Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations prioritise staff training or technical controls…
Governance, Ownership & Risk

Should organisations prioritise staff training or technical controls first for GDPR breach reduction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Organisations should treat both as necessary, but the first priority is reducing the chance of accidental disclosure through technical and procedural controls. Training matters because human error is a dominant breach factor, yet the article shows that weak measures and poor awareness together create the failure. Effective programmes combine clearer workflows, better safeguards, and regular awareness training.

Why technical controls come first for breach reduction

The best first move is to reduce the chance that a mistake becomes a reportable breach. For GDPR, that usually means tightening data handling paths, limiting access, and making disclosure harder to do accidentally. Training is still necessary, but it works best when people are operating inside safer workflows rather than relying on memory alone.

That is why technical and procedural controls deserve priority. They shape the default state of the environment, whereas training depends on consistent human performance under pressure, interruptions, and ambiguity. If the underlying process still makes accidental disclosure easy, awareness alone will not reliably prevent it.

For privacy and data handling controls, see the Identity Data Privacy and Consent Guide, which focuses on minimisation, lawful handling, and retention discipline. The same logic appears in the EU General Data Protection Regulation (GDPR), especially where security of processing and data protection by design shape how organisations should build the control environment.

Why training still matters, but cannot carry the programme alone

Staff training is most valuable where judgement is required: spotting unusual requests, pausing before sending data, escalating exceptions, and understanding what counts as personal data. It helps reduce risky behaviour, but it does not remove risky conditions. A well-trained user can still make a mistake if the system is poorly designed, the process is unclear, or the approval path is too easy to bypass.

Training also degrades if it is treated as a one-time compliance exercise. In practice, the highest value comes from short, repeated reinforcement tied to real workflows, not from broad awareness messaging detached from the tasks people actually perform. That is especially true where staff handle customer records, exports, shared mailboxes, or exceptions to normal access.

Organisations should therefore align awareness with the real failure points in handling personal data, then support it with stronger baseline controls. The CIS Controls v8 are useful here because they emphasise account management, access control, audit logging, and data protection as practical safeguards that reduce avoidable exposure.

How to decide the sequence in practice

The right sequence is usually: first, remove the easiest paths to accidental disclosure; second, train staff on the remaining judgement points; third, monitor for repeat mistakes. If a process allows large exports, broad visibility, or uncontrolled sharing, training should not be the only compensating measure. If the workflow is already constrained, training becomes more effective because staff are making fewer high-risk decisions.

A useful test is whether a breach could still happen even if the person involved knew the policy. If the answer is yes, the organisation needs stronger controls before it relies on awareness alone. That includes clearer permissions, safer defaults, fewer manual handoffs, and stronger review points for outbound sharing and data movement.

For structured control selection and audit-ready governance, the NIST SP 800-53 Rev 5 Security and Privacy Controls offers a control catalogue that supports access control, audit, and system integrity decisions. For organisations building to a formal management system, ISO/IEC 27001:2022 Information Security Management gives a governance model for combining policy, implementation, and review.

Risk and Threat Considerations

GDPR breach reduction fails when organisations overestimate how much awareness can compensate for weak handling paths. The material risk is accidental disclosure through ordinary work, such as misdirected email, overbroad access, or unsecured sharing, especially when the process makes mistakes easy and detection slow.

Failure mechanism: Human error becomes a breach when users operate inside a workflow with excessive access, weak approval friction, or poor data handling safeguards. Training may reduce the odds, but it does not reliably prevent a mistake that the system is structurally set up to permit.

Impact: The result can be unauthorised disclosure, loss of confidentiality, incident response overhead, regulatory exposure, and repeated operational error. If the same weak process is used across many teams, the breach risk scales faster than training can compensate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 25 — Data protection by design and by defaultBreach reduction depends on building safer default handling into the process.
Art. 32 — Security of processingDirectly supports prioritising technical and organisational measures against accidental disclosure.
Recommendation — Design workflows so personal data exposure is limited by default. Implement appropriate technical and organisational measures to reduce processing risk.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeExcess access is a common root cause of accidental disclosure and overexposure.
AU-2 — Audit EventsMonitoring helps detect repeat handling mistakes and weak processes.
Recommendation — Restrict access rights to only what users need for their tasks. Log relevant data access and sharing events for review and investigation.
CIS Controls v8CIS-6 — Access Control ManagementReducing breach likelihood starts with controlling who can reach sensitive data.
Recommendation — Manage access rights tightly and remove unnecessary permissions.
ISO/IEC 27001:2022A.8.12 — Data leakage preventionDirectly addresses accidental disclosure risk through technical controls.
A.5.15 — Access controlAccess control is central when staff handling drives breach likelihood.
Recommendation — Apply data leakage prevention controls to limit unintended disclosure. Define and enforce access rules that limit unnecessary data exposure.

Practitioner Guidance

What to prioritise: Start with the highest-frequency disclosure paths, especially shared inboxes, exports, cross-team handoffs, and broad access rights. Those are the places where technical friction removes the most risk fastest.

Decision rule: If a breach can occur without anyone intentionally bypassing policy, fix the workflow first; if the risk depends on a person recognising a subtle exception, reinforce it with training and supervision.

What good looks like: Staff can complete routine work with fewer manual judgment calls, less data moved by default, and clear escalation points when they need to share something outside the normal path.

Practitioner takeaway: Training is necessary, but breach reduction improves most when organisations make the safe action the easy action, then train people to recognise the remaining edge cases.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org