Practical, plain-English training for UK small businesses, charities and care providers. Delivered by someone who works with this daily — not read off a generic slide deck.
Who this is for
Small organisations that handle personal data but do not have a compliance department — and where one member of staff clicking the wrong link causes a genuine problem.
🏢 Small businesses
5 to 50 staff handling customer or employee data
🏥 Care providers
Care homes and domiciliary care handling sensitive resident data
🤝 Charities
Handling donor and beneficiary data, often with volunteers
🏘️ Housing providers
Sheltered and supported housing with vulnerable residents
What we cover
1. UK GDPR in plain English
What the law actually requires, the six lawful bases, and the difference between what you must do and what consultants tell you that you must do.
2. Handling data subject requests
What to do when someone asks for their data, asks you to delete it, or objects to marketing. Deadlines, what you can refuse, and how to log it properly.
3. Recognising the scams that target organisations
Invoice redirection, CEO fraud, business email compromise and fake supplier requests — with real examples of what they look like.
4. Practical staff habits
Passwords, two-factor authentication, what not to put in an email, and how to verify a request without offending a genuine customer.
5. What to do when it goes wrong
Breach response, the 72-hour ICO reporting duty, when you must tell affected individuals, and how to document it.
6. Protecting vulnerable service users (care and housing only)
How fraudsters target elderly and vulnerable people, what staff should watch for, and how to raise a concern.
This is practical awareness training — helping your staff recognise scams and handle data requests properly. It is delivered by Nathan Brandon, founder of Silent Erase, an ICO-registered UK privacy service (registration C1971457).
It is not legal advice, and it is not a substitute for a Data Protection Officer where your organisation is legally required to appoint one. If you need formal DPO services or legal sign-off on a compliance position, you need a solicitor or a certified DPO — and we will tell you that rather than take the booking.
Why us rather than a generic course
Most GDPR training is written by people who have read the regulation. Ours is written by someone who spends every day sending erasure requests, tracking which organisations comply, and dealing with the fraud that follows when data leaks.
That means the examples are current and real, the scam content is genuinely up to date, and staff leave knowing what a fraudulent email actually looks like rather than a theoretical description of one.
Enquire about training
Tell us about your organisation and we will come back within 2 working days with a specific proposal. No obligation and no sales calls unless you ask for one.
Or email admin@silenterase.com directly · ICO Registration C1971457