Data protection leaders: compliance without carrots or sticks
Originally published on LinkedIn, March 2019.

When employees stop following data protection policies and revert to the old way of working, the problem is rarely the policies themselves. It is almost always rooted in a poor or missing Data Protection Strategy, an inadequate framework, or a botched implementation. The good news is that none of this requires starting from scratch.
Frustration all round #
During a recent meeting with a potential client, the phrase “our employees are tired of hearing about GDPR” came up several times. Policies and procedures implemented over the previous two years were now largely ignored. Many parts of the company had returned to working in the old way.

The lawyer responsible for data protection felt her department was in control but was frustrated with the rest of the company. A manager from IT spoke of the lack of enforcement: “If my boss isn’t interested, why should I be?”
Enforcement? Times are changing #

For many years, organisations used a carrot-and-stick strategy to enforce their internal policies — reward for following the rules, negative consequence for not. Times are changing. Organisations must now motivate employees to live up to data protection policies through different approaches, and ensure that motivation and control are baked into organisational systems and frameworks from the outset — Data Protection by Design.
Get it right first time #
While technical controls and automation — retention and deletion, DLP tools, and so on — can help achieve compliance with some policies, the ineffectiveness of the manual framework elements is almost always rooted in a poor or missing Data Protection Strategy, an inadequate data protection lifecycle and framework, often followed by a botched implementation.
The following soft systems diagram outlines some of the key elements, touch-points, and interactions. Much depends on the social interaction of people from top to bottom:

Note: the diagram above is mostly applicable for B2Cs where personal data often fuels the business.
For some organisations, the initial decision to be minimally compliant and do things on the cheap is now starting to expose weak frameworks with no robust foundation or embedment, let alone alignment with existing business strategy, mission, values, and behaviours.
For organisations already in a mess, the priority is to identify the weaknesses and gaps and then prioritise the repair and improvement work — typically using a robust programme capability maturity model as a reference point.
Factors to consider #
Organisations do not need to start from scratch. There are plenty of existing frameworks and standards available globally that can be used for inspiration, adapted, and scaled to suit requirements. The keyword is “adapted” — this is often hard work. Here are some organisational factors that can help or hinder.
Alignment with existing business strategy #
All organisations need a Data Protection Strategy. Start by understanding the importance of personal data in your organisation. Is it fuelling your business? Do you have a large workforce? Do you need to attract top talent? What other laws and regulations may be applicable?
Align your Data Protection Strategy with the relevant elements of your business strategy, your organisation’s mission and vision, and its values and behaviours. Consider whether an ethics-based approach could be relevant — not only could this be a good business opportunity, but employees are often motivated when they see their employer doing the right thing and understand they are part of that.
Clear and realistic policies #
Have policies written in a clear, unambiguous manner consistent with your company voice. They must focus on what is important and not trivial matters. They must be action-oriented, realistic — not aspirational or fairy tales — measurable, and testable. Employees must be able to understand the context and see what is in it for them. Policies must engage hearts and minds, not frighten or confuse.

No legalese, please. The legal department should not normally be writing the policies — unless they have been on a creative writing course, or your organisation is a law firm.
Start-ups, creatives, and innovators #
Existing organisational culture can create resistance towards policies. This is widespread in creative and innovation workplaces where the notion of “we don’t need rules” is often lived and breathed by the executive team themselves.

In these environments, a solid understanding of existing work practices is needed to identify risk scenarios, which can then become part of the storytelling to the teams about why policies are needed and what business benefits will follow. Involve the teams in defining and writing the policies and rules they will ultimately own.
Empower your teams to document procedures #
Procedures — the how-to — underpin policies. Avoid writing them yourself. Train the individuals who will be using them, or will be responsible for them, and ensure they are involved in defining and writing them. They will feel empowered and trusted, and ownership will sit at local team level.
Where feasible, implement procedures on an ongoing basis rather than all at once. People can only absorb so many changes at any one time. Implementing piecemeal introduces changes in small chunks and enables a rhythm of change, provoking continual awareness and regular feedback. A big-bang implementation has become an outdated concept and is inherently risky.
When implementing procedures, use RACI matrices to clearly articulate expectations, roles, and responsibilities:

Build on existing compliance culture #
Depending on your industry sector and jurisdiction, pockets of compliance culture may already exist. Colleagues who have embedded practices around CSR, Anti-Bribery, Anti-Money Laundering, or Business Ethics are worth reaching out to for alignment tips.
Health and Safety regulations have been around for a long time, and many organisations work hard to live up to their obligations — though H&S culture does vary between countries.

A few years ago I facilitated workshops at the UK office of a Danish multinational and was struck by the strong H&S culture. As a guest, my day started with a fire precautions briefing. I was reminded to use the railing on the stairs, and an employee chased after me when I walked away from the coffee machine without a lid on my cup. That kind of motivated, embedded compliance culture is exactly what data protection programmes should be aiming for.
Cross-cultural misunderstanding #
Establishing a policy framework in a multinational organisation adds further complexity. Local workforce culture often differs from the Group. For example, if employees are accustomed to giving their credit cards to colleagues at lunchtime to buy food on their behalf, you will face real challenges when implementing safe behaviours around data handling.

Local culture also plays a significant part in communicating risk appetite. Agreeing, documenting, and communicating risk appetite and risk tolerances must start at executive level. Alignment between the Group and local markets must be consistent and account for local culture, local threats, and local operational setup.

A meaningful workday #
Organisations must provide employees involved in handling personal data with meaningful and motivating tasks. If work is tedious and boring, an employee may find ways to make their day more interesting by doing things they should not be doing.
In the UK, a receptionist at a doctor’s surgery was discovered accessing the health records of friends and family. Policies were in place and adequate training had been given. At trial, she claimed her daily tasks were monotonous. All it took was motivation — “I’m bored” — and opportunity — “I have system access.”

Other important factors #
- Get out of your office and walk the organisation. Ask questions, seek feedback, be on hand to help and clarify. Discuss the relevance of employees’ work in the bigger picture of how personal data fuels the business.
- Establish feedback loops to deal with improvement suggestions, resistance, or errors. Keep your door open. Show gratitude for contributions.
- Make it easy for your employees — where appropriate, provide the tools they need to live up to the policies.
- Provide regular, refreshed, role-based data protection education and training using innovative methods such as gamification.
- Run frequent awareness campaigns targeted to specific departments when policies and procedures change or new ones are introduced.
- Executives and senior management must be seen living and breathing the policies. I have written about this in my earlier article on setting the right tone from the top.
- Ensure regular policy reviews take place to address changes in business strategy, new threats, technology evolution, and societal change.
- Embrace assurance reviews and audits. Ensure risks are addressed appropriately and followed up.
- If following an ethics-based approach, you will typically be aiming to go beyond compliance. Read about the mindset your employees need to attain in Leaders: win by respecting your customers.
Frequently Asked Questions #
Why do data protection policies get ignored after initial implementation? The most common root causes are a weak or absent Data Protection Strategy, policies that were written in legalese by the legal team rather than in plain language by the people who understand the work, a big-bang implementation that overwhelmed employees, and an absence of visible commitment from senior management. Technical controls can enforce some requirements, but sustainable compliance depends on social factors — leadership, culture, and motivation.
What is the difference between a policy and a procedure in a data protection context? A policy states what must be done and why — it sets the expectation. A procedure describes how it is done in practice — the step-by-step. Policies are typically owned at a programme or governance level; procedures should be owned by the teams who carry them out, ideally written by those teams with appropriate education and guidance. This distinction matters because it determines who writes what, who owns it, and who is accountable when it breaks down.
How do you embed data protection compliance in a creative or innovation-led culture that resists rules? Start with understanding rather than enforcement. Map existing work practices, identify the risk scenarios that arise from them, and use those scenarios as the basis for storytelling — explaining why certain rules exist and what could go wrong without them. Involve the teams in defining the rules they will eventually own. People are far more likely to follow policies they helped write than ones handed down from a legal or compliance function.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





