Create the user named eric and deny to interactive login.
Who ever creates the files/directories on /data group owner should be automatically should be the same group owner of /data.
Create the group named training
Make on /data that only the user owner and group owner member can fully access.