Skip to main content

GDPR: managing assessment tasks and teams

Originally published on LinkedIn, August 2017. Please note that the choice of tools mentioned in the article is out-dated and reflects the time back then. The market for online tools has increased substantially in recent years.

Illustration of two figures coordinating colourful task cards — representing visual task management in a GDPR assessment team

There is no silver bullet GDPR tool. Organisations searching for a single platform that handles every requirement will be searching for a long time. What matters more is how you manage assessment work and teams — and in many cases, tools you already have can take you further than you think.

The reality of GDPR tooling #

A common question in organisations concerns “GDPR tools”, often in the hope that something exists that will support a multitude of requirements. Such a tool does not exist and probably never will, though some jack-of-all-trades-but-master-of-none tools may emerge. The “privacy management tools” category is very broad — the IAPP’s Tech Vendor Report provides a good overview, plenty of insights, and a useful categorisation scheme.

To support the initial gap and risk assessment in a GDPR programme and to get started, many organisations make do with existing tools — typically Office tools such as Excel, Visio, PowerPoint, and SharePoint — at least until they have conducted an RFP process and sourced appropriate tools matching their requirements.

SharePoint as a starting point #

For many years I have been a fan of SharePoint and have had experience building project and programme site templates that support collaboration and productivity. In the three GDPR programmes I had managed at the time of writing, I always initially established a basic Repository of Processing Activities in SharePoint to support Article 30. However, with SharePoint’s limitations such a setup is only sufficient for the short term or suitable for small organisations — short term meaning while you look for a more robust solution.

Assessment task management #

Many organisations turn to traditional scheduling software to manage their assessment tasks — MS Project, Excel, and so on. Note: tasks here means work, not the actual assessment content such as questionnaires.

With Microsoft Office 365, many organisations miss an opportunity by not fully using the tools already within their licence. One worth exploring is Planner.

Screenshot of the Office 365 application launcher with Planner highlighted

What is Planner? #

Planner is a visual task management tool that is easy to use in small teams and is well suited to assessment teams in GDPR and data protection initiatives. If you are familiar with Kanban or Scrum boards, you will feel at home with it.

Comparison showing a traditional MS Project and SharePoint task list on the left versus Planner’s visual board on the right

I use Planner in parallel with a physical board to support stand-up meetings and the energy and focus that physical boards bring. This also avoids the usual technical hitches of dragging and dropping, scrolling, and everyone getting distracted during the meeting.

Side-by-side comparison of a physical sticky-note Kanban board and the equivalent online Planner board

Planner provides useful reports across multiple plans, personalisation, and the ability to empower team members to update their own tasks without the PM becoming a bottleneck. Reports can easily be embedded in Steering Committee material. Planner also integrates with other Office 365 collaboration tools — Groups, Teams, and so on.

Screenshot of the Planner dashboard showing multiple GDPR assessment plans with task counts and completion status

Planner can support one assessment team or multiple assessment teams across an enterprise, though the latter will require some consolidation to produce enterprise-level status reporting.

Assessment deliverables #

An assessment is planned per processing activity, and a processing activity may cover one or more purposes — see my earlier article on why purpose is a great starting point for more on this.

As a minimum, the assessments in my projects generate the following deliverables:

Diagram showing GDPR assessment deliverables: assessment scope, stakeholder list, data flows per purpose, legal questionnaire, IS questionnaire, Article 30 register, gaps and risks, and assessment report

Typically an assessment team runs two or three assessments in parallel, with deliverables in various stages of completion. Within Planner, each deliverable is scheduled with the tasks needed to complete it and the resources required. Team members have a personalised view of their tasks across parallel assessments and can update progress independently. Tasks can be enriched with images, embedded documents, and links, and collaboration is supported by messaging at task level with message history.

Illustration of a minimal assessment team: workshop facilitator/business analyst, legal SME (privacy lawyer), and information security SME

As a minimum, an assessment team should contain key competences covering facilitation and interviewing, business analysis, legal data protection, and information security. Team size will vary depending on the scale or complexity of the processing activity. Additional support is needed to collate information from the people in the organisation responsible for managing data across the lifecycle — typically those responsible for business processes, business applications, and IT infrastructure.

Planner in the bigger scheme of things #

Planner sits at the operational level — it manages the work at the coal face:

Diagram showing how Planner fits into the bigger picture: Data Protection Strategy at the top, feeding a Deliverables Roadmap, with Planner managing the tasks needed to complete deliverables, alongside Deliverable Descriptions

It is simple, easy to use, and visual. There are of course many approaches to managing this kind of work — this is the one I have found most beneficial in practice.

Frequently Asked Questions #

What should every GDPR assessment produce as a minimum? At minimum, each assessment should produce: an assessment scope covering business applications and IT infrastructure, a stakeholder list, data flows per purpose, a legal questionnaire and an information security questionnaire, an Article 30 register entry, a gaps and risks log, and an assessment report. The assessment is planned at the level of the processing activity, not the business process.

What competences does a GDPR assessment team need? As a minimum: a facilitator or business analyst to run interviews and workshops, a data protection legal SME, and an information security SME. Additional resource is needed from those in the organisation who are responsible for the relevant business processes, applications, and IT infrastructure.

Should I use specialist GDPR software or standard Office tools? For the initial phase, standard Office tools — SharePoint, Excel, Planner — are often sufficient and have the advantage of being already available and familiar. They are a pragmatic starting point while you run an RFP process to select purpose-built privacy management software that matches your specific requirements. Do not wait for the perfect tool before starting the work.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts