When introducing e-learning, many human resources developers are faced with the question of what needs to be done regarding data protection. After all, a digital learning platform is always associated with personal data. But data protection and e-learning are actually very easy to combine – if you keep a few basic things in mind. The three most important tips: Think about data protection from the very beginning, pay attention to transparency, and anonymize data when in doubt.
The good news first: Anyone who generally deals with data protection does not need to be afraid of the topic in e-learning either. Laws like the GDPR have, among other things, contributed to the fact that the mere mention of the term data protection causes stomach aches for many people. Anyone who has not specialized in the field of data protection is often faced with many questions.
I therefore spoke to our blink.it data protection expert, who completed an intensive 60-hour data protection training. I wanted to know from him: What can human resources developers in companies concretely do so that the topic of data protection does not become a problem when introducing new e-learning processes?
Note: All information is based on careful research and consultation with experts. However, we generally cannot provide legal advice. For specific questions regarding your company, it is best to contact your internal data protection officer directly.
In e-learning and offline: This is what "data protection must be maintained" means
The expert's answers were all logical and easy to understand. In principle, the following always applies: Data protection must be maintained. At least those who process personal data should concern themselves with it. This applies to seminars just as much as to setting up an e-learning platform for employee training.
The processing of personal data is therefore generally prohibited. Unless you have a legal basis. And you can ensure exactly that if you follow a few tips. A legal basis exists primarily in the following two cases:
The consent of the person concerned is available (in writing).
Another law overrides data protection, e.g. the retention obligation for invoices.

E-learning and data protection? No problem if you obtain the consent of the participants.
In e-learning, the consent of the participants in your employee training is the key to maintaining data protection. Basically, our data protection officer has three tips for companies that want to use e-learning:
Think about data protection from the very beginning
Pay attention to transparency
When in doubt: Anonymize data
What is meant by these roughly summarized tips is presented in more detail below.
Tip 1: Think about data protection from the very beginning
The most important tip our data protection officer shared with me: Think about data protection as early as possible and contact your company's internal data protection officer. Describe to them what kind of e-learning is to be used in the context of employee training and ask about internal data protection regulations for it.
The best and easiest way to maintain data protection is a declaration of consent from those affected – i.e. the participants of the e-learning or employee training. Important: A declaration of consent cannot be given retroactively. The consent of each participant must therefore already be present before the platform is used for the first time. This is exactly why you should think about data protection from the very beginning.
In principle, the following applies to a declaration of consent for data processing:
It cannot be given retroactively.
It can be revoked by the person concerned at any time.
It must be purpose-bound.
The purpose must be limited in time.
Purpose-bound means that consent is given for a specific use of data processing. The time limit does not have to be specified in calendar days – it is sufficient, for example, to relate the processing to the duration of the employee's employment in the company. In this example, the time limit is reached when the employee leaves the company.
By the way: According to the GDPR, "processing of personal data" refers to any case in which data is written down. This applies to physical files just as much as to digital files – whether offline or online. Any information that makes a person identifiable is considered personal. More on this under: www.dsgvo-gesetz.de
Thinking about data protection from the very beginning concretely means:
Contacting the internal data protection officer as soon as the topic of e-learning comes up in the company.
Obtaining a declaration of consent from the participants as soon as they register on the e-learning platform.
Tip 2: Pay attention to transparency
Even with a declaration of consent, the data protection officer advises making all data processing as open and transparent as possible. That is to say: Inform your training participants when and how all information is stored. For example, if 2,000 participants are working on a platform in e-learning and every comment can be viewed by all participants – point this out to the participants, perhaps with an information text on the platform itself or detailed information in the intranet.
By the way: Anyone who writes their own address on a (freely accessible) website publishes it by doing so. However, anyone who leaves their address in a place on the web that is protected by a barrier has not made it public. A barrier exists, for example, if you have to create an account to access a website. Thus, personal data that appears on LinkedIn, the intranet, or an e-learning platform, for example, may not be passed on or processed in any other way.

Transparency in e-learning: It should be clear to participants at all times when and for what purpose their data is being stored and processed.
A transparent e-learning provider
The point of transparency does not only apply to disclosing data processing to participants. The technology partner of the e-learning platform should also have transparent data protection regulations.
Check whether your digital provider meets the following requirements:
Possibilities for anonymization, e.g. for quiz questions and tests
Possibility to obtain the consent of the participants in a simple and transparent manner even before processing
Existence of a data processing agreement
A data processing agreement (DPA) is mandatory when two parties enter into an agreement that involves the processing of digital data. It defines the purpose and type of processing. Ideally, your e-learning provider already has a DPA that your company or your data protection officer can review.
And what about us at blink.it? Data protection is not only fundamentally important to us; we also attach great importance to transparency and the simple application of data protection in e-learning. Thus, we not only fulfill the points mentioned above, but also offer to customize the declaration of consent during user registration to your own data protection regulations. In this way, individual regulations for you and your participants can also be included. And by the way: All blink.it employees have completed basic data protection training.
Tip 3: When in doubt – anonymize data
If there is no sufficient reason to collect personal data in e-learning, you can still anonymize or pseudonymize the data in accordance with data protection. For example, when evaluating an online training course, it may not be important how individual participants performed. If it is about the fundamental success of the e-learning measure, the trainer should summarize the data in such a way that no conclusions can be drawn about individual results.
In the best case, the trainer can set up the platform itself in such a way that results from interactive modules such as quiz questions, surveys, or exams are provided in anonymized form. This allows you to decide internally if and to what extent even the trainer can view the personal results.
Involving the data protection officer from the very beginning, paying attention to transparency, and checking the DPA – then you can combine the topics of e-learning and data protection without any difficulties!
Conclusion
Data protection in e-learning succeeds best when companies plan for it from the very beginning, handle data transparently, and only process the personal information that is actually needed.
Anyone introducing digital learning should therefore involve the internal data protection officer at an early stage and clarify together which personal data will be processed and what legal basis exists for this. The data protection terms of the learning platform provider and a required data processing agreement should also be reviewed. Where personal data is not necessary, anonymization or pseudonymization can offer additional options.

Frequently Asked Questions and Answers
What role does data protection play in e-learning?
Personal data is frequently processed in e-learning, for example when registering on a learning platform or when using quiz questions, exams, and comment functions. Therefore, data protection should already be considered during the planning phase.
When should the data protection officer be involved in the introduction of e-learning?
The internal data protection officer should be involved as early as possible. This allows clarification, even before the introduction of the learning platform, on which data will be processed and which internal data protection regulations apply.
What should companies look out for regarding the data protection of a learning platform?
Among other things, companies should pay attention to transparent data protection terms, possibilities for anonymization or pseudonymization, and the necessary contractual regulations for data processing.
When can data be anonymized in e-learning?
Anonymization can be useful when individual participant results are not needed to evaluate a learning measure. Data can then be summarized in such a way that no conclusions can be drawn about individual persons.







