Leaders: set the right "tone from the top" to help your data protection program succeed
Originally published on LinkedIn, February 2019.

Poor tone from the top can undermine even the most professionally built data protection programme. An organisation may have excellent policies, state-of-the-art security tools, and a capable team — but if one or more executives are sending the wrong signals, it becomes a serious issue that requires urgent attention.
What is tone from the top? #
In simple terms, it is the attitude and overall culture lived and breathed by executive and senior management — setting the right example to the rest of the organisation. Done well, it is a relatively inexpensive soft control and tends to be invisible. Done badly, it gets noticed and can be detrimental to the business.
Poor tone manifests in different ways #
Many cite the US corporate scandals at the turn of the century — Enron, WorldCom — as classic examples of catastrophically wrong tone from the top. But the pattern continues. Cases of executives whose attitudes and behaviour crossed the line have included allegations of physical misconduct by a retail CEO, false accounting by a car manufacturer’s chief executive, and a senior Danish public official who misused his position for personal benefit and whose organisation then fired the whistle-blower who reported it.

Tone from the top in data protection programmes #
In the context of a data protection programme, tone from the top is an essential element. Although the phrase is not specifically mentioned in the GDPR, a positive tone undoubtedly underpins the principle of Accountability — and several others besides.
Once poor tone is detected or perceived, it negatively impacts:
- the effectiveness of the overall data protection programme
- the morale of the data protection team
- the organisational culture — which becomes infected with an attitude of “if they don’t care, why should we?”

Symptoms of poor tone from the top #
Here are the warning signs you may have come across:
- Not inviting data protection leaders to strategic discussions that may create issues concerning personal data
- Executives openly circumventing data protection policies

- Perception that data protection is a one-off or tick-box initiative
- Rewarding or favouring employees who get work done by circumventing controls
- Steering Committee or Board meetings regularly cancelled, or repeated no-shows by certain members

- No Data Protection Strategy or business case
- Following a “risk-based approach” without being able to articulate the organisation’s risk appetite

- Downplaying, trivialising, or removing privacy risks from risk registers — because some misguided executives see reported risks as an admission of lack of control, a case of exposing dirty laundry

- Not allocating sufficient or competent resources to the data protection programme team
- Refusing to participate in training or awareness sessions — which typically means decision makers are not sufficiently informed about key aspects of the programme

- Despite personal data fuelling the business, believing data protection requirements are specific to one department — resulting in a biased focus on legal, IT, or security alone

- Flippant remarks to employees about privacy and security controls
- Doing things on the cheap or pursuing minimal compliance — for example, using “paper tiger” documentation toolkits for the policy framework

The questions leaders should be asking #
Poor tone from the top can also manifest in never asking the right questions. As John Thorp suggests in his excellent book The Information Paradox, the four questions every leader should be asking regularly are:
- Are we doing the right things?
- Are we doing them the right way?
- Are we getting them done well?
- Are we getting the benefits?
If these questions are not being asked — or if the answers are being suppressed before they reach the top — that is itself a symptom of poor tone.
Frequently Asked Questions #
What does “tone from the top” mean in a data protection context? It refers to the attitude, behaviour, and cultural signals set by executive and senior management in relation to data protection. A positive tone means leaders visibly champion privacy, attend relevant meetings, ask the right questions, and hold themselves to the same standards they expect of others. It underpins the GDPR’s Accountability principle and is one of the most cost-effective controls an organisation can deploy.
What are the consequences of poor executive tone for a data protection programme? Poor tone reduces the effectiveness of the programme, damages team morale, and spreads a culture of indifference — “if they don’t care, why should we?” Policies and technical controls cannot compensate for an executive team that openly circumvents them, trivialises risk, or treats data protection as someone else’s problem.
How do you address poor tone from the top? There is no single fix, but Privacy Champions embedded in departments can help build momentum from the ground up while you work on senior buy-in. A clear Data Protection Strategy with a business case — linked to organisational objectives rather than just regulatory risk — tends to resonate better at board level than a compliance-led argument. Making the cost of inaction visible, in business terms, is usually more effective than citing regulatory fines alone.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





