Data Protection Strategy revisited
Originally published on LinkedIn, October 2018.

Six months after GDPR became enforceable, many organisations had already missed the point. The Regulation was not just about updating old legislation — it was about protecting the rights and freedoms of individuals and creating a transparent framework for the digital economy. Too many treated it as a project deadline rather than the beginning of something permanent.
Who got it right — and who didn’t #
First, let us acknowledge the many organisations that are in good shape and able to demonstrate compliance. They probably did not just work hard over the past couple of years — many built upon structures, controls, and a mindset they had in place for years, if not decades.
On the flip side, many organisations are still in trouble. After conversations with peers, conference attendance, and meetings across Europe, a pattern of common failure modes emerged:
- Some viewed 25 May as a deadline and celebrated victory too early
- Some did not appreciate that GDPR is not the only applicable data protection legislation and failed to understand how it intertwines with other laws and regulations
- Some have not embedded sustainable governance and management systems
- Many patched things up with “plasters” — treating symptoms rather than root causes
- Absence of, or inadequate investment in, organisational change management
- Many incorrectly saw Information Security standards such as ISO 27001 as their only saviour — but what does ISO 27001 say about key data protection principles such as Lawfulness, Fairness and Transparency, Purpose Limitation, or Data Minimisation?
- Most have struggled with Data Protection by Design and by Default
- Many failed to put a business case together for their programme and failed to develop a Data Protection Strategy
Most of the above points to a lack of accountability and poor tone from the top.
Three strategic approaches worth considering #

Ethics-based #
Having attended the second Data Ethics Forum in Copenhagen, I came away inspired and returned to two excellent books: Data Ethics — the new competitive advantage by Pernille Tranberg and Gry Hasselbalch, and Ethical Data and Information Management by Katherine O’Keefe and Daragh O Brien. Both are worth reading if you want to identify business benefits beyond “risk reduction” and to process data in an ethical manner.
This is where organisations have most significantly missed the opportunity — the chance to align data protection with business strategy and other organisational objectives. For many, the CSR strategy could be a good starting point.

Slogan borrowed from dataethics.eu
Compliance-based #
This has sometimes been the default approach when the programme is anchored in the legal department. I recently came across a global market leader who saw a law degree — any kind — as a prerequisite to manage their global programme, because they believed GDPR to be primarily a legal issue. The lawyer they chose had never managed any kind of business change programme or project. At the other end of the scale, some organisations have gone for a minimum compliance approach.

Risk-based #
Followed by many, but unfortunately some organisations failed to grasp that it is primarily about the risks to the rights and freedoms of individuals — not risks to the organisation such as financial or reputational risk, or an excuse to avoid needed investment. Organisations have also struggled to understand privacy risk and how to integrate a privacy risk model with their Enterprise Risk Management framework.
Plasters — quick-fix controls deployed to treat symptoms — are a worthwhile response only if vigorous risk management is followed and the plaster is used as a temporary measure until a more robust response is implemented.

The approaches to avoid #
Unfortunately, by not formulating their strategy, some organisations have by default taken other approaches:

The ostrich approach: ignoring risks or pretending they do not exist.
The prayer approach: looking to a higher being to solve all your problems or make them disappear.
The denial approach: recognising what risks may be relevant to your organisation, but refusing to accept they will materialise.
JFDI: just do something — not the right thing, not in the right way, not done well. The results tend to erode over time and things quickly return to the way they were before the programme started.
It is not too late #
With a wave of new legislation arriving globally, it is still not too late for any organisation to start developing their Data Protection Strategy and gear up for the future. The organisations that treat data protection as a strategic matter — not a one-time project — will be far better placed to navigate what comes next.
Frequently Asked Questions #
What is a Data Protection Strategy? A Data Protection Strategy is a documented, senior-management-endorsed approach to how an organisation will manage personal data in a way that is sustainable, accountable, and aligned with business objectives. It goes beyond legal compliance to address governance structures, organisational change, cultural embedding, and long-term risk management.
What is the difference between an ethics-based and a compliance-based approach to data protection? A compliance-based approach asks “what must we do to avoid a fine?” An ethics-based approach asks “what should we do to be worthy of people’s trust?” The compliance approach tends to produce minimum viable effort; the ethics approach tends to produce durable cultural change and can deliver genuine competitive advantage.
Why is ISO 27001 not enough for GDPR compliance? ISO 27001 is an information security standard focused primarily on confidentiality, integrity, and availability of information assets. It does not address several core data protection principles such as Lawfulness, Fairness and Transparency, Purpose Limitation, or Data Minimisation. Organisations that rely on ISO 27001 alone will have significant gaps in their GDPR compliance posture.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





