Skip to main content

Leaders: win by respecting your customers, and their personal data — and don't forget your employees

Originally published on LinkedIn, February 2019.

Illustration of a robot with currency symbols on its chest holding hands with three human figures — representing organisations that treat personal data as a commodity rather than a responsibility

Complying with data protection law and genuinely respecting personal data are not the same thing. Compliance is the floor, not the ceiling. Organisations that want to build lasting competitive advantage need to move from treating data protection as a legal obligation to embedding it as a cultural value — lived and breathed across every level of the business.

Privacy-focused culture #

Does your organisation have a culture that respects personal data in every aspect of its processing? Not just protects it, not just complies with the rules around it — but genuinely respects the rights and freedoms of the people who entrust data about themselves to you.

For many organisations, personal data fuels the business. For some, it becomes a business imperative to extract maximum value from that data — even when doing so compromises respect for the individual.

Illustration of a giant hand squeezing a suited figure, with coins and the words “Data” and “Insights” spilling out — representing the extraction of value from individuals’ data at the expense of their rights

Questionable practices #

Aside from the headline cases, there is no shortage of examples of questionable practices that quietly continue.

It was widely reported that some airlines use an algorithm to intentionally split up families who do not pre-purchase seating. Think about how that decision came to be. Somebody thought it was a great idea. Somebody else approved it. A team of people worked to implement it. And there are no doubt metrics being reported somewhere on how much revenue it generates.

Illustration of a robot standing next to a family — child asking “Can I sit by the window mummy?” while the robot says “Hehe, I’ll be with you every step of the way!” — illustrating algorithmic manipulation of seating

Or consider the service that provides parents with automated risk ratings for potential childminders — assessing risks of drug use, bullying, bad attitude, and disrespectfulness by scanning Twitter feeds, Facebook pages, and Instagram posts.

Illustration of a hand holding a tablet displaying a stick figure profile being assessed, alongside an elderly woman with a walking stick — representing automated profiling of individuals based on social media

Organisations must live up to the principles of data protection legislation — lawfulness, fairness and transparency, purpose limitation, data minimisation, and so on. And although some may be able to demonstrate technical compliance, many are obviously still not doing the right thing. Mechanisms such as DPIAs and Data Protection by Design and by Default help, but in my view they do not go far enough.

Engraining respect for personal data is not easy #

It goes beyond having neatly written policies and procedures. It goes well beyond training and awareness. It goes beyond having a network of Privacy Champions in all departments.

It requires mindsets to be changed at all levels of the organisation where the processing of personal data is concerned — instinctively asking “is this right?” and “is this fair?” before acting.

As I wrote in a previous article, having the right tone from the top is an absolute prerequisite. Respect must be embedded in all levels of leadership and management, and engrained across the workforce involved in or dependent on the processing of personal data.

It will be worth the effort. The opportunity to differentiate your organisation through enhanced reputation and increased brand value is real — and those same things are typically listed as key risks in your risk register.

How do organisations truly achieve respect for personal data? #

Engaging people with organisational change management competences is essential. They have the knowledge, techniques, and experience to facilitate the change — but only after other foundational mechanisms are in place. A Data Protection Strategy is a prerequisite, and it must be aligned with existing business strategy and objectives. From there, it must be cascaded and embedded in individuals’ performance objectives, values, and behaviours from top to bottom. In other words, their daily work.

The key must #

Illustration of a figure holding a sign reading “Corporate Policy: Win by respecting our customers!” — representing the ambition to embed respect as a business objective, not just a compliance requirement

The principle of respect must be given the same level of focus and attention as the achievement of business objectives. Personal data fuels the business — respect for it, and a clear sense of what is right and wrong, must be part of the equation. If that focus is missing or is allowed to erode, the hard work will be wasted.

Don’t forget your employees #

No matter whether you are a global corporation or an SME, comprehensive data protection legislation such as the GDPR places obligations on your company to protect the rights and freedoms of your employees — not just your customers.

If you operate globally, do not assume that the level of protection appropriate in Denmark or the UK will be acceptable elsewhere. This is especially relevant where you have offices in countries with repressive governments, where risks to the rights and freedoms of your colleagues may be higher — and where consequences could include physical abuse, torture, and persecution, not just to your colleagues but to their families.

Illustration of three figures representing different threat scenarios for employees in high-risk jurisdictions — a dismissed employee, a detained person, and an authority figure

When scoping a risk assessment or DPIA, remember to account for these broader perspectives. A PESTLE analysis will help surface the political and social factors that must be considered — and they will often be highly relevant.

A quick and easy test to see who gets it #

It is often possible to get a quick feel for whether an organisation genuinely respects data subjects. Without leaving your office, take a look at the privacy notice on your organisation’s website — or a competitor’s.

  • Is it understandable from a layperson’s perspective, or is it a page of legalese written by a lawyer more interested in protecting the organisation’s interests than your rights and freedoms?
  • Does it give you comfort that your data is in the right hands, or is there a feeling of deception?
  • Does the tone and style match the rest of the website, or is it so generic that it is obviously a cut, paste, and find-replace exercise?

Privacy notices are public, easy to access, and one of the more straightforward privacy tasks to complete. If an organisation cannot get that right, what does that tell you about what is happening behind the scenes?

Frequently Asked Questions #

What does a privacy-focused culture actually look like in practice? It means employees at every level instinctively ask “is this right?” and “is this fair?” before processing personal data — not because a policy tells them to, but because the organisation’s values and leadership model make it the expected way of working. It is visible in how privacy is discussed in meetings, how risk decisions are made, and how products and services are designed from the outset.

Why is employee data often overlooked in data protection programmes? Programmes tend to focus on customer data because that is where commercial risk and regulatory scrutiny are most visible. Employee data carries its own obligations under GDPR and, in global organisations operating in high-risk jurisdictions, the stakes for individuals can be far higher — including risks to physical safety. A DPIA and PESTLE analysis scoped to cover employee data is essential, not optional.

How can I tell quickly whether an organisation takes data protection seriously? Read their privacy notice. A well-written notice that speaks plainly to the reader, explains what data is collected and why in accessible language, and feels consistent with the rest of the organisation’s communications is a strong positive signal. A generic, legalese-heavy document that resembles a template is a reliable warning sign about how data protection is prioritised internally.


If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.

Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.

Author
Tim Clements
Tim Clements is Business Owner of Purpose and Means, a data protection and GRC consultancy based in Copenhagen, operating globally. He helps data protection and GRC leaders simplify complexity into actionable strategies, providing tools, training, and support to engage and influence across the organisation. Tim is a Chartered Fellow of the BCS (British Computer Society).

Browse by Topic

access controls accountability accountability frameworks ai act ai ethics ai governance ai infrastructure sovereignty ai literacy ai regulation article 12 article 13 article 22 article 25 article 28 article 30 article 32 article 35 article 46 article 5 article 6 article 7 audit and assessment automated decision-making awareness awareness campaigns behaviour change beyond legal board level board reporting case law change management chief people officer cloud infrastructure compliance monitoring consent cookie compliance cross-border transfers customer success dark patterns data accuracy data breach notification data flows data mapping data minimisation data processing agreements data protection data protection by design data protection culture data protection day data protection hero data protection leader data quality data residency data retention data science data sovereignty data subject rights datatilsynet deceptive design design thinking direct marketing dora dpia education employee data employee engagement enterprise architecture eprivacy esg executive communication external legal counsel finance and banking gdpr gdpr at 10 generative ai governance grc healthcare history horizon scanning hr and data protection hr and employment incident response information security intellectual property internal communications international transfers lawful basis leadership lego serious play machine learning marketing nis2 passwords privacy by design privacy culture privacy notice privacy policy product management profiling public sector purpose limitation quantum computing records of processing regulatory guidance risk management risk reduction ropa sales security software development special category data standard contractual clauses strategic planning sub-processors supply chain sustainability system design third-party risk training training design transparency trend radar ux design vendor management visual communication weak signals workshop facilitation

Related Posts