Skip to main content

GDPR: what is your Data Protection Strategy?

Originally published on LinkedIn in May 2017, as the fifth in a series on running a GDPR project. The previous posts covered GDPR project considerations, the Visual Privacy Program Game Plan, breaking a GDPR project into deliverables, and managing regulatory uncertainty.


A signpost with multiple GDPR signs pointing in different directions, with a confused figure standing beneath them

I’m not a gambling man, but I imagine my money would be safe if I were to bet that many organisations will not be compliant with the GDPR when it becomes enforced on 25 May 2018.

A vintage black and white photograph of a bookmaker’s stand — a metaphor for the odds facing organisations approaching GDPR compliance

You and your colleagues may be struggling to understand what “GDPR compliant” looks like, or what the definition of “done” is in terms of a programme to address the GDPR. Despite reading the regulation itself, monitoring news and developments published by your local DPA, and following the articles and comments of knowledgeable privacy professionals, you will not find a definitive answer. An organisation’s Privacy Programme is an ongoing endeavour — in the context of GDPR, 25 May 2018 should be viewed as a milestone rather than a finish date.

For most organisations it is not an option to wait in the hope that an answer suddenly appears. Your organisation needs to begin drafting a Data Protection Strategy that will set out its stall as far as addressing the GDPR is concerned. This document should be a very early deliverable in your programme or project. Without it, like any other form of direction, you will ultimately find yourself up that famous creek without a paddle.

What shapes your Data Protection Strategy? #

The Data Protection Strategy for your organisation depends upon a number of factors, including (in no particular order): the size and nature of your business, business model (B2B, B2C, C2C), market sector, categories of data subjects, the data you are processing, the volume of that data, your competitors, business risk, the level of dependency on the processing of personal data, jurisdictions, other compliance requirements, business strategy, number of employees, and available resources — to name a few.

Involve the right stakeholders #

An effective Data Protection Strategy needs to be crafted with the involvement of a wide group of stakeholders. Your legal department may insist on following the letter of the law, which could be at odds with the CFO who may only want to fund “a minimum level of compliance”. Colleagues within your business may see opportunities to enhance brand image or differentiate products and services. A strong emphasis from the CIO or CTO towards technology may fail to acknowledge the critical element of people and cultural change — not a wise strategy when so many data breaches are triggered by humans (poorly trained employees, or those with the wrong mindset, are sometimes your biggest risk).

A workshop diagram showing the wide range of stakeholders involved in a Data Protection Strategy: Marketing, Legal, Procurement, PR, Information Security, Audit, HR, Compliance and ethics, Finance, lines of business, M&A, IT development, and IT operations

Agreeing an approach that is right for your organisation may result in the Data Protection Strategy being compliance-based, ethics-based, risk-based, or a combination of the three. If you don’t involve the right stakeholders, or the project is anchored in the wrong place in your organisation, you could needlessly be too focused on compliance — or missing business opportunities.

Three strategic approaches #

A risk-based strategy could acknowledge that your organisation accepts that come 25 May 2018, there will be gaps. However, by demonstrating that you have documented your strategy, have a plan, are making progress, closing gaps, addressing risks, and have established sufficient policies, procedures, and embedded roles and responsibilities to govern data protection beyond May 2018 — a DPA could conclude that your organisation has a strong intention to take the GDPR seriously and is in control. This is where the words “appropriate” and “adequate” come into play: although there are many hard requirements within the GDPR, there are also many areas where one could reasonably conclude “it depends”.

An ethics-based strategy could be perceived as focusing on an individual’s “right to privacy”. In their excellent book Data Ethics: the new competitive advantage, authors Gry Hasselbalch and Pernille Tranberg detail a number of cases where organisations have taken a strong ethics-based stance. One of my favourite examples is LEGO, which has placed the protection of children’s data at the heart of its online universes — recognising the uncertainty of integrating with social media, taking strong corporate responsibility regarding the use of customer data by suppliers and partners, and applying no third-party cookies on websites aimed at under-13s.

Hand-drawn cartoon with the LEGO logo and the caption “LEGO is a good egg!” — illustrating the ethics-based approach to data protection

An ethics-based strategy may require your organisation to do more than is strictly required by the GDPR — and therefore be potentially more costly — but the benefits are worthwhile.

A compliance-based strategy focuses on meeting the letter of the law. On its own, this is rarely sufficient, but it may be the starting point for organisations that have not yet begun their GDPR journey.

How to produce your Data Protection Strategy #

Producing a Data Protection Strategy need not be a difficult task. A starting point is to assemble key stakeholders in one or more facilitated workshops and agree on the key strategy elements: the current state of data protection in your organisation, key areas that require addressing, priorities, targets for May 2018 and beyond, measurements, relevant existing projects, and new initiatives needed. Many inputs to the strategy — especially elements from the as-is analysis — are typically delivered as part of a pre-analysis phase of a privacy programme.

A useful way to summarise the strategy is a one-pager, such as CEB’s “Strategy on a Page” format, resulting in a document that is simple to grasp and easy to communicate across your organisation. The one-pager is, of course, a summary of a larger document containing the detail.

Example Data Protection Strategy one-pager showing statement of strategy, key metrics, initiatives, key assumptions, and data protection targets for May 2018

What comes next #

With a Data Protection Strategy agreed and approved, it can be used to shape a GDPR Deliverables Roadmap, develop a first-cut schedule, and begin moving forward in your project or programme in the direction appropriate to your organisation. Your organisation will also be able to align suitable investment strategies for the technologies needed to support the strategy — and therefore effectively screen and reject unsuitable tools plied by vendors.

Does your organisation have a strategy for data protection? If so, what is your approach?

Frequently Asked Questions #

What is a Data Protection Strategy? A Data Protection Strategy is a document that sets out how an organisation intends to address data protection requirements, including the GDPR. It defines the strategic approach — compliance-based, risk-based, or ethics-based — and shapes the programme of work, deliverables, and investment decisions that follow.

Should a Data Protection Strategy be compliance-based, risk-based, or ethics-based? Most organisations will adopt a combination of the three. A risk-based approach acknowledges gaps and demonstrates intent and progress. An ethics-based approach goes beyond legal compliance to place privacy at the heart of the organisation’s values. A compliance-based approach focuses on meeting specific legal requirements. The right blend depends on your organisation’s size, sector, risk appetite, and business model.

When should a Data Protection Strategy be produced? It should be one of the very first deliverables in any GDPR or privacy programme — before detailed planning begins. Without a strategy, your programme lacks direction, and you risk investing effort in the wrong areas or failing to secure appropriate leadership buy-in and funding.


I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts