Skip to main content

Data Protection Day 2027: the planning starts now

Data Protection Day 2027 planning

Every year on 28 January, companies around the world mark Data Protection Day, or Data Privacy Day as the Americans call it. The date is itself a story. It commemorates the day in 1981 when the Council of Europe opened Convention 108 for signature - the first legally binding international treaty on data protection. Few employees know that and fewer still know why it was needed.

That gap is the opportunity. Over the years, Purpose and Means has helped companies plan, create and deliver Data Protection Day awareness, education and training for all employees and for dedicated data protection teams. What I have learned in that time is simple: people do not remember rules, they remember stories.

Why stories work better than articles #

For many employees data protection or ‘GDPR’ is a list of rules: do this, do not do that, report this and that. Presented that way, the rules feel like blockages to progress or to innovate. I think GDPR gets wrongly blamed for many things that shouldn’t be done and in some cases it’s because of ignorance, poor guidance for insufficient education.

Once people understand where a rule came from, or why it exists, it becomes meaningful. They see what went wrong, who was harmed, and why someone decided the law had to change.

Data subject rights are a good example. They get treated as a checklist of requests that land in someone’s inbox, and my impression is that many data protection practitioners do not fully understand why they even exist, other than it was something they got taught on a course. Each right has its own story:

The right of access grew out of the late 1960s / early 1970s, when governments and companies began building large computerised databases and citizens realised they had no way of knowing what was held about them.

The right to rectification has roots in credit reporting, where inaccurate records quietly shut people out of loans, housing and jobs, often without them ever finding out why.

The right to be forgotten became a household concept after a Spanish man took on Google over search results pointing to a decades-old newspaper notice about his debts. The 2014 ruling changed how the world thinks about the internet’s memory.

Protection against solely automated decisions can be traced back to France in 1974, when a government plan to link citizens’ records across administrations through a single identifier caused a public outcry. France’s 1978 data protection law followed.

When a customer service agent understands that an access request connects to decades of people fighting to find out what was held about them, the request stops being an annoyance. It becomes something worth getting right.

This is just one example of the types of topics Purpose and Means delivers for clients during data protection month / week, or the day itself. Sessions on the origins of data protection itself, and on the mechanisms most people take for granted: consent, purpose limitation, data minimisation, the role of the regulator. Each has a why, and the why is what makes it stick.

Whole company, or a specific audience #

Data Protection Day works on two levels, and Purpose and Means supports both.

Making data protection come to life for all employees. This means broad, engaging sessions that give everyone a reason to care, whether they work in the warehouse, the finance team or the executive suite. The stories are relatable.

Deeper, niche education for specific teams. Some audiences need more than awareness. I create focused content for:

  • Marketing and digital marketing teams, where tracking, profiling and consent decisions are made every day
  • DPOs, privacy champions, data protection ambassadors - whatever you call them in your organisation
  • Dedicated data protection teams who want to sharpen their knowledge, rethink how they engage the business, or plan the year ahead

A privacy champion who can tell the story behind a rule is far more persuasive than one who can only quote the article number.

From a single presentation to an interactive programme #

What I create depends on what fits your organisation, your culture and your internal platforms. It can be:

A presentation with a speaker, delivered live in person or virtually, built around stories and strong visuals rather than bullet points.

Content for your own internal systems, including interactive exercises, quizzes, games and scenario-based activities your employees can work through at their own pace.

A mix of both, such as a live session on Data Protection Day followed by self-paced activities across the week or the month.

Everything is designed to be relevant to your organisation and its sector. It’s important that your employees can apply the new knowledge in their own job context.

Start planning now #

Data Protection Day 2027 falls on a Thursday. That sounds a long way off, but good content takes time, and November and December are when internal calendars fill up and approval processes slow down. The organisations that get the most from 28 January are the ones that start the conversation in the autumn.

If you would like to make this year’s Data Protection Day the one your employees actually remember, now is the time to talk.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you would like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts