Getting executive buy-in for your data protection program — how far would you go?
Originally published on LinkedIn, June 2019.

Deep down, you know your data protection programme could be adding far greater value to your organisation than it currently does. You have ideas, perhaps a maturity assessment and a prioritised remediation plan. You have presented your recommendations to your boss, who showed them to her boss — and then it stopped. “Didn’t we already address this?” “GDPR is so last year.”

Getting executive buy-in on an ongoing basis remains one of the most common frustrations for data protection leaders. Here are some practical approaches, in no particular order, drawn from personal experience across global organisations.
Framing #
Some data protection leaders failed to get traction for their work because colleagues were immediately turned off by the terminology — “GDPR”, “Data Subject”, “Article xx”, “Controller”, “DPIA”, “Data Protection by Design and by Default”. The language of the data protection office, not the language of the business.
Certain terms need to be understood by specific people, but not by everyone. If your work is being perceived as a barrier to daily operations or as a tick-box exercise, you may have a framing problem.
You need an overall frame and specific frames for key stakeholders and departments. Recognising the business value personal data brings to the organisation, and the part it plays in the achievement of colleagues’ personal objectives, will only help the dialogue you need to have with them — in their business terminology, their world. The communications department is often a significant help in developing the right frame and key messages.
Political manoeuvring #
Sometimes called stakeholder management, this means understanding the political dynamics of your organisation. Who has the ear of specific executives? Who do you need to build your coalition of change with? Who is most likely to support your proposal and put financial resources behind it? Who are the resistors, and what strategies do you need to bring them on board — if that is even possible?
It also means recognising exactly how personal data supports, or in some sectors fuels, your business.

Identify those who have the most to gain from the processing of personal data. They often need help seeing the holistic view — not just the benefits but also the legal obligations. Make it personal: understand their problems with data processing and how it affects them.
People approve ideas and initiatives. You can influence people.

Get out and about in your organisation. Wander around. Meet people. Build relationships. Get yourself known face-to-face and not just as a name in an email signature.
Business case #
Often overlooked because of past JFDI approaches to data protection, a robust business case is an essential document for justifying your intentions.

Most organisations will not allow new initiatives involving investment and resource allocation without an approved business case, typically driven through a portfolio management process. With budgets already set and the portfolio fixed, it is challenging to get a new initiative considered — and even a compelling case may be deferred to next year.
Some companies have established internal start-up routes that allow ideas to be considered and tested outside the traditional corporate portfolio. If you have a compelling case to test, for example, a data ethics approach in a specific line of business, this could be an excellent route if your organisation has one.
Business cases do not need to be thick documents. Less is more. Ensure you include:
- Problem statement
- Options considered
- Alignment with existing business objectives
- Risks
- Cost/benefit analysis
- Timeline
Once you have a draft business case, produce two high-level visual documents for stakeholder meetings where you may only have ten minutes to pitch:
1. Problem statement summary — RiskTelling #
Business cases often fail to offer compelling justification for investment because they focus on symptoms rather than root causes. Addressing a problem is often a tangle of complexity involving technology, policies and procedures, organisational structures, people, and information.
By conducting root cause analysis, you can pinpoint the relationships and dependencies between these factors — and when understood and documented, they map out what needs to be done. Factors left unaddressed present risks, and by understanding the relationships a narrative can be developed to explain to key stakeholders why deep surgery is required rather than applying plasters.
I call this approach “RiskTelling.” Conceptually it looks like this:

See also my earlier article on useful analysis models for more on the POTI framework that underpins this approach.
2. Visual game plan #
This is a one-page overview of how you will be tackling the work involved. Using builds and animations in PowerPoint you can story-tell what will happen and set expectations with key stakeholders. Read my earlier article about visual game plans if you want to discover how beneficial they can be.
Open door policy #
Although some leaders claim to operate with an open-door policy, it often depends on who you are. If you work in an organisation that genuinely has one and you want to use it, prepare by having the story (the why), a visual game plan (the how), and the business case ready to circulate afterwards.

In most organisations, you will need to sell your idea upwards through several layers, until the carefully prepared business case is diluted to a couple of bullet points in a loosely related set of slides presented by somebody far removed from your programme. Even your boss is not present at the meeting, let alone you.
External input #
It is sometimes beneficial to bring in somebody from outside to deliver your idea to your executive team on your behalf — with a degree of stealth about the fact that the idea originated from you. This works especially when the external body or individual has a strong reputation or track record, though it can be deeply frustrating for you and your colleagues who have painstakingly tried to articulate the same idea for months at a fraction of the cost.
How far would you go? #
Would you go as far as David Stirling?
Stirling was an officer in the British Army during the Second World War with an idea he knew would be quashed if presented through his chain of command. He decided he needed to go directly to the top brass. On crutches following an accident, he gained access to army HQ, burst into the office of a senior officer, and explained his idea. That officer persuaded his Commander-in-Chief to accept the plan.

His idea became the SAS. Without his audacity, the unit might never have existed — and many of the special forces around the world that followed might never have been established.
There is a time and a place for such an approach. I am not suggesting it as a routine option unless you have a genuinely groundbreaking idea and a leadership culture that encourages direct engagement. The lesson worth taking, however, is that the organisations which actively seek and reward ideas from employees at all levels — as Richer Sounds does — tend to be the ones that sustain success over time.
Frequently Asked Questions #
Why do data protection leaders struggle to get executive buy-in? The most common causes are poor framing — using regulatory language rather than business language — a lack of a business case, and failure to understand the political dynamics of the organisation. When data protection is positioned as a legal obligation rather than a business enabler, it is easy for executives to deprioritise it. Repositioning the conversation around business objectives, risk to revenue, and competitive advantage tends to get further.
What should a data protection business case include? Keep it concise: a problem statement, the options considered, alignment with existing business objectives, risks, a cost/benefit analysis, and a timeline. Alongside the written case, prepare two high-level visual documents — a RiskTelling summary that explains the underlying causes of the problem, and a visual game plan that shows how you intend to address it. These are the tools for the ten-minute stakeholder meeting, not the full document.
What is RiskTelling? RiskTelling is an approach to communicating risk and complexity to executive audiences by linking symptoms back to their root causes across a structured framework — typically POTI (Processes, Organisation, Technology, Information). Rather than presenting a list of risks, it tells a coherent story of why the problems exist, what the dependencies are, and why deep remediation is needed rather than quick fixes. It is a more compelling basis for securing investment than a conventional risk register entry.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





