GDPR project considerations
Originally published on LinkedIn in December 2016, ahead of the GDPR coming into force in May 2018. The project management principles here hold for any company running a compliance programme.

For organisations yet to start their GDPR projects, or unsure where to begin, these year-end reflections may be of interest. The key decisions — who owns the project, what you are trying to achieve, and what “done” actually looks like — are worth settling early.
How compliant are you now? #
Before embarking on a GDPR journey, a fundamental question organisations should ask is how compliant they are with existing data protection legislation — the Data Protection Directive, the e-Privacy Directive, local data protection legislation — and how they are able to demonstrate this.
For organisations in regulated sectors, the GDPR may “just” require strengthening existing compliance regimes. Remembering that security can exist without privacy but privacy requires security, those organisations may need to address the more legal aspects of GDPR and ensure they can demonstrate compliance. For others, the journey will be considerably more of a mountain to climb.

The GDPR means a degree of change for most organisations across processes (new ways of working), organisation (new or updated roles and responsibilities, organisational structures), technology (changes to applications, infrastructure), and information and documentation (new or updated policies, contracts, data processor agreements, privacy notices).
Who is managing your GDPR project? #
In most cases a formal project must be established to manage the change. This may sound obvious, but many companies fail to acknowledge this — instead handing the responsibility to a functional manager who is expected to lead the work and somehow fit everything in between their own and their colleagues’ existing tasks.
A formal project requires professional project management with appropriate resources assigned to produce specific deliverables that will result in the required business outcomes to ensure ongoing GDPR compliance. All deliverables must ideally be linked to specific GDPR requirements and/or internal requirements.

Project ownership and stakeholder dynamics #
A GDPR project involves tight expectation management of a highly diverse range of internal and external stakeholders and requires some deep digging into an organisation’s way of working.
Where to anchor project ownership and responsibility depends upon the nature of the business and the GDPR’s impact on it. Anchoring could be within Legal, IT, Finance, Information Security, HR, Procurement, Compliance, or within a line of business — to name a few examples I encountered whilst discussing GDPR projects with organisations across Denmark. In some cases the ownership had already been passed around like a hot potato. Strong project management is needed to manage and operate within the dynamics of these stakeholders.

Just another compliance project #
In many ways, a GDPR project is “just another compliance project” in the sense that the main work can be split into four key blocks:
- Understand your baseline — identify the gaps and risks between the current state (as-is) and the required target state (to-be)
- Close the gaps and treat the risks
- Define and implement the appropriate level of governance within the project and, most importantly, in the “business as usual” (BaU) environment post-project
- Get the right mindset and responsibilities among your people — education, training, executive coaching
The human side of GDPR #
You will fail if you neglect any of the above. Many of the breaches reported on an almost weekly basis are triggered by human behaviour, which means the fourth point should not be taken lightly — and certainly not de-scoped if funding becomes an issue.
Senior management will need to understand the value of the data that fuels their business and that investment is required to protect it — not just from a GDPR perspective — and to seed further business enablement. It is sometimes worth taking a reality check about your own organisation’s data security (or luck). Next time you read about a data breach, give an honest answer to this question:
“Could this have been us?”

Ensuring ongoing compliance #
Much of the work carried out during the life of a GDPR project will need to be maintained once the project is closed. It is not a one-time task. Accountabilities and responsibilities will need to be embedded in the organisation before the project closes.
The GDPR project needs to kick-start a Data Protection Management Life-Cycle — the motor — to ensure ongoing compliance. It needs to be designed, built, and tested to meet GDPR and organisational requirements, and will require regular oiling and tinkering to ensure it maintains performance and compliance expectations.

What does “Done” look like? #
When is the project complete? This may be challenging to define, especially for organisations that want to do things on the cheap. “Done” must be articulated to ensure compliance risk is tracked throughout the project and residual risks are smoothly transitioned into BaU.
With the amount of work ahead, it may be permissible to define “Done” on the fly rather than up front in your project initiation document — but every day you avoid starting the obvious must-do work of digging into your baseline (as-is) increases your organisation’s risk of non-compliance.
Frequently Asked Questions #
What is a GDPR project? A GDPR project is a formally managed programme of work to assess an organisation’s current data protection practices, close compliance gaps, and establish the governance needed to maintain ongoing compliance. It covers processes, technology, people, and documentation.
Who should own the GDPR project in an organisation? There is no single right answer — ownership could sit in Legal, IT, HR, Compliance, Information Security, or a line of business, depending on the nature of the organisation. What matters is that ownership is clearly defined, formally resourced, and not left to a functional manager to absorb on top of existing responsibilities.
How do you know when a GDPR project is complete? “Done” should be defined at the outset as part of your project initiation. At a minimum, the project is complete when all identified gaps have been closed or accepted, governance responsibilities have been embedded in the business-as-usual environment, and residual risks have been formally transitioned to the appropriate owners.
I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.





