Skip to main content

Get Traction in Your Privacy Programme by Understanding Culture and Sub-Cultures

Originally published on LinkedIn, November 2019.

Getting traction in a privacy programme — making it effective at actually driving down data protection risk - is not primarily about the technology you deploy, the policies and procedures you implement, the number of people in your team, or the size of your budget. It often comes from something less tangible: tuning into the culture and sub-cultures of your organisation. This matters especially in the B2C sector, where the gap between the privacy team and the rest of the business can be wide.

Stop Leading with Article Numbers #

From experience working with large global companies, the less you mention GDPR jargon and quote article numbers when engaging with teams, the better. This applies across the board - but it applies most of all to leadership and senior management.

Illustration of high heels and trainers side by side, representing contrasting workplace cultures

Occasionally there is an opportunity to observe presentations from larger consultancy firms. The ones that fail to land tend to share a common characteristic: they are generic, peppered with “article this” and “recital that,” and not tailored to the individuals or the company in front of them. In some cases they are visibly copy-pasted from an earlier client engagement.

Article numbers and recitals sound impressive. They can also signal credibility within the data protection profession. But for most of the people you need to bring along — managers, team leads, marketing colleagues, finance directors — they are triggers to switch off. They signal that what follows is a legal lecture rather than a conversation about how the organisation actually works.

Quoting them will not create resonance with a leadership team. It certainly will not help with managers and their teams. Generic is generic.

Tuning into Culture and Sub-Cultures #

To get traction you need to reach people’s hearts and minds. You do that by digging deeper — understanding the sub-cultures that exist within your organisation, not just the headline culture.

You can often sense the corporate culture as soon as you walk into a building. The way the reception is designed. Whether people are wearing lanyards. Whether the space feels open or closed. Whether people look up when you walk in or stay heads-down. You can also simply ask one or two employees directly — people are often candid about what their department is like when asked in the right way.

What you are likely to find is that significant variation exists between departments. HR, Marketing, Finance, and the various lines of business do not all operate the same way, even within the same organisation. In some cases, genuinely distinct sub-cultures exist — each requiring its own approach if you want to communicate and collaborate effectively.

Illustration of a bearded person in casual clothing, a person in a t-shirt, and a person in a suit and tie, representing different workplace sub-cultures

You can observe the variance by paying attention to people and their surroundings:

  • Beards and t-shirts versus suits, ties, and clean-cut presentation?
  • An abundance of tattoos?
  • Sneakers versus formal shoes?
  • Dark wood furniture verging on antique, versus open-plan functional tech-company aesthetics?
  • Photos on desks — cats or kids?

The choices people make in their appearance, how they arrange their workspace, the objects they keep on their desks — these often reveal something about their interests, motivations, and the way they like to work.

To be clear: this is not a suggestion to mirror how people dress when you meet them. It is an observation that these signals can tell you something useful about what will resonate, and what will not.

What’s in it for Me? #

You will often hear the phrase “what’s in it for me?” from people who are being asked to change how they work. Unless you have tuned into the sub-cultures you are working with, you will struggle to answer that question in terms that land.

Illustration of hands with a watch and rings, representing detail and personal expression

Consider what is involved in explaining to a marketing team how GDPR intersects with the ePrivacy Directive (the EU law governing electronic communications, cookies, and direct marketing) and applicable local marketing legislation. That is a genuinely complex set of overlapping obligations. Presenting it in regulatory language, with article references and recital citations, will not help your marketing colleagues understand what they need to do differently. You need to enter their world — their language, their tone, their priorities — rather than expecting them to translate from yours.

The same principle applies across every department. A conversation with Finance about data retention should feel different from a conversation with IT about data minimisation by design. A briefing for the HR team about employee data handling should feel different from a session with the commercial team about customer consent.

Getting Resonance #

The goal is resonance — a message that connects with where people actually are, rather than where you think they should be.

This sounds obvious. Many companies are not doing it. Data protection programmes that rely on compliance mandates and regulatory language to drive behaviour change tend to produce surface-level compliance at best. Policies get acknowledged, training modules get clicked through, and behaviour stays broadly the same.

Programmes that invest time in understanding the cultures and sub-cultures they are working within — and that adapt their communication accordingly — tend to go further. They produce genuine shifts in how people think about data, not just whether they have ticked the right boxes.

The investment required is not primarily financial. It is time, curiosity, and a willingness to lead with the question “what matters to this group?” rather than “what does the regulation require of them?”

Frequently Asked Questions #

Why does quoting GDPR article numbers put people off? For most people outside the legal and privacy profession, regulatory references signal complexity, obligation, and risk — none of which are motivating. They also signal that the person presenting has not translated the regulation into terms that are relevant to the audience in front of them. A marketing manager does not need to know the number of the article that governs consent; they need to understand what consent means for their next campaign and what they need to do differently.

How do I identify the sub-cultures in my organisation? Start by spending time in different departments before you present to them. Walk the floor if you can. Have informal conversations. Look at how spaces are arranged and how people interact. Ask a trusted contact in each team what their department cares about most, what frustrates them, and how they prefer to receive information. None of this needs to be formal — the goal is to arrive in the room with a working model of who you are talking to, not a blank slate.

How do I adapt my privacy communications for different departments without losing consistency? The underlying message and the obligations remain constant — what changes is the framing, the examples, and the language. A consistent privacy programme can express the same requirements in terms of customer trust for the commercial team, process efficiency for operations, risk reduction for finance, and technical implementation for IT. The regulation is the same; the resonance depends on how you translate it for each audience.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts