Skip to main content

Who is championing your Privacy (GDPR) Program?

Originally published on LinkedIn, April 2018.

Illustration of a circle of figures holding hands, representing Privacy Champions connected across an organisation

Privacy Champions — individuals embedded in key departments with specific skills and knowledge to represent your privacy programme — are one of the most effective tools for building GDPR traction from the ground up. They are particularly valuable when tone from the top is weak, and they remain useful long after the initial programme has concluded.

Why Privacy Champions? #

With GDPR enforcement approaching in May 2018, countless programmes were battling to demonstrate sufficient accountability and show they were “in control”. At the same time, many organisations across Europe had only just started their privacy programmes — or had not yet begun.

The concept of champions is not new. I first encountered it during my time at Aviva around 2001. What makes it work in a GDPR context is that Privacy Champions help embed and reinforce knowledge, safe practices, and the required attitude from the bottom up — while you work in parallel to get senior management to take ownership. Ideally, Privacy Champions will be part of a broader organisational change strategy, with dedicated change management practitioners driving the initiative alongside other programme workstreams.

Diagram showing the five key benefits of Privacy Champions around a central circle of figures: creating super-users, gathering feedback from the trenches, clarifying data protection concepts in department, reducing pressure on the core team, and assisting with managing resistance to change

The role of the Privacy Champion #

  • Acquire knowledge about data protection concepts and your company’s privacy programme “in the trenches” and share it with colleagues
  • Promote the privacy programme within their own department and cross-company
  • Identify issues and risks within their own department
  • Identify potential areas of resistance to the changes associated with GDPR
  • Become a go-to person during the programme and post-implementation of key policies and procedures

Responsibilities of a Privacy Champion #

  • Act as a role model for privacy concepts and tasks
  • Understand the key impacts of the GDPR on the organisation and specifically on their own department
  • Understand the key programme deliverables, milestones, and timeline
  • Attend programme meetings when required
  • Assist with cascading programme communications
  • Review relevant key deliverables and provide feedback
  • Attend train-the-trainer sessions
  • Provide ongoing support to colleagues in their department during the programme
  • Introduce new colleagues to required GDPR education and training

Typical profile of a Privacy Champion #

  • Knowledge of their own department’s processes and applications
  • Understanding of the business and organisational setup
  • Positive and open-minded
  • Able to give regular feedback to the privacy programme team
  • Charismatic and influential
  • Trusted and respected by colleagues
  • Ability to recognise resistance to change and be supportive to colleagues

Typical touch points with the core programme team #

  • Initial Privacy Champion kick-off
  • Regular programme status updates
  • Quarterly Privacy Champion face-to-face meetings
  • Programme meetings as required to discuss the development of deliverables — communications, readiness assessments, training preparation, etc.
  • Email exchanges
  • Privacy programme portal for news, articles, and lessons learned

How to establish Privacy Champions #

  • Present the concept to Senior Management or the Programme Board, ideally with a cost/benefit analysis to justify funding
  • Identify the departments across the organisation where Privacy Champions are required
  • Identify suitable candidates
  • Prepare initial basic GDPR materials for all Privacy Champions
  • Conduct kick-off
  • Book quarterly meetings
  • Prepare custom materials for specific departments
  • Conduct specific education and training for Privacy Champions

Frequently Asked Questions #

What is a Privacy Champion? A Privacy Champion is an individual within a department who, given specific skills and knowledge, represents the privacy programme in their functional area. They are not privacy experts — they are informed colleagues who can answer basic questions, flag issues, model the right behaviours, and act as a conduit between their team and the core programme.

When should you establish Privacy Champions? As early as possible in the programme. Privacy Champions are most valuable during the period when awareness is low, senior buy-in is not yet secured, and the core team cannot reach every corner of the organisation directly. They remain useful post-implementation as embedded points of contact for ongoing privacy questions.

What is the difference between a Privacy Champion and a Data Protection Officer? A DPO is a formal role with specific responsibilities and independence requirements under GDPR Article 37–39. A Privacy Champion is an informal programme role with no legal standing — a change enabler rather than a compliance function. The two roles are complementary: Privacy Champions extend the reach of the privacy programme into departments in ways that a DPO cannot do alone.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts