Data Protection Day 2027: the planning starts now

Every year on 28 January, companies around the world mark Data Protection Day, or Data Privacy Day as the Americans call it. The date is itself a story. It commemorates the day in 1981 when the Council of Europe opened Convention 108 for signature - the first legally binding international treaty on data protection. Few employees know that and fewer still know why it was needed.
That gap is the opportunity. Over the years, Purpose and Means has helped companies plan, create and deliver Data Protection Day awareness, education and training for all employees and for dedicated data protection teams. What I have learned in that time is simple: people do not remember rules, they remember stories.
Why stories work better than articles #
For many employees data protection or ‘GDPR’ is a list of rules: do this, do not do that, report this and that. Presented that way, the rules feel like blockages to progress or to innovate. I think GDPR gets wrongly blamed for many things that shouldn’t be done and in some cases it’s because of ignorance, poor guidance for insufficient education.
Once people understand where a rule came from, or why it exists, it becomes meaningful. They see what went wrong, who was harmed, and why someone decided the law had to change.
Data subject rights are a good example. They get treated as a checklist of requests that land in someone’s inbox, and my impression is that many data protection practitioners do not fully understand why they even exist, other than it was something they got taught on a course. Each right has its own story:
The right of access grew out of the late 1960s / early 1970s, when governments and companies began building large computerised databases and citizens realised they had no way of knowing what was held about them.
The right to rectification has roots in credit reporting, where inaccurate records quietly shut people out of loans, housing and jobs, often without them ever finding out why.
The right to be forgotten became a household concept after a Spanish man took on Google over search results pointing to a decades-old newspaper notice about his debts. The 2014 ruling changed how the world thinks about the internet’s memory.
Protection against solely automated decisions can be traced back to France in 1974, when a government plan to link citizens’ records across administrations through a single identifier caused a public outcry. France’s 1978 data protection law followed.
When a customer service agent understands that an access request connects to decades of people fighting to find out what was held about them, the request stops being an annoyance. It becomes something worth getting right.
This is just one example of the types of topics Purpose and Means delivers for clients during data protection month / week, or the day itself. Sessions on the origins of data protection itself, and on the mechanisms most people take for granted: consent, purpose limitation, data minimisation, the role of the regulator. Each has a why, and the why is what makes it stick.
Whole company, or a specific audience #
Data Protection Day works on two levels, and Purpose and Means supports both.
Making data protection come to life for all employees. This means broad, engaging sessions that give everyone a reason to care, whether they work in the warehouse, the finance team or the executive suite. The stories are relatable.
Deeper, niche education for specific teams. Some audiences need more than awareness. I create focused content for:
- Marketing and digital marketing teams, where tracking, profiling and consent decisions are made every day
- DPOs, privacy champions, data protection ambassadors - whatever you call them in your organisation
- Dedicated data protection teams who want to sharpen their knowledge, rethink how they engage the business, or plan the year ahead
A privacy champion who can tell the story behind a rule is far more persuasive than one who can only quote the article number.
From a single presentation to an interactive programme #
What I create depends on what fits your organisation, your culture and your internal platforms. It can be:
A presentation with a speaker, delivered live in person or virtually, built around stories and strong visuals rather than bullet points.
Content for your own internal systems, including interactive exercises, quizzes, games and scenario-based activities your employees can work through at their own pace.
A mix of both, such as a live session on Data Protection Day followed by self-paced activities across the week or the month.
Everything is designed to be relevant to your organisation and its sector. It’s important that your employees can apply the new knowledge in their own job context.
Start planning now #
Data Protection Day 2027 falls on a Thursday. That sounds a long way off, but good content takes time, and November and December are when internal calendars fill up and approval processes slow down. The organisations that get the most from 28 January are the ones that start the conversation in the autumn.
If you would like to make this year’s Data Protection Day the one your employees actually remember, now is the time to talk.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you would like to discuss what this means for your organisation, book a call or explore our services.





