Skip to main content

GDPR: assembling a team of competent individuals

Originally published on LinkedIn, July 2017.

Cartoon showing people asking “Is it a bird? Is it a plane? No! It’s a GDPR Expert!!” — illustrating the debate around GDPR expertise

The debate about whether “GDPR experts” exist has generated a lot of heat. But it is largely the wrong debate. What organisations actually need for a successful GDPR programme is not a team of experts — it is a team assembled around the right competences. The distinction matters, and getting it wrong is expensive.

It’s all about competences #

There has been some interesting discussion in GDPR circles that divides opinion and, in some cases, makes blood boil. “Do GDPR experts exist?” is one theme in particular. It reminded me of the Monty Python sketch “Bicycle Repairman” — where in a world full of supermen, the revered expert is simply a person who can repair bikes.

I have personally not met anyone who openly pitches themselves as a “GDPR expert”. There are people in my network who, knowing their background, their competences, and their positions in various political and trade organisations, might warrant that label — but only in the context of their specific set of competences.

In the projects I have managed I have rarely needed to assemble a team of experts, unless it is a mission-critical endeavour. I am generally more interested in assembling a team containing the right competences to complete the job. One of the critical early tasks in any project is to establish the project organisation — identifying, agreeing, and documenting the needed roles and responsibilities. Training the team in the disciplines and techniques that will be used during the project is also essential. Collectively, the team will provide the expertise.

A team of experts is also normally expensive.

An opportunity to learn #

GDPR is complex and takes some organisations into uncharted territory, but it builds upon existing data protection legislation based on principles going back decades. It is not all totally new. There are therefore significant opportunities to apply existing knowledge, learn new things, share them, and build expertise along the way.

The key is to select the right course and the right certification scheme. Some organisations have jumped on the bandwagon by offering certification for a single day of education — it was not that long ago that a foundation class was normally three days long. There are also organisations that have established their own certification schemes, which is a bit like printing your own currency.

Professional project and programme management #

Project management is a profession, and GDPR is a perfect showcase of why professional project management matters — so the choice of project manager is critical. The PM needs to plan, estimate, manage stakeholders, manage assumptions, risks and issues, monitor and report progress, and lead and orchestrate the team.

“Assumptions management” deserves a particular mention here. In the context of a GDPR project, where clarification and guidance from your own supervisory authority and the Article 29 Working Party has often been slow and drawn out, managing assumptions carefully is essential. I explored this in more detail in an earlier article on managing the uncertainty of interpreting GDPR requirements.

Ideally the PM will have a background in managing projects and programmes associated with compliance, governance, policy implementation, security, or process implementation. The PM also requires the support of a strong Steering Committee with senior executive representation to direct, advise, approve, support, and help remove obstacles.

Illustration of a project manager conducting a team — representing the PM role in orchestrating a GDPR programme

Project or programme? #

So far I have written in the context of a project. There has also been fair discussion about whether GDPR requires a programme rather than a project — which reminds me of the band discussion in the Bad News episode of The Comic Strip Presents: “Are we Heavy Metal or part of the New Romantics?”

Ideally a project environment would be established to manage the initial as-is assessment. Depending on the organisation and the scale of change needed to reach the target state, a programme may then be initiated to coordinate the number of identified change initiatives and projects needed over the years ahead.

A programme, in MSP terms at least, is a group of related projects managed in a coordinated way to obtain benefits not available from managing the projects individually. The right answer depends on your strategic objectives, existing maturity, ambition, organisational size, funding, nature of business, and risk exposure.

These questions should be addressed as part of your organisation’s Data Protection Strategy — a key and early deliverable in any serious compliance effort.

Frequently Asked Questions #

Do you need GDPR experts to run a GDPR programme? Not necessarily. What you need is a team with the right combination of competences — legal, technical, project management, and change management. Collectively the team provides the expertise. Assembling a team of individually credentialled “experts” is often both impractical and expensive.

What makes a good project manager for a GDPR programme? A PM with a background in compliance, governance, security, or policy implementation is well suited. Beyond technical knowledge, the PM needs to manage stakeholders, handle assumptions carefully in the face of regulatory uncertainty, report progress clearly, and lead a cross-functional team. Strong Steering Committee support is equally important.

Should GDPR be run as a project or a programme? It depends on the organisation. A project works well for the initial as-is assessment and scoping. If the gap analysis reveals significant change across multiple workstreams, a programme structure — coordinating several related projects — is more appropriate. The right answer should come out of your Data Protection Strategy, not be assumed upfront.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts