Skip to main content

Data Protection Strategy revisited

Originally published on LinkedIn, October 2018.

Illustration of a box of GDPR Plasters labelled “compliant” — satirising quick-fix approaches to data protection compliance

Six months after GDPR became enforceable, many organisations had already missed the point. The Regulation was not just about updating old legislation — it was about protecting the rights and freedoms of individuals and creating a transparent framework for the digital economy. Too many treated it as a project deadline rather than the beginning of something permanent.

Who got it right — and who didn’t #

First, let us acknowledge the many organisations that are in good shape and able to demonstrate compliance. They probably did not just work hard over the past couple of years — many built upon structures, controls, and a mindset they had in place for years, if not decades.

On the flip side, many organisations are still in trouble. After conversations with peers, conference attendance, and meetings across Europe, a pattern of common failure modes emerged:

  • Some viewed 25 May as a deadline and celebrated victory too early
  • Some did not appreciate that GDPR is not the only applicable data protection legislation and failed to understand how it intertwines with other laws and regulations
  • Some have not embedded sustainable governance and management systems
  • Many patched things up with “plasters” — treating symptoms rather than root causes
  • Absence of, or inadequate investment in, organisational change management
  • Many incorrectly saw Information Security standards such as ISO 27001 as their only saviour — but what does ISO 27001 say about key data protection principles such as Lawfulness, Fairness and Transparency, Purpose Limitation, or Data Minimisation?
  • Most have struggled with Data Protection by Design and by Default
  • Many failed to put a business case together for their programme and failed to develop a Data Protection Strategy

Most of the above points to a lack of accountability and poor tone from the top.

Three strategic approaches worth considering #

Illustration of a robot holding hands with three human figures, with a speech bubble saying “It’s great someone’s looking out for our rights and freedoms” — representing the ethics-based approach to data protection

Ethics-based #

Having attended the second Data Ethics Forum in Copenhagen, I came away inspired and returned to two excellent books: Data Ethics — the new competitive advantage by Pernille Tranberg and Gry Hasselbalch, and Ethical Data and Information Management by Katherine O’Keefe and Daragh O Brien. Both are worth reading if you want to identify business benefits beyond “risk reduction” and to process data in an ethical manner.

This is where organisations have most significantly missed the opportunity — the chance to align data protection with business strategy and other organisational objectives. For many, the CSR strategy could be a good starting point.

Illustration with handwritten text “Peace, love and Data Ethics” above hands cradling small figures representing people — the slogan borrowed from dataethics.eu

Slogan borrowed from dataethics.eu

Compliance-based #

This has sometimes been the default approach when the programme is anchored in the legal department. I recently came across a global market leader who saw a law degree — any kind — as a prerequisite to manage their global programme, because they believed GDPR to be primarily a legal issue. The lawyer they chose had never managed any kind of business change programme or project. At the other end of the scale, some organisations have gone for a minimum compliance approach.

Illustration of an empty executive desk with a “BOSS” nameplate and handwritten text “Do no more than the bare minimum!” — representing the compliance-minimalist mindset

Risk-based #

Followed by many, but unfortunately some organisations failed to grasp that it is primarily about the risks to the rights and freedoms of individuals — not risks to the organisation such as financial or reputational risk, or an excuse to avoid needed investment. Organisations have also struggled to understand privacy risk and how to integrate a privacy risk model with their Enterprise Risk Management framework.

Plasters — quick-fix controls deployed to treat symptoms — are a worthwhile response only if vigorous risk management is followed and the plaster is used as a temporary measure until a more robust response is implemented.

Illustration of three overlapping plasters — representing quick-fix GDPR controls that treat symptoms rather than root causes

The approaches to avoid #

Unfortunately, by not formulating their strategy, some organisations have by default taken other approaches:

Four-panel illustration showing The Ostrich approach, The Prayer approach, The Denial approach, and JFDI

The ostrich approach: ignoring risks or pretending they do not exist.

The prayer approach: looking to a higher being to solve all your problems or make them disappear.

The denial approach: recognising what risks may be relevant to your organisation, but refusing to accept they will materialise.

JFDI: just do something — not the right thing, not in the right way, not done well. The results tend to erode over time and things quickly return to the way they were before the programme started.

It is not too late #

With a wave of new legislation arriving globally, it is still not too late for any organisation to start developing their Data Protection Strategy and gear up for the future. The organisations that treat data protection as a strategic matter — not a one-time project — will be far better placed to navigate what comes next.

Frequently Asked Questions #

What is a Data Protection Strategy? A Data Protection Strategy is a documented, senior-management-endorsed approach to how an organisation will manage personal data in a way that is sustainable, accountable, and aligned with business objectives. It goes beyond legal compliance to address governance structures, organisational change, cultural embedding, and long-term risk management.

What is the difference between an ethics-based and a compliance-based approach to data protection? A compliance-based approach asks “what must we do to avoid a fine?” An ethics-based approach asks “what should we do to be worthy of people’s trust?” The compliance approach tends to produce minimum viable effort; the ethics approach tends to produce durable cultural change and can deliver genuine competitive advantage.

Why is ISO 27001 not enough for GDPR compliance? ISO 27001 is an information security standard focused primarily on confidentiality, integrity, and availability of information assets. It does not address several core data protection principles such as Lawfulness, Fairness and Transparency, Purpose Limitation, or Data Minimisation. Organisations that rely on ISO 27001 alone will have significant gaps in their GDPR compliance posture.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts