The Privacy Mindset: Seeing the Bigger Picture by Making Things Personal
Originally published on LinkedIn, December 2019.
Are you in the privacy profession to help your business comply with applicable laws and regulations — or to help grow your business through trust, transparency, and fairness to your customers? Perhaps a combination of the two, especially in a B2C context. Either way, the answer depends less on your tools, your policies, or your budget than on your mindset.
Smashing Rocks #
You may have come across the parable of the stonecutters. It appears in various forms. The version that resonates most with me goes like this.
Whilst out walking, you come across a person with a huge hammer who is smashing rocks.
“What’s going on here?” you ask.
The person responds, with a degree of frustration: “What does it look like I’m doing? I’m breaking rocks.”
You continue and find another person doing the same thing.
“What’s going on here?” you ask.
The person responds, with a wink: “I’m making a living.”
You walk further and find a third person doing exactly the same thing — but looking happy.
“What’s going on here?” you ask.
The person responds, with a broad smile: “I’m building a cathedral that will give pleasure to people for centuries to come.”

Carmine Gallo retells a version of this story in his book The Storyteller’s Secret, using it to illustrate the difference between people who see their work as a task, a transaction, or a contribution to something larger. I was reminded of it again recently — and of how clearly it maps onto the privacy profession.
Three Mindsets in the Privacy Profession #
All three stonecutters are doing the same work. The difference is entirely in how they understand what they are doing and why it matters.
I have seen all three mindsets in privacy professionals — at conferences, in training sessions, and on-site with clients.
The rock breaker sees the work as theoretical compliance. Check the boxes, satisfy the requirement, move to the next one. Without seeing their contribution in the bigger scheme of things, their work — and that of their colleagues if they share the same mindset — can produce outcomes that actively harm the people they are supposed to be serving. The most common example is the threatening privacy notice: legally reviewed, technically compliant, and written in a way that makes customers feel surveilled rather than respected.
The living maker treats compliance as a transaction. It is a job to be done, a function to be performed. There is nothing wrong with professionalism. But it tends to produce minimum viable compliance rather than anything that builds genuine trust.
The cathedral builder sees data protection for what it actually is at its core: a framework for respecting people, their rights, and their freedoms — and for providing organisations with a structure to operate within when processing personal data responsibly. This is what legislation like GDPR is designed to achieve. The cathedral builder keeps that in mind even when working on the most granular compliance detail.

Many people are so focused on the details of theoretical compliance that they not only struggle to operationalise it — they often fail to pay any attention to the experience of the customers, employees, or patients whose data they are handling. Making it personal changes that. It reconnects the work to the people it is supposed to serve.
Motivating Your Team #
Mindset matters not just individually but as a leadership challenge. How your team understands the value of what they do is a significant motivational factor — and it is something you can influence directly.
Are you getting your team to hammer away at one legal requirement after another? Or are they shaping an ongoing programme with a continued focus on customer trust and transparency?

Respect the people, not just dotting i’s and crossing t’s. The two are not mutually exclusive — the detail matters — but the detail needs to sit inside a bigger frame of reference if it is going to produce work that actually changes anything.
Start Building Your Cathedral Today #
You can start to change things today by changing your own mindset. It is not about ignoring legal requirements. It is about re-framing them and seeing them in the bigger scheme of things.
The practical implication is straightforward: before you write a privacy notice, ask whether a customer will feel informed or threatened by it. Before you design a consent mechanism, ask whether it respects the person or just satisfies the requirement. Before you brief your team on a new obligation, ask whether the framing connects to why the obligation exists or just what it demands.
None of this requires a new tool, a bigger budget, or a restructured team. It requires a decision about which stonecutter you are going to be.
Stop smashing rocks. Build something that lasts.
Frequently Asked Questions #
What is the privacy mindset and why does it matter? The privacy mindset is an orientation toward data protection that keeps the people behind the data in view — not just the legal requirements around it. It matters because compliance without that orientation tends to produce technically adequate but practically inadequate outcomes: privacy notices that intimidate rather than inform, consent mechanisms designed to minimise friction for the organisation rather than reflect genuine choice, and programmes that tick boxes without changing behaviour.
How do I shift my team from a compliance mindset to a privacy mindset? Start with how you frame the work. If your team briefings and programme communications lead with obligations, penalties, and requirements, you are reinforcing the rock-breaking frame. Try leading instead with the outcomes you are trying to achieve for the people whose data you handle — customer trust, employee confidence, patient dignity. The legal requirements are still there; they are just positioned as means rather than ends.
Does a focus on trust and transparency conflict with strict legal compliance? Not at all — the two reinforce each other. Organisations that genuinely respect their customers’ data tend to find compliance more straightforward, because the instinct to do the right thing by people generally aligns with what the law requires. Where they diverge, the law sets the floor. The privacy mindset is about building above that floor, not ignoring it.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





