Skip to main content

GDPR project considerations

Originally published on LinkedIn in December 2016, ahead of the GDPR coming into force in May 2018. The project management principles here hold for any company running a compliance programme.


The average GDPR project - lots of tasks, stakeholders and meetings

For organisations yet to start their GDPR projects, or unsure where to begin, these year-end reflections may be of interest. The key decisions — who owns the project, what you are trying to achieve, and what “done” actually looks like — are worth settling early.

How compliant are you now? #

Before embarking on a GDPR journey, a fundamental question organisations should ask is how compliant they are with existing data protection legislation — the Data Protection Directive, the e-Privacy Directive, local data protection legislation — and how they are able to demonstrate this.

For organisations in regulated sectors, the GDPR may “just” require strengthening existing compliance regimes. Remembering that security can exist without privacy but privacy requires security, those organisations may need to address the more legal aspects of GDPR and ensure they can demonstrate compliance. For others, the journey will be considerably more of a mountain to climb.

GDPR – a bit extra on top of an existing regime?

The GDPR means a degree of change for most organisations across processes (new ways of working), organisation (new or updated roles and responsibilities, organisational structures), technology (changes to applications, infrastructure), and information and documentation (new or updated policies, contracts, data processor agreements, privacy notices).

Who is managing your GDPR project? #

In most cases a formal project must be established to manage the change. This may sound obvious, but many companies fail to acknowledge this — instead handing the responsibility to a functional manager who is expected to lead the work and somehow fit everything in between their own and their colleagues’ existing tasks.

A formal project requires professional project management with appropriate resources assigned to produce specific deliverables that will result in the required business outcomes to ensure ongoing GDPR compliance. All deliverables must ideally be linked to specific GDPR requirements and/or internal requirements.

GDPR requirement and internal requirement both feed into the appointment of a DPO

Project ownership and stakeholder dynamics #

A GDPR project involves tight expectation management of a highly diverse range of internal and external stakeholders and requires some deep digging into an organisation’s way of working.

Where to anchor project ownership and responsibility depends upon the nature of the business and the GDPR’s impact on it. Anchoring could be within Legal, IT, Finance, Information Security, HR, Procurement, Compliance, or within a line of business — to name a few examples I encountered whilst discussing GDPR projects with organisations across Denmark. In some cases the ownership had already been passed around like a hot potato. Strong project management is needed to manage and operate within the dynamics of these stakeholders.

Stakeholder map showing Finance, IT, Legal, HR, Procurement, Info Security and Business all converging on the Project Manager

Just another compliance project #

In many ways, a GDPR project is “just another compliance project” in the sense that the main work can be split into four key blocks:

  1. Understand your baseline — identify the gaps and risks between the current state (as-is) and the required target state (to-be)
  2. Close the gaps and treat the risks
  3. Define and implement the appropriate level of governance within the project and, most importantly, in the “business as usual” (BaU) environment post-project
  4. Get the right mindset and responsibilities among your people — education, training, executive coaching

The human side of GDPR #

You will fail if you neglect any of the above. Many of the breaches reported on an almost weekly basis are triggered by human behaviour, which means the fourth point should not be taken lightly — and certainly not de-scoped if funding becomes an issue.

Senior management will need to understand the value of the data that fuels their business and that investment is required to protect it — not just from a GDPR perspective — and to seed further business enablement. It is sometimes worth taking a reality check about your own organisation’s data security (or luck). Next time you read about a data breach, give an honest answer to this question:

“Could this have been us?”

A collage of data breach news headlines

Ensuring ongoing compliance #

Much of the work carried out during the life of a GDPR project will need to be maintained once the project is closed. It is not a one-time task. Accountabilities and responsibilities will need to be embedded in the organisation before the project closes.

The GDPR project needs to kick-start a Data Protection Management Life-Cycle — the motor — to ensure ongoing compliance. It needs to be designed, built, and tested to meet GDPR and organisational requirements, and will require regular oiling and tinkering to ensure it maintains performance and compliance expectations.

Data Protection in BaU: circular lifecycle diagram showing Assess, Protect, Sustain and Respond

What does “Done” look like? #

When is the project complete? This may be challenging to define, especially for organisations that want to do things on the cheap. “Done” must be articulated to ensure compliance risk is tracked throughout the project and residual risks are smoothly transitioned into BaU.

With the amount of work ahead, it may be permissible to define “Done” on the fly rather than up front in your project initiation document — but every day you avoid starting the obvious must-do work of digging into your baseline (as-is) increases your organisation’s risk of non-compliance.

Frequently Asked Questions #

What is a GDPR project? A GDPR project is a formally managed programme of work to assess an organisation’s current data protection practices, close compliance gaps, and establish the governance needed to maintain ongoing compliance. It covers processes, technology, people, and documentation.

Who should own the GDPR project in an organisation? There is no single right answer — ownership could sit in Legal, IT, HR, Compliance, Information Security, or a line of business, depending on the nature of the organisation. What matters is that ownership is clearly defined, formally resourced, and not left to a functional manager to absorb on top of existing responsibilities.

How do you know when a GDPR project is complete? “Done” should be defined at the outset as part of your project initiation. At a minimum, the project is complete when all identified gaps have been closed or accepted, governance responsibilities have been embedded in the business-as-usual environment, and residual risks have been formally transitioned to the appropriate owners.


I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts