↓Skip to main content

End of year budget, Data Protection Day, and planning your 2027 training calendar

Data Protection education and training 2027

Earlier this week, a client contacted me about delivering education to her team before the end of November because there was still money in the pot. In your company, there is no doubt also a line in the budget for data protection education/training. October is often the month when colleagues in the team ask questions about how much remains. For some data protection leaders, the answer is awkward: the year began with ambitions, and training and education has often remained earmarked rather than spent. That budget does not automatically roll over. Unspent budget at year-end is either surrendered or shapes for a smaller allocation next year. The window to do something useful with it is shorter than it feels.

Two ways to use what’s left #

The obvious option is to run education before 31 December. The second is to commission Q1 work now, while the budget still exists. A well-designed programme takes time: understanding your context, identifying the right audiences, building content that connects to how your people actually work. Commissioning in October or November, for delivery from January onwards, means the planning is done before new year pressures arrive.

Purpose and Means has just updated its course catalogue, which now covers an expanded range of topics — including AI governance, agentic AI and Article 22, geopolitics and data protection, tracking mechanisms, voice recording and transcription, digital finance, and a growing set of AI and data protection intersection courses. There is a good chance something on that list is relevant to your teams right now.

Looking further ahead: a new self-paced learning platform is in development, built around bite-sized modules and gamification — designed to make data protection training genuinely easy to consume rather than something people sit through once and forget. More on that soon.

Before year-end: FieldTalk in November #

If budget is tight or you just want a way to engage your data protection team before the year closes, FieldTalk is worth knowing about. It is a free online conference for data protection practitioners — no budget required, just register on the website and join. It runs in November, which makes it a natural way to bring something meaningful to your team in the final weeks of the year without a procurement process.

Details and registration are on the FieldTalk website.

Data Protection Day: an anchor for Q1 #

Data Protection Day falls on 28 January — a Thursday in 2027. It marks the anniversary of Convention 108 being first opened to signature, the first legally binding international treaty on data protection, and it has become a natural moment for companies to give their programme a visible leadership presence.

The companies that get the most from it are the ones that have already decided what they want to say and to whom, rather than the ones that notice the date arriving in the third week of January and throw something together. It works best as an anchor: a fixed point around which to structure the beginning of the year — a live session for all employees, a targeted workshop for a specific team, a moment to launch something new. Purpose and Means designs and delivers exactly this kind of work. We have written more about what makes it effective.

Planning a training cadence for 2027 #

The most common pattern in data protection training is the annual surge: something happens, training gets commissioned, delivered, and forgotten about until the same trigger appears again. Employees learn that data protection is something that happens to them periodically, not something woven into how the company works.

A training cadence looks different. It means deciding now what you want different groups to know and be able to do by December 2027 — and working backwards to a sequence of sessions that build on each other. Data Protection Day in January is a natural starting point. Some companies then add a mid-year module, a targeted intervention in Q4, and role-specific content for teams like marketing, HR, or product development.

The decisions that shape this are best made before the year is underway, not in response to whatever is urgent that week. The last weeks of the year are exactly the right time to make them, and if budget is available to support the planning, now is the moment to use it.

Start the conversation now #

If you have end-of-year budget and are trying to decide how to use it well, or if you are starting to think about what your data protection training calendar should look like in 2027, now is the right time to talk.

We can help you decide what your teams need, build a programme that fits your organisation’s context and culture, and structure delivery in a way that makes sense for your calendar and your budget — whether that means running sessions before the end of the year, anchoring the year on Data Protection Day in January, or building a sustained cadence across 2027.

Book a call to start the conversation. Or if you want to explore what we offer first, the full course portfolio is a good place to start.


If you found this useful, the Purpose and Means newsletter covers data protection, GRC, and AI governance — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you would like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords planning privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts