Get Traction in Your Privacy Programme by Understanding Culture and Sub-Cultures
Originally published on LinkedIn, November 2019.
Getting traction in a privacy programme — making it effective at actually driving down data protection risk - is not primarily about the technology you deploy, the policies and procedures you implement, the number of people in your team, or the size of your budget. It often comes from something less tangible: tuning into the culture and sub-cultures of your organisation. This matters especially in the B2C sector, where the gap between the privacy team and the rest of the business can be wide.
Stop Leading with Article Numbers #
From experience working with large global companies, the less you mention GDPR jargon and quote article numbers when engaging with teams, the better. This applies across the board - but it applies most of all to leadership and senior management.

Occasionally there is an opportunity to observe presentations from larger consultancy firms. The ones that fail to land tend to share a common characteristic: they are generic, peppered with “article this” and “recital that,” and not tailored to the individuals or the company in front of them. In some cases they are visibly copy-pasted from an earlier client engagement.
Article numbers and recitals sound impressive. They can also signal credibility within the data protection profession. But for most of the people you need to bring along — managers, team leads, marketing colleagues, finance directors — they are triggers to switch off. They signal that what follows is a legal lecture rather than a conversation about how the organisation actually works.
Quoting them will not create resonance with a leadership team. It certainly will not help with managers and their teams. Generic is generic.
Tuning into Culture and Sub-Cultures #
To get traction you need to reach people’s hearts and minds. You do that by digging deeper — understanding the sub-cultures that exist within your organisation, not just the headline culture.
You can often sense the corporate culture as soon as you walk into a building. The way the reception is designed. Whether people are wearing lanyards. Whether the space feels open or closed. Whether people look up when you walk in or stay heads-down. You can also simply ask one or two employees directly — people are often candid about what their department is like when asked in the right way.
What you are likely to find is that significant variation exists between departments. HR, Marketing, Finance, and the various lines of business do not all operate the same way, even within the same organisation. In some cases, genuinely distinct sub-cultures exist — each requiring its own approach if you want to communicate and collaborate effectively.

You can observe the variance by paying attention to people and their surroundings:
- Beards and t-shirts versus suits, ties, and clean-cut presentation?
- An abundance of tattoos?
- Sneakers versus formal shoes?
- Dark wood furniture verging on antique, versus open-plan functional tech-company aesthetics?
- Photos on desks — cats or kids?
The choices people make in their appearance, how they arrange their workspace, the objects they keep on their desks — these often reveal something about their interests, motivations, and the way they like to work.
To be clear: this is not a suggestion to mirror how people dress when you meet them. It is an observation that these signals can tell you something useful about what will resonate, and what will not.
What’s in it for Me? #
You will often hear the phrase “what’s in it for me?” from people who are being asked to change how they work. Unless you have tuned into the sub-cultures you are working with, you will struggle to answer that question in terms that land.

Consider what is involved in explaining to a marketing team how GDPR intersects with the ePrivacy Directive (the EU law governing electronic communications, cookies, and direct marketing) and applicable local marketing legislation. That is a genuinely complex set of overlapping obligations. Presenting it in regulatory language, with article references and recital citations, will not help your marketing colleagues understand what they need to do differently. You need to enter their world — their language, their tone, their priorities — rather than expecting them to translate from yours.
The same principle applies across every department. A conversation with Finance about data retention should feel different from a conversation with IT about data minimisation by design. A briefing for the HR team about employee data handling should feel different from a session with the commercial team about customer consent.
Getting Resonance #
The goal is resonance — a message that connects with where people actually are, rather than where you think they should be.
This sounds obvious. Many companies are not doing it. Data protection programmes that rely on compliance mandates and regulatory language to drive behaviour change tend to produce surface-level compliance at best. Policies get acknowledged, training modules get clicked through, and behaviour stays broadly the same.
Programmes that invest time in understanding the cultures and sub-cultures they are working within — and that adapt their communication accordingly — tend to go further. They produce genuine shifts in how people think about data, not just whether they have ticked the right boxes.
The investment required is not primarily financial. It is time, curiosity, and a willingness to lead with the question “what matters to this group?” rather than “what does the regulation require of them?”
Frequently Asked Questions #
Why does quoting GDPR article numbers put people off? For most people outside the legal and privacy profession, regulatory references signal complexity, obligation, and risk — none of which are motivating. They also signal that the person presenting has not translated the regulation into terms that are relevant to the audience in front of them. A marketing manager does not need to know the number of the article that governs consent; they need to understand what consent means for their next campaign and what they need to do differently.
How do I identify the sub-cultures in my organisation? Start by spending time in different departments before you present to them. Walk the floor if you can. Have informal conversations. Look at how spaces are arranged and how people interact. Ask a trusted contact in each team what their department cares about most, what frustrates them, and how they prefer to receive information. None of this needs to be formal — the goal is to arrive in the room with a working model of who you are talking to, not a blank slate.
How do I adapt my privacy communications for different departments without losing consistency? The underlying message and the obligations remain constant — what changes is the framing, the examples, and the language. A consistent privacy programme can express the same requirements in terms of customer trust for the commercial team, process efficiency for operations, risk reduction for finance, and technical implementation for IT. The regulation is the same; the resonance depends on how you translate it for each audience.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





