Skip to main content

Data protection leaders: compliance without carrots or sticks

Originally published on LinkedIn, March 2019.

Illustration of a crate of carrots beside a bucket of sticks — representing the outdated carrot-and-stick approach to compliance enforcement

When employees stop following data protection policies and revert to the old way of working, the problem is rarely the policies themselves. It is almost always rooted in a poor or missing Data Protection Strategy, an inadequate framework, or a botched implementation. The good news is that none of this requires starting from scratch.

Frustration all round #

During a recent meeting with a potential client, the phrase “our employees are tired of hearing about GDPR” came up several times. Policies and procedures implemented over the previous two years were now largely ignored. Many parts of the company had returned to working in the old way.

Illustration of hands fidgeting with a plaster, with handwritten text: “GDPR? It’s so ’last year’”

The lawyer responsible for data protection felt her department was in control but was frustrated with the rest of the company. A manager from IT spoke of the lack of enforcement: “If my boss isn’t interested, why should I be?”

Enforcement? Times are changing #

Illustration labelled “Relics of back-in-the-day management” showing a crate of carrots and a bucket of sticks

For many years, organisations used a carrot-and-stick strategy to enforce their internal policies — reward for following the rules, negative consequence for not. Times are changing. Organisations must now motivate employees to live up to data protection policies through different approaches, and ensure that motivation and control are baked into organisational systems and frameworks from the outset — Data Protection by Design.

Get it right first time #

While technical controls and automation — retention and deletion, DLP tools, and so on — can help achieve compliance with some policies, the ineffectiveness of the manual framework elements is almost always rooted in a poor or missing Data Protection Strategy, an inadequate data protection lifecycle and framework, often followed by a botched implementation.

The following soft systems diagram outlines some of the key elements, touch-points, and interactions. Much depends on the social interaction of people from top to bottom:

Rich picture soft systems diagram showing the interconnected elements of an internal data protection system for a B2C organisation — including strategy, policies, procedures, education, risk management, vendor management, and external factors

Note: the diagram above is mostly applicable for B2Cs where personal data often fuels the business.

For some organisations, the initial decision to be minimally compliant and do things on the cheap is now starting to expose weak frameworks with no robust foundation or embedment, let alone alignment with existing business strategy, mission, values, and behaviours.

For organisations already in a mess, the priority is to identify the weaknesses and gaps and then prioritise the repair and improvement work — typically using a robust programme capability maturity model as a reference point.

Factors to consider #

Organisations do not need to start from scratch. There are plenty of existing frameworks and standards available globally that can be used for inspiration, adapted, and scaled to suit requirements. The keyword is “adapted” — this is often hard work. Here are some organisational factors that can help or hinder.

Alignment with existing business strategy #

All organisations need a Data Protection Strategy. Start by understanding the importance of personal data in your organisation. Is it fuelling your business? Do you have a large workforce? Do you need to attract top talent? What other laws and regulations may be applicable?

Align your Data Protection Strategy with the relevant elements of your business strategy, your organisation’s mission and vision, and its values and behaviours. Consider whether an ethics-based approach could be relevant — not only could this be a good business opportunity, but employees are often motivated when they see their employer doing the right thing and understand they are part of that.

Clear and realistic policies #

Have policies written in a clear, unambiguous manner consistent with your company voice. They must focus on what is important and not trivial matters. They must be action-oriented, realistic — not aspirational or fairy tales — measurable, and testable. Employees must be able to understand the context and see what is in it for them. Policies must engage hearts and minds, not frighten or confuse.

Illustration of a suited figure banging a gavel and writing simultaneously — representing the legal department drafting policies in legalese

No legalese, please. The legal department should not normally be writing the policies — unless they have been on a creative writing course, or your organisation is a law firm.

Start-ups, creatives, and innovators #

Existing organisational culture can create resistance towards policies. This is widespread in creative and innovation workplaces where the notion of “we don’t need rules” is often lived and breathed by the executive team themselves.

Illustration with handwritten text “Rules? My people work best with as few as possible” above three figures at laptops — two of them wearing hoodies suggesting hackers or threat actors

In these environments, a solid understanding of existing work practices is needed to identify risk scenarios, which can then become part of the storytelling to the teams about why policies are needed and what business benefits will follow. Involve the teams in defining and writing the policies and rules they will ultimately own.

Empower your teams to document procedures #

Procedures — the how-to — underpin policies. Avoid writing them yourself. Train the individuals who will be using them, or will be responsible for them, and ensure they are involved in defining and writing them. They will feel empowered and trusted, and ownership will sit at local team level.

Where feasible, implement procedures on an ongoing basis rather than all at once. People can only absorb so many changes at any one time. Implementing piecemeal introduces changes in small chunks and enables a rhythm of change, provoking continual awareness and regular feedback. A big-bang implementation has become an outdated concept and is inherently risky.

When implementing procedures, use RACI matrices to clearly articulate expectations, roles, and responsibilities:

RACI matrix example showing activities across rows and roles across columns — with R (Responsible), A (Accountable), C (Consult), and I (Informed) assignments for each combination

Build on existing compliance culture #

Depending on your industry sector and jurisdiction, pockets of compliance culture may already exist. Colleagues who have embedded practices around CSR, Anti-Bribery, Anti-Money Laundering, or Business Ethics are worth reaching out to for alignment tips.

Health and Safety regulations have been around for a long time, and many organisations work hard to live up to their obligations — though H&S culture does vary between countries.

Illustration showing three H&S scenarios labelled “Safety first!” — a worker on a roof, an emergency exit sign, and a takeaway coffee cup with a lid

A few years ago I facilitated workshops at the UK office of a Danish multinational and was struck by the strong H&S culture. As a guest, my day started with a fire precautions briefing. I was reminded to use the railing on the stairs, and an employee chased after me when I walked away from the coffee machine without a lid on my cup. That kind of motivated, embedded compliance culture is exactly what data protection programmes should be aiming for.

Cross-cultural misunderstanding #

Establishing a policy framework in a multinational organisation adds further complexity. Local workforce culture often differs from the Group. For example, if employees are accustomed to giving their credit cards to colleagues at lunchtime to buy food on their behalf, you will face real challenges when implementing safe behaviours around data handling.

Illustration of multiple hands reaching up holding credit cards, with speech bubbles ordering food — representing shared card use as a cultural norm that conflicts with data security safe behaviours

Local culture also plays a significant part in communicating risk appetite. Agreeing, documenting, and communicating risk appetite and risk tolerances must start at executive level. Alignment between the Group and local markets must be consistent and account for local culture, local threats, and local operational setup.

Illustration of a coastal cliff with a sign reading “Medium / High Risk” — representing the challenge of communicating and calibrating risk appetite across different contexts

A meaningful workday #

Organisations must provide employees involved in handling personal data with meaningful and motivating tasks. If work is tedious and boring, an employee may find ways to make their day more interesting by doing things they should not be doing.

In the UK, a receptionist at a doctor’s surgery was discovered accessing the health records of friends and family. Policies were in place and adequate training had been given. At trial, she claimed her daily tasks were monotonous. All it took was motivation — “I’m bored” — and opportunity — “I have system access.”

Illustration of a figure resting their head on their hand with a thought bubble: “I’m bored! Hang on, I can look at the records again!”

Other important factors #

  • Get out of your office and walk the organisation. Ask questions, seek feedback, be on hand to help and clarify. Discuss the relevance of employees’ work in the bigger picture of how personal data fuels the business.
  • Establish feedback loops to deal with improvement suggestions, resistance, or errors. Keep your door open. Show gratitude for contributions.
  • Make it easy for your employees — where appropriate, provide the tools they need to live up to the policies.
  • Provide regular, refreshed, role-based data protection education and training using innovative methods such as gamification.
  • Run frequent awareness campaigns targeted to specific departments when policies and procedures change or new ones are introduced.
  • Executives and senior management must be seen living and breathing the policies. I have written about this in my earlier article on setting the right tone from the top.
  • Ensure regular policy reviews take place to address changes in business strategy, new threats, technology evolution, and societal change.
  • Embrace assurance reviews and audits. Ensure risks are addressed appropriately and followed up.
  • If following an ethics-based approach, you will typically be aiming to go beyond compliance. Read about the mindset your employees need to attain in Leaders: win by respecting your customers.

Frequently Asked Questions #

Why do data protection policies get ignored after initial implementation? The most common root causes are a weak or absent Data Protection Strategy, policies that were written in legalese by the legal team rather than in plain language by the people who understand the work, a big-bang implementation that overwhelmed employees, and an absence of visible commitment from senior management. Technical controls can enforce some requirements, but sustainable compliance depends on social factors — leadership, culture, and motivation.

What is the difference between a policy and a procedure in a data protection context? A policy states what must be done and why — it sets the expectation. A procedure describes how it is done in practice — the step-by-step. Policies are typically owned at a programme or governance level; procedures should be owned by the teams who carry them out, ideally written by those teams with appropriate education and guidance. This distinction matters because it determines who writes what, who owns it, and who is accountable when it breaks down.

How do you embed data protection compliance in a creative or innovation-led culture that resists rules? Start with understanding rather than enforcement. Map existing work practices, identify the risk scenarios that arise from them, and use those scenarios as the basis for storytelling — explaining why certain rules exist and what could go wrong without them. Involve the teams in defining the rules they will eventually own. People are far more likely to follow policies they helped write than ones handed down from a legal or compliance function.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts