Who is championing your Privacy (GDPR) Program?
Originally published on LinkedIn, April 2018.

Privacy Champions — individuals embedded in key departments with specific skills and knowledge to represent your privacy programme — are one of the most effective tools for building GDPR traction from the ground up. They are particularly valuable when tone from the top is weak, and they remain useful long after the initial programme has concluded.
Why Privacy Champions? #
With GDPR enforcement approaching in May 2018, countless programmes were battling to demonstrate sufficient accountability and show they were “in control”. At the same time, many organisations across Europe had only just started their privacy programmes — or had not yet begun.
The concept of champions is not new. I first encountered it during my time at Aviva around 2001. What makes it work in a GDPR context is that Privacy Champions help embed and reinforce knowledge, safe practices, and the required attitude from the bottom up — while you work in parallel to get senior management to take ownership. Ideally, Privacy Champions will be part of a broader organisational change strategy, with dedicated change management practitioners driving the initiative alongside other programme workstreams.

The role of the Privacy Champion #
- Acquire knowledge about data protection concepts and your company’s privacy programme “in the trenches” and share it with colleagues
- Promote the privacy programme within their own department and cross-company
- Identify issues and risks within their own department
- Identify potential areas of resistance to the changes associated with GDPR
- Become a go-to person during the programme and post-implementation of key policies and procedures
Responsibilities of a Privacy Champion #
- Act as a role model for privacy concepts and tasks
- Understand the key impacts of the GDPR on the organisation and specifically on their own department
- Understand the key programme deliverables, milestones, and timeline
- Attend programme meetings when required
- Assist with cascading programme communications
- Review relevant key deliverables and provide feedback
- Attend train-the-trainer sessions
- Provide ongoing support to colleagues in their department during the programme
- Introduce new colleagues to required GDPR education and training
Typical profile of a Privacy Champion #
- Knowledge of their own department’s processes and applications
- Understanding of the business and organisational setup
- Positive and open-minded
- Able to give regular feedback to the privacy programme team
- Charismatic and influential
- Trusted and respected by colleagues
- Ability to recognise resistance to change and be supportive to colleagues
Typical touch points with the core programme team #
- Initial Privacy Champion kick-off
- Regular programme status updates
- Quarterly Privacy Champion face-to-face meetings
- Programme meetings as required to discuss the development of deliverables — communications, readiness assessments, training preparation, etc.
- Email exchanges
- Privacy programme portal for news, articles, and lessons learned
How to establish Privacy Champions #
- Present the concept to Senior Management or the Programme Board, ideally with a cost/benefit analysis to justify funding
- Identify the departments across the organisation where Privacy Champions are required
- Identify suitable candidates
- Prepare initial basic GDPR materials for all Privacy Champions
- Conduct kick-off
- Book quarterly meetings
- Prepare custom materials for specific departments
- Conduct specific education and training for Privacy Champions
Frequently Asked Questions #
What is a Privacy Champion? A Privacy Champion is an individual within a department who, given specific skills and knowledge, represents the privacy programme in their functional area. They are not privacy experts — they are informed colleagues who can answer basic questions, flag issues, model the right behaviours, and act as a conduit between their team and the core programme.
When should you establish Privacy Champions? As early as possible in the programme. Privacy Champions are most valuable during the period when awareness is low, senior buy-in is not yet secured, and the core team cannot reach every corner of the organisation directly. They remain useful post-implementation as embedded points of contact for ongoing privacy questions.
What is the difference between a Privacy Champion and a Data Protection Officer? A DPO is a formal role with specific responsibilities and independence requirements under GDPR Article 37–39. A Privacy Champion is an informal programme role with no legal standing — a change enabler rather than a compliance function. The two roles are complementary: Privacy Champions extend the reach of the privacy programme into departments in ways that a DPO cannot do alone.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





