Skip to main content

Visual Privacy Program Game Plan

Originally published on LinkedIn in January 2017, as a follow-up to GDPR project considerations. The Visual Game Plan approach remains a practical tool for communicating any privacy or compliance programme to senior stakeholders.


An example Visual Privacy Program Game Plan showing programme scope, timeline, goal and objectives, operational framework, risks and assumptions, and programme organisation

Once you have assembled a core team of subject matter experts (SMEs)* to help your Project or Programme Manager define how your organisation will tackle data protection legislation — and formulated this in a Project or Programme Initiation Document (PID) or Programme Charter — a Visual Game Plan is a useful tool both during and after that work.

What is a Visual Game Plan? #

A Visual Game Plan is a one-page summary of your PID. It communicates your organisation’s data protection challenge to busy executives, senior managers, and anyone else who needs to understand the gist of your privacy programme in about ten minutes.

The document is simple, easy to digest, and visually tells the key elements of your “data protection story”. If presenting using PowerPoint, Keynote, or a similar tool, introduce each element one by one using the animation function.

An example Visual Privacy Program Game Plan — your organisation’s will look quite different, reflecting its own challenges and context

What to include #

Typical elements to consider for your Visual Game Plan:

  • Goal and objectives
  • Scope
  • Approach
  • Key resources
  • Key risks
  • Key assumptions
  • Known issues
  • Known dependencies
  • Rough timeline
  • Ballpark budget

The Visual Game Plan can be drawn up on flip chart paper or as a PowerPoint slide. Once you have presented it and addressed any questions, modify it as needed — for example, with additional risks — and then circulate it to your audience together with the full PID or Charter.

Incidentally, Visual Game Plans came to me via David Sibbet in his book Visual Meetings — very inspirational.

Frequently Asked Questions #

What is a Visual Privacy Program Game Plan? A Visual Game Plan is a one-page summary of your data protection programme, covering scope, objectives, approach, key risks, and timeline. It is designed to brief busy executives and senior stakeholders on your GDPR or privacy programme in approximately ten minutes.

What should a Visual Game Plan include? At a minimum: goal and objectives, programme scope, the approach you are taking, key resources, key risks and assumptions, known issues and dependencies, a rough timeline, and an indicative budget. The exact content will vary depending on your organisation’s situation.

How is a Visual Game Plan different from a Project Initiation Document? A PID or Programme Charter is a detailed, multi-page document covering the why, what, when, who, and how of your programme. The Visual Game Plan is a one-page summary designed to communicate the essence quickly and clearly to stakeholders who will not read the full PID.


* Suggested SMEs to involve from the outset: Legal, IT, HR, Compliance, Information Security, Risk Management, Internal Audit, Procurement, and your lines of business.


I publish a fortnightly newsletter on data protection and privacy — practical, opinionated, and free. You can sign up on the newsletter page.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts