Skip to main content

The Privacy Mindset: Seeing the Bigger Picture by Making Things Personal

Originally published on LinkedIn, December 2019.

Are you in the privacy profession to help your business comply with applicable laws and regulations — or to help grow your business through trust, transparency, and fairness to your customers? Perhaps a combination of the two, especially in a B2C context. Either way, the answer depends less on your tools, your policies, or your budget than on your mindset.

Smashing Rocks #

You may have come across the parable of the stonecutters. It appears in various forms. The version that resonates most with me goes like this.

Whilst out walking, you come across a person with a huge hammer who is smashing rocks.

“What’s going on here?” you ask.

The person responds, with a degree of frustration: “What does it look like I’m doing? I’m breaking rocks.”

You continue and find another person doing the same thing.

“What’s going on here?” you ask.

The person responds, with a wink: “I’m making a living.”

You walk further and find a third person doing exactly the same thing — but looking happy.

“What’s going on here?” you ask.

The person responds, with a broad smile: “I’m building a cathedral that will give pleasure to people for centuries to come.”

Illustration of two people smashing rocks with large hammers

Carmine Gallo retells a version of this story in his book The Storyteller’s Secret, using it to illustrate the difference between people who see their work as a task, a transaction, or a contribution to something larger. I was reminded of it again recently — and of how clearly it maps onto the privacy profession.

Three Mindsets in the Privacy Profession #

All three stonecutters are doing the same work. The difference is entirely in how they understand what they are doing and why it matters.

I have seen all three mindsets in privacy professionals — at conferences, in training sessions, and on-site with clients.

The rock breaker sees the work as theoretical compliance. Check the boxes, satisfy the requirement, move to the next one. Without seeing their contribution in the bigger scheme of things, their work — and that of their colleagues if they share the same mindset — can produce outcomes that actively harm the people they are supposed to be serving. The most common example is the threatening privacy notice: legally reviewed, technically compliant, and written in a way that makes customers feel surveilled rather than respected.

The living maker treats compliance as a transaction. It is a job to be done, a function to be performed. There is nothing wrong with professionalism. But it tends to produce minimum viable compliance rather than anything that builds genuine trust.

The cathedral builder sees data protection for what it actually is at its core: a framework for respecting people, their rights, and their freedoms — and for providing organisations with a structure to operate within when processing personal data responsibly. This is what legislation like GDPR is designed to achieve. The cathedral builder keeps that in mind even when working on the most granular compliance detail.

Illustration of a confrontational interaction between two people, representing a customer’s experience of a threatening privacy notice

Many people are so focused on the details of theoretical compliance that they not only struggle to operationalise it — they often fail to pay any attention to the experience of the customers, employees, or patients whose data they are handling. Making it personal changes that. It reconnects the work to the people it is supposed to serve.

Motivating Your Team #

Mindset matters not just individually but as a leadership challenge. How your team understands the value of what they do is a significant motivational factor — and it is something you can influence directly.

Are you getting your team to hammer away at one legal requirement after another? Or are they shaping an ongoing programme with a continued focus on customer trust and transparency?

Illustration of two people giving each other a high five across a table, representing team engagement and shared purpose

Respect the people, not just dotting i’s and crossing t’s. The two are not mutually exclusive — the detail matters — but the detail needs to sit inside a bigger frame of reference if it is going to produce work that actually changes anything.

Start Building Your Cathedral Today #

You can start to change things today by changing your own mindset. It is not about ignoring legal requirements. It is about re-framing them and seeing them in the bigger scheme of things.

The practical implication is straightforward: before you write a privacy notice, ask whether a customer will feel informed or threatened by it. Before you design a consent mechanism, ask whether it respects the person or just satisfies the requirement. Before you brief your team on a new obligation, ask whether the framing connects to why the obligation exists or just what it demands.

None of this requires a new tool, a bigger budget, or a restructured team. It requires a decision about which stonecutter you are going to be.

Stop smashing rocks. Build something that lasts.

Frequently Asked Questions #

What is the privacy mindset and why does it matter? The privacy mindset is an orientation toward data protection that keeps the people behind the data in view — not just the legal requirements around it. It matters because compliance without that orientation tends to produce technically adequate but practically inadequate outcomes: privacy notices that intimidate rather than inform, consent mechanisms designed to minimise friction for the organisation rather than reflect genuine choice, and programmes that tick boxes without changing behaviour.

How do I shift my team from a compliance mindset to a privacy mindset? Start with how you frame the work. If your team briefings and programme communications lead with obligations, penalties, and requirements, you are reinforcing the rock-breaking frame. Try leading instead with the outcomes you are trying to achieve for the people whose data you handle — customer trust, employee confidence, patient dignity. The legal requirements are still there; they are just positioned as means rather than ends.

Does a focus on trust and transparency conflict with strict legal compliance? Not at all — the two reinforce each other. Organisations that genuinely respect their customers’ data tend to find compliance more straightforward, because the instinct to do the right thing by people generally aligns with what the law requires. Where they diverge, the law sets the floor. The privacy mindset is about building above that floor, not ignoring it.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts