Managing the uncertainty of interpreting GDPR requirements in your GDPR project
Originally published on LinkedIn in February 2017, as the fourth in a series on running a GDPR project. The previous posts covered GDPR project considerations, the Visual Privacy Program Game Plan, and how to break a GDPR project into deliverables.

In some organisations there may be one or two stakeholders who are not comfortable buying into a project where you as Project Manager are not able to present a clear picture of the end state — or where the answer to some key questions involves explaining that there are still areas to be clarified, and that clarification may not be available until the end of the year.
Some stakeholders question how you are able to plan such a project and may prefer to wait. In the meantime your organisation is on the back foot. Key customers come knocking on the door wanting to see evidence that you are taking GDPR seriously, and you are either in control or not in control of your GDPR project.
The diagram above attempts to explain how to manage the uncertainty around aspects of the GDPR and still move forward, as well as the importance of having regular and structured communication between your GDPR Project Team, the Project Board, and other Governance Boards or key stakeholder groups in your organisation.
Don’t wait — manage assumptions instead #
Waiting until the full picture of the GDPR has been painted is not an option. You must move forward based on what you know. Identifying gaps and key risks is an early piece of work in any compliance project, so planning this work and getting started as soon as possible is obvious.
To avoid gaping holes in your project schedule or big question marks in your project documentation, you need to:
- Describe assumptions and document them in an Assumptions Log
- Set target validation dates for each assumption
- Assign ownership to appropriate people in your organisation, whose task is to track and ensure they get validated
How assumptions connect to your roadmap #
The assumptions underpin your GDPR Deliverables Roadmap as well as your project schedule. If an assumption is correct, you move forward as planned. If it is not valid, you adjust accordingly and then move forward using your GDPR project’s change process (if you have one).
The assumptions you make will be based on expert knowledge gained from colleagues within your organisation and external partners. The importance of having a collaborative project organisation — where open communication channels exist between the GDPR Project Team, the Project Board, various Governance Boards, and expert legal competences specialised in data protection — cannot be overstated.
External legal partners may bring valuable insights from other organisations they are working with, from their industry networks, and from your own Data Protection Authority.
Assumptions Management as a discipline #
Assumptions Management is a key discipline in any GDPR project. To use that well-known quote, you must ensure your assumptions are monitored and validated — to avoid making an ASS out of U and ME.
Frequently Asked Questions #
What is an Assumptions Log in a GDPR project? An Assumptions Log is a document that records each assumption your project is making about GDPR requirements that have not yet been fully clarified. Each entry includes the assumption itself, a target date for validation, and a named owner responsible for tracking and resolving it.
How do you manage GDPR regulatory uncertainty without stalling your project? You move forward based on what you know, documenting assumptions explicitly rather than leaving gaps in your project plan. Regular structured communication between the Project Team, Project Board, legal advisers, and your Data Protection Authority keeps assumptions grounded in the best available expertise.
What happens if a GDPR assumption turns out to be wrong? If an assumption is validated and confirmed, you continue as planned. If it turns out to be incorrect, you adjust your deliverables and schedule accordingly, using your project’s change control process to formally record and manage the impact.
I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.





