Agiliton
Sector obligation map

Mandatory training obligations in technology and SaaS

0 training duties across 1 instrument binding Technology & SaaS, plus 10 that bind you whatever your sector — statute, rulebook, statutory guidance and licence conditions. Every one traced to its clause, its date and its published source, and each one labelled with what makes it a training duty.

JurisdictionUnited Kingdom
Built2026-08-12
Training duties10
Instruments9
Verified10 of 10
Every entry traced to a published clause

We searched the sector’s own regime and found no staff training duty in it. That is the finding, and it is more useful than a list would have been.

Technology and SaaS is the thinnest sector in this series for sector-specific training duties, and we would rather say so than pad it. Your obligations are real — they simply arrive through the cross-cutting layer that binds every employer, not through a regime aimed at you.

That has a practical consequence. A compliance programme built around “what does our regulator require” will under-deliver here, because the binding duties come from health and safety law, fire safety and data protection — owned, in most technology firms, by three different people none of whom is the CISO.

The obligations

Each clause carries a label saying why it is a training duty. Where the instrument does not use the word, we cite the guidance or the case that makes training the way you discharge it. Where we cannot cite anyone, it is not listed as a training duty at all.

says trainThe instrument itself requires training, instruction or CPD.
competenceThe instrument requires competence, qualification or knowledge. Training is the usual means; the instrument does not name it.
guidanceThe binding duty is an outcome. Official guidance under the instrument names training as how it is discharged.
case lawThe binding duty is an outcome. Case law makes training the operative discharge.
ClauseWho must be trained or assessedWhat is requiredIntervalEvidence required

Binds you whatever your sector

10 further obligations sit outside Technology & SaaS regulation and bind you as an employer or as a deployer of AI. They are the ones a sector-by-sector review misses, because nobody who reads only their own rulebook ever reaches them.

ClauseWho must be trained or assessedWhat is requiredIntervalEvidence required
EU AI Act (Reg (EU) 2024/1689)
Article 4 (AI literacy)
says train
defined population — quoted from the pre-amendment text: "their staff and other persons dealing with the operation and use of AI systems on their behalf"AS ENACTED: providers and deployers were to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used. AS AMENDED from 2026-07-27 by the Digital Omnibus on AI: AI literacy remains an obligation on providers and deployers, but no specific or 'sufficient' level is mandated; the Commission and Member States take a stronger role in promoting AI literacy. The obligation on deployers of HIGH-RISK AI systems to ensure staff are trained for human oversight remains in place.none specifiednone specified
Article 26(2)
says train
named population — the natural persons assigned to exercise human oversightQuoted: "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."none specifiednone specified in this paragraph
Employment Rights Act 2025
Whole Act — training provisions at s.65 and related
says train
named role — trade union equality representatives, not the general workforceThe Act's training provisions concern whether a trade union equality representative has undergone sufficient training to carry on those activities, with notice requirements on the union and reference to a relevant ACAS or Secretary of State Code of Practice. It is not a mandatory workforce training duty of the kind the rest of this map records.none specifiedWritten notice from the trade union to the employer
Equality Act 2010
Section 109(4), with section 109(1)
case law
Allay (UK) Ltd v Gehlen [2021] UKEAT/0031/20 — stale or inadequate training defeats the s.109(4) 'all reasonable steps' defence, making training the operative discharge.
all staff — the defence turns on steps taken to prevent employees doing discriminatory actsAn employer is liable for anything done by a person in the course of their employment. Quoted from 109(4): "In proceedings against A's employer (B) in respect of anything alleged to have been done by A in the course of A's employment it is a defence for B to show that B took all reasonable steps to prevent A—(a) from doing that thing, or (b) from doing anything of that description."none specifiedThe employer must SHOW the steps taken. The burden sits with the employer.
UK GDPR
Article 24, read with Article 5(2)
guidance
UK GDPR Article 39(1)(b) — read at source 2026-08-12 — names staff training as an element of compliance with the Regulation: the data protection officer must "monitor compliance with this Regulation... including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits". LIMIT OF THIS CITATION, stated plainly: Article 39 applies only where Article 37 requires a DPO to be appointed, so it does not by itself establish a training duty for every controller. It establishes that the Regulation treats staff training as part of compliance. The unconditional citation would be the ICO Accountability Framework, which has NOT been read — see not_yet_searched.
not specified — training is not expressly named in Article 24Quoted: "the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation." Those measures must be reviewed and updated where necessary, and are to include appropriate data protection policies where proportionate to the processing activities. Article 5(2) supplies the accountability principle itself: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1" — that is, with all six data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality.measures to be reviewed and updated where necessary — no intervalThe controller must be able to DEMONSTRATE compliance. This is the accountability limb.
The Regulatory Reform (Fire Safety) Order 2005
Article 21, with articles 3 and 6
says train
all staff — quoted: "his employees"Quoted, 21(1): the responsible person "must ensure that his employees are provided with adequate safety training (a) at the time when they are first employed; and (b) on their being exposed to new or increased risks because of" transfer or change of responsibilities, new or changed work equipment, new technology, or a new or changed system of work. 21(2): that training must "(a) include suitable and sufficient instruction and training on the appropriate precautions and actions to be taken by the employee in order to safeguard himself and other relevant persons on the premises; (b) be repeated periodically where appropriate; (c) be adapted to take account of any new or changed risks; (d) be provided in a manner appropriate to the risk identified by the risk assessment; and (e) TAKE PLACE DURING WORKING HOURS."Trigger-based, not periodic: on first employment AND on each of four listed changes. "Repeated periodically where appropriate" — no interval stated.none specified in the article
The Management of Health and Safety at Work Regulations 1999
Regulation 13(2), with 13(1) and 13(3)
says train
all staff — every employee, on recruitment and again on each triggering changeQuoted, 13(2): "Every employer shall ensure that his employees are provided with adequate health and safety training— (a) on their being recruited into the employer's undertaking; and (b) on their being exposed to new or increased risks because of— (i) their being transferred or given a change of responsibilities within the employer's undertaking, (ii) the introduction of new work equipment into or a change respecting work equipment already in use within the employer's undertaking, (iii) the introduction of new technology into the employer's undertaking, or (iv) the introduction of a new system of work into or a change respecting a system of work already in use within the employer's undertaking." 13(1) separately requires the employer, "in entrusting tasks to his employees, [to] take into account their capabilities as regards health and safety."No fixed interval. The duty is TRIGGER-BASED — on recruitment, and on each of the four changes listed in 13(2)(b).Not specified in the regulation itself.
Health and Safety at Work etc. Act 1974
Section 2(2)(c), with section 2(1)
says train
all staff — scoped by what is 'necessary to ensure' their health and safetyQuoted, s.2(2)(c): the employer's general duty extends in particular to "the provision of such information, instruction, training and supervision as is necessary to ensure, so far as is reasonably practicable, the health and safety at work of his employees." This is the primary-legislation parent of the MHSWR reg 13 duty. Note the double qualifier: training is owed only so far as it is BOTH 'necessary to ensure' health and safety AND 'reasonably practicable'.None. The measure is necessity, not interval.Not specified in the section.
Council Directive 89/391/EEC (the Framework Directive) on the introduction of measures to encourage improvements in the safety and health of workers at work
Article 12(1) and 12(4)
says train
all staff — 'each worker'Quoted, 12(1): "The employer shall ensure that each worker receives adequate safety and health training, in particular in the form of information and instructions specific to his workstation or job: — on recruitment, — in the event of a transfer or a change of job, — in the event of the introduction of new work equipment or a change in equipment, — in the event of the introduction of any new technology. The training shall be: — adapted to take account of new or changed risks, and — repeated periodically if necessary." Quoted, 12(4): "The training referred to in paragraphs 1 and 3 MAY NOT BE AT THE WORKERS' EXPENSE... The training referred to in paragraph 1 MUST TAKE PLACE DURING WORKING HOURS."No fixed interval. Trigger-based on four named events, PLUS two standing qualities the UK implementation does not spell out as clearly: adapted to new or changed risks, and "repeated periodically if necessary".Not specified in Article 12.
Article 12(2)
says train
named population — workers from OUTSIDE undertakings and/or establishments engaged in work in your undertaking. Contractors, agency staff, visiting engineers, maintenance crews.Quoted in full: "The employer shall ensure that workers from outside undertakings and/or establishments engaged in work in his undertaking and/or establishment HAVE IN FACT RECEIVED appropriate instructions regarding health and safety risks during their activities in his undertaking and/or establishment."None — triggered by the outside workers being engaged in work in your undertaking.Not specified, but note the wording: the employer must ensure they "have in fact received" the instructions. That is a verification duty, not a provision duty — it is not discharged by having issued something.

Related duties — not training obligations

2 provisions that sit alongside the duties above without themselves requiring training. They are here because they are the ones most often mistaken for training duties, or most often missed when scoping them. We separate them rather than pad the count.

ClauseWho it concernsWhat is requiredIntervalEvidence required
UK General Data Protection Regulation (Regulation (EU) 2016/679 as retained)
Article 39(1)(b)
related
named role — staff involved in processing operationsQuoted, Art 39(1)(b): the DPO's tasks include "to monitor compliance with this Regulation, with other domestic law relating to data protection and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, AWARENESS-RAISING AND TRAINING OF STAFF INVOLVED IN PROCESSING OPERATIONS, and the related audits".None.Art 39(1)(b) refers to "the related audits", which presupposes the training is auditable.
Article 32(4)
related
named population — any natural person acting under the authority of the controller or processor who has access to personal data. That is wider than 'employees': it reaches contractors, temps and anyone else acting under authority.Quoted in full: "The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by domestic law." This is an INSTRUCTION duty rather than a training duty — but it is the provision that obliges a technology business to make sure the people touching personal data know what they may and may not do with it, and instruction is how that is discharged in practice.None.Not specified in Article 32(4). Article 5(2) accountability applies generally.

Where gaps commonly sit

What we searched, and what it returned

Three whole instruments, scanned end to end, for any staff training or competence duty.

NIS 2018 (162,143 chars): 99 raw keyword hits, 9 once “competent authority” — the Regulations’ term for the regulator, not for individual skill — was excluded. None imposes a duty on staff.
Online Safety Act 2023 (824,013 chars): all 12 occurrences of “training” sit in Schedule 1, the list of services exempt from the Act, defining education and training providers. Not one is an operative duty.
PSTI Act 2022 (170,858 chars): zero occurrences. Its security requirements are product-facing, not workforce-facing.

Regulation 12, the security duty for relevant digital service providers, requires “appropriate and proportionate measures to manage the risks” and lists the elements: security of systems and facilities, incident handling, business continuity management, monitoring. Training is not among them.

This negative covers the operative text of SI 2018/506 only. The NIS guidance layer and the Cyber Assessment Framework are declared unread.

The GDPR training requirement is not the one usually cited

Article 39(1)(b) is where the Regulation names training — but as a task assigned to a data protection officer, to monitor “awareness-raising and training of staff involved in processing operations, and the related audits”.

Only organisations required to appoint a DPO under Article 37 have an Article 39 duty at all. An organisation with no DPO still owes Articles 24, 32 and 5(2) — and those are the obligations training actually discharges. Cited the wrong way round, a firm can conclude it has no duty because it has no DPO.

Coverage

This map states what it did not check as well as what it did. A map that quietly omits its own gaps is worth less than one that marks them.

Searched and found

0 obligations across 1 instruments, each read directly from the published source on 2026-08-12.

Searched and found nothing

Recorded because “we searched and found nothing” is a different fact from “we did not search”.

  • The Network and Information Systems Regulations 2018 (SI 2018/506) — WHOLE INSTRUMENT (162 — NO EXPRESS STAFF TRAINING DUTY FOUND. The raw keyword scan returned 99 hits, which collapsed to 9 once 'competent authority' — the Regulations' term for the REGULATOR, not for individual skill — was excluded. None of the remaining 9 imposes a training or competence duty on staff. Regulation 12, the security duty for relevant digital service providers, requires 'appropriate and proportionate measures to manage the risks' and lists the elements at Article 2 of EU Regulation 2018/151 (security of systems and facilities, incident handling, business continuity management, monitoring) — training is not among them. Read at source 2026-08-12. SCOPE OF THIS NEGATIVE: it covers the operative text of SI 2018/506 only. It does not cover the NIS guidance layer, the Cyber Assessment Framework, or sector-specific competent authority guidance, none of which has been read.
  • The Online Safety Act 2023 — WHOLE INSTRUMENT (824 — NO STAFF TRAINING DUTY EXISTS IN THIS ACT. Every one of the 12 occurrences sits in SCHEDULE 1, which lists the services EXEMPT from the Act's duties, and they are there because education and training providers are among the exempted categories — e.g. paragraph 19 ('Education provided by an independent training provider') and paragraph 22, which defines 'independent training provider' as a provider of post-16 education or training meeting funding and inspection conditions. Not one of the 12 is an operative duty on a regulated service to train anybody. SCOPE: the Act's operative text and Schedules only. Ofcom's codes of practice and guidance issued under the Act have NOT been read, and are the more likely home of any competence expectation.
  • The Product Security and Telecommunications Infrastructure Act 2022 — WHOLE INSTRUMENT (170 — ZERO occurrences of 'training' or 'trained' in the entire Act. Its security requirements are product-facing — what a connectable product must do — not workforce-facing. SCOPE: the Act's operative text only; the security requirements regulations made under it were not separately scanned.
Not searched

Their absence is not evidence that they contain no training duty.

  • UK GDPR Articles 24, 32 and 5(2) — these are where the training obligation actually sits, and they are held in the cross-cutting file where one record is currently DEMOTED for want of a citation. Article 39(1)(b) recorded here may be the citation that upgrades it.
  • Data (Use and Access) Act 2025 and any consequential amendment to the UK GDPR training/DPO provisions — not checked.
  • Cyber Essentials / ISO 27001 — contractual and certification requirements, not statutory. Should be recorded as such so they are not mistaken for law.
  • FCA regulation for the fintech subset of this sector — a technology firm carrying a Part 4A permission is inside the Financial Services map, not this one.
  • Ofcom codes of practice and guidance issued under the Online Safety Act 2023 — the Act itself has now been read in full and contains no staff training duty (see negative findings), so if a competence expectation exists for regulated services it will be in the Ofcom layer. Unread; highest-value remaining gap for this sector.
  • Security requirements regulations made under the PSTI Act 2022 — the Act itself has zero training references; the regulations beneath it were not separately scanned.
  • Data (Use and Access) Act 2025 — amended UK GDPR Art 32(3) with effect 20.8.2025. Its wider effect on the Art 24/32/39 accountability layer has not been traced.

Sources

Thirty minutes, on your own material

Ten minutes on where your obligations actually sit. Fifteen watching a module built live from your own source documents. Five on whether there is a next step. Nothing to prepare and nothing to send beforehand.

Book a briefing