GDPR: what is your Data Protection Strategy?
Originally published on LinkedIn in May 2017, as the fifth in a series on running a GDPR project. The previous posts covered GDPR project considerations, the Visual Privacy Program Game Plan, breaking a GDPR project into deliverables, and managing regulatory uncertainty.

I’m not a gambling man, but I imagine my money would be safe if I were to bet that many organisations will not be compliant with the GDPR when it becomes enforced on 25 May 2018.

You and your colleagues may be struggling to understand what “GDPR compliant” looks like, or what the definition of “done” is in terms of a programme to address the GDPR. Despite reading the regulation itself, monitoring news and developments published by your local DPA, and following the articles and comments of knowledgeable privacy professionals, you will not find a definitive answer. An organisation’s Privacy Programme is an ongoing endeavour — in the context of GDPR, 25 May 2018 should be viewed as a milestone rather than a finish date.
For most organisations it is not an option to wait in the hope that an answer suddenly appears. Your organisation needs to begin drafting a Data Protection Strategy that will set out its stall as far as addressing the GDPR is concerned. This document should be a very early deliverable in your programme or project. Without it, like any other form of direction, you will ultimately find yourself up that famous creek without a paddle.
What shapes your Data Protection Strategy? #
The Data Protection Strategy for your organisation depends upon a number of factors, including (in no particular order): the size and nature of your business, business model (B2B, B2C, C2C), market sector, categories of data subjects, the data you are processing, the volume of that data, your competitors, business risk, the level of dependency on the processing of personal data, jurisdictions, other compliance requirements, business strategy, number of employees, and available resources — to name a few.
Involve the right stakeholders #
An effective Data Protection Strategy needs to be crafted with the involvement of a wide group of stakeholders. Your legal department may insist on following the letter of the law, which could be at odds with the CFO who may only want to fund “a minimum level of compliance”. Colleagues within your business may see opportunities to enhance brand image or differentiate products and services. A strong emphasis from the CIO or CTO towards technology may fail to acknowledge the critical element of people and cultural change — not a wise strategy when so many data breaches are triggered by humans (poorly trained employees, or those with the wrong mindset, are sometimes your biggest risk).

Agreeing an approach that is right for your organisation may result in the Data Protection Strategy being compliance-based, ethics-based, risk-based, or a combination of the three. If you don’t involve the right stakeholders, or the project is anchored in the wrong place in your organisation, you could needlessly be too focused on compliance — or missing business opportunities.
Three strategic approaches #
A risk-based strategy could acknowledge that your organisation accepts that come 25 May 2018, there will be gaps. However, by demonstrating that you have documented your strategy, have a plan, are making progress, closing gaps, addressing risks, and have established sufficient policies, procedures, and embedded roles and responsibilities to govern data protection beyond May 2018 — a DPA could conclude that your organisation has a strong intention to take the GDPR seriously and is in control. This is where the words “appropriate” and “adequate” come into play: although there are many hard requirements within the GDPR, there are also many areas where one could reasonably conclude “it depends”.
An ethics-based strategy could be perceived as focusing on an individual’s “right to privacy”. In their excellent book Data Ethics: the new competitive advantage, authors Gry Hasselbalch and Pernille Tranberg detail a number of cases where organisations have taken a strong ethics-based stance. One of my favourite examples is LEGO, which has placed the protection of children’s data at the heart of its online universes — recognising the uncertainty of integrating with social media, taking strong corporate responsibility regarding the use of customer data by suppliers and partners, and applying no third-party cookies on websites aimed at under-13s.

An ethics-based strategy may require your organisation to do more than is strictly required by the GDPR — and therefore be potentially more costly — but the benefits are worthwhile.
A compliance-based strategy focuses on meeting the letter of the law. On its own, this is rarely sufficient, but it may be the starting point for organisations that have not yet begun their GDPR journey.
How to produce your Data Protection Strategy #
Producing a Data Protection Strategy need not be a difficult task. A starting point is to assemble key stakeholders in one or more facilitated workshops and agree on the key strategy elements: the current state of data protection in your organisation, key areas that require addressing, priorities, targets for May 2018 and beyond, measurements, relevant existing projects, and new initiatives needed. Many inputs to the strategy — especially elements from the as-is analysis — are typically delivered as part of a pre-analysis phase of a privacy programme.
A useful way to summarise the strategy is a one-pager, such as CEB’s “Strategy on a Page” format, resulting in a document that is simple to grasp and easy to communicate across your organisation. The one-pager is, of course, a summary of a larger document containing the detail.

What comes next #
With a Data Protection Strategy agreed and approved, it can be used to shape a GDPR Deliverables Roadmap, develop a first-cut schedule, and begin moving forward in your project or programme in the direction appropriate to your organisation. Your organisation will also be able to align suitable investment strategies for the technologies needed to support the strategy — and therefore effectively screen and reject unsuitable tools plied by vendors.
Does your organisation have a strategy for data protection? If so, what is your approach?
Frequently Asked Questions #
What is a Data Protection Strategy? A Data Protection Strategy is a document that sets out how an organisation intends to address data protection requirements, including the GDPR. It defines the strategic approach — compliance-based, risk-based, or ethics-based — and shapes the programme of work, deliverables, and investment decisions that follow.
Should a Data Protection Strategy be compliance-based, risk-based, or ethics-based? Most organisations will adopt a combination of the three. A risk-based approach acknowledges gaps and demonstrates intent and progress. An ethics-based approach goes beyond legal compliance to place privacy at the heart of the organisation’s values. A compliance-based approach focuses on meeting specific legal requirements. The right blend depends on your organisation’s size, sector, risk appetite, and business model.
When should a Data Protection Strategy be produced? It should be one of the very first deliverables in any GDPR or privacy programme — before detailed planning begins. Without a strategy, your programme lacks direction, and you risk investing effort in the wrong areas or failing to secure appropriate leadership buy-in and funding.
I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.





