Skip to main content

Managing the uncertainty of interpreting GDPR requirements in your GDPR project

Originally published on LinkedIn in February 2017, as the fourth in a series on running a GDPR project. The previous posts covered GDPR project considerations, the Visual Privacy Program Game Plan, and how to break a GDPR project into deliverables.


Diagram showing how the GDPR Project Team, Project Board, Data Protection Authority, external law partners, and governance boards interact — with the Assumptions Log and Deliverables Roadmap at the centre

In some organisations there may be one or two stakeholders who are not comfortable buying into a project where you as Project Manager are not able to present a clear picture of the end state — or where the answer to some key questions involves explaining that there are still areas to be clarified, and that clarification may not be available until the end of the year.

Some stakeholders question how you are able to plan such a project and may prefer to wait. In the meantime your organisation is on the back foot. Key customers come knocking on the door wanting to see evidence that you are taking GDPR seriously, and you are either in control or not in control of your GDPR project.

The diagram above attempts to explain how to manage the uncertainty around aspects of the GDPR and still move forward, as well as the importance of having regular and structured communication between your GDPR Project Team, the Project Board, and other Governance Boards or key stakeholder groups in your organisation.

Don’t wait — manage assumptions instead #

Waiting until the full picture of the GDPR has been painted is not an option. You must move forward based on what you know. Identifying gaps and key risks is an early piece of work in any compliance project, so planning this work and getting started as soon as possible is obvious.

To avoid gaping holes in your project schedule or big question marks in your project documentation, you need to:

  • Describe assumptions and document them in an Assumptions Log
  • Set target validation dates for each assumption
  • Assign ownership to appropriate people in your organisation, whose task is to track and ensure they get validated

How assumptions connect to your roadmap #

The assumptions underpin your GDPR Deliverables Roadmap as well as your project schedule. If an assumption is correct, you move forward as planned. If it is not valid, you adjust accordingly and then move forward using your GDPR project’s change process (if you have one).

The assumptions you make will be based on expert knowledge gained from colleagues within your organisation and external partners. The importance of having a collaborative project organisation — where open communication channels exist between the GDPR Project Team, the Project Board, various Governance Boards, and expert legal competences specialised in data protection — cannot be overstated.

External legal partners may bring valuable insights from other organisations they are working with, from their industry networks, and from your own Data Protection Authority.

Assumptions Management as a discipline #

Assumptions Management is a key discipline in any GDPR project. To use that well-known quote, you must ensure your assumptions are monitored and validated — to avoid making an ASS out of U and ME.

Frequently Asked Questions #

What is an Assumptions Log in a GDPR project? An Assumptions Log is a document that records each assumption your project is making about GDPR requirements that have not yet been fully clarified. Each entry includes the assumption itself, a target date for validation, and a named owner responsible for tracking and resolving it.

How do you manage GDPR regulatory uncertainty without stalling your project? You move forward based on what you know, documenting assumptions explicitly rather than leaving gaps in your project plan. Regular structured communication between the Project Team, Project Board, legal advisers, and your Data Protection Authority keeps assumptions grounded in the best available expertise.

What happens if a GDPR assumption turns out to be wrong? If an assumption is validated and confirmed, you continue as planned. If it turns out to be incorrect, you adjust your deliverables and schedule accordingly, using your project’s change control process to formally record and manage the impact.


I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts