to recognise the remaining edge cases.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- When should organisations prioritise user training and third-party assessments alongside technical controls?
- Should organisations prioritise secrets rotation or policy controls first for agents?
- Should organisations prioritise secret scanning or privilege reduction first?