Leaders: win by respecting your customers, and their personal data — and don't forget your employees
Originally published on LinkedIn, February 2019.

Complying with data protection law and genuinely respecting personal data are not the same thing. Compliance is the floor, not the ceiling. Organisations that want to build lasting competitive advantage need to move from treating data protection as a legal obligation to embedding it as a cultural value — lived and breathed across every level of the business.
Privacy-focused culture #
Does your organisation have a culture that respects personal data in every aspect of its processing? Not just protects it, not just complies with the rules around it — but genuinely respects the rights and freedoms of the people who entrust data about themselves to you.
For many organisations, personal data fuels the business. For some, it becomes a business imperative to extract maximum value from that data — even when doing so compromises respect for the individual.

Questionable practices #
Aside from the headline cases, there is no shortage of examples of questionable practices that quietly continue.
It was widely reported that some airlines use an algorithm to intentionally split up families who do not pre-purchase seating. Think about how that decision came to be. Somebody thought it was a great idea. Somebody else approved it. A team of people worked to implement it. And there are no doubt metrics being reported somewhere on how much revenue it generates.

Or consider the service that provides parents with automated risk ratings for potential childminders — assessing risks of drug use, bullying, bad attitude, and disrespectfulness by scanning Twitter feeds, Facebook pages, and Instagram posts.

Organisations must live up to the principles of data protection legislation — lawfulness, fairness and transparency, purpose limitation, data minimisation, and so on. And although some may be able to demonstrate technical compliance, many are obviously still not doing the right thing. Mechanisms such as DPIAs and Data Protection by Design and by Default help, but in my view they do not go far enough.
Engraining respect for personal data is not easy #
It goes beyond having neatly written policies and procedures. It goes well beyond training and awareness. It goes beyond having a network of Privacy Champions in all departments.
It requires mindsets to be changed at all levels of the organisation where the processing of personal data is concerned — instinctively asking “is this right?” and “is this fair?” before acting.
As I wrote in a previous article, having the right tone from the top is an absolute prerequisite. Respect must be embedded in all levels of leadership and management, and engrained across the workforce involved in or dependent on the processing of personal data.
It will be worth the effort. The opportunity to differentiate your organisation through enhanced reputation and increased brand value is real — and those same things are typically listed as key risks in your risk register.
How do organisations truly achieve respect for personal data? #
Engaging people with organisational change management competences is essential. They have the knowledge, techniques, and experience to facilitate the change — but only after other foundational mechanisms are in place. A Data Protection Strategy is a prerequisite, and it must be aligned with existing business strategy and objectives. From there, it must be cascaded and embedded in individuals’ performance objectives, values, and behaviours from top to bottom. In other words, their daily work.
The key must #

The principle of respect must be given the same level of focus and attention as the achievement of business objectives. Personal data fuels the business — respect for it, and a clear sense of what is right and wrong, must be part of the equation. If that focus is missing or is allowed to erode, the hard work will be wasted.
Don’t forget your employees #
No matter whether you are a global corporation or an SME, comprehensive data protection legislation such as the GDPR places obligations on your company to protect the rights and freedoms of your employees — not just your customers.
If you operate globally, do not assume that the level of protection appropriate in Denmark or the UK will be acceptable elsewhere. This is especially relevant where you have offices in countries with repressive governments, where risks to the rights and freedoms of your colleagues may be higher — and where consequences could include physical abuse, torture, and persecution, not just to your colleagues but to their families.

When scoping a risk assessment or DPIA, remember to account for these broader perspectives. A PESTLE analysis will help surface the political and social factors that must be considered — and they will often be highly relevant.
A quick and easy test to see who gets it #
It is often possible to get a quick feel for whether an organisation genuinely respects data subjects. Without leaving your office, take a look at the privacy notice on your organisation’s website — or a competitor’s.
- Is it understandable from a layperson’s perspective, or is it a page of legalese written by a lawyer more interested in protecting the organisation’s interests than your rights and freedoms?
- Does it give you comfort that your data is in the right hands, or is there a feeling of deception?
- Does the tone and style match the rest of the website, or is it so generic that it is obviously a cut, paste, and find-replace exercise?
Privacy notices are public, easy to access, and one of the more straightforward privacy tasks to complete. If an organisation cannot get that right, what does that tell you about what is happening behind the scenes?
Frequently Asked Questions #
What does a privacy-focused culture actually look like in practice? It means employees at every level instinctively ask “is this right?” and “is this fair?” before processing personal data — not because a policy tells them to, but because the organisation’s values and leadership model make it the expected way of working. It is visible in how privacy is discussed in meetings, how risk decisions are made, and how products and services are designed from the outset.
Why is employee data often overlooked in data protection programmes? Programmes tend to focus on customer data because that is where commercial risk and regulatory scrutiny are most visible. Employee data carries its own obligations under GDPR and, in global organisations operating in high-risk jurisdictions, the stakes for individuals can be far higher — including risks to physical safety. A DPIA and PESTLE analysis scoped to cover employee data is essential, not optional.
How can I tell quickly whether an organisation takes data protection seriously? Read their privacy notice. A well-written notice that speaks plainly to the reader, explains what data is collected and why in accessible language, and feels consistent with the rest of the organisation’s communications is a strong positive signal. A generic, legalese-heavy document that resembles a template is a reliable warning sign about how data protection is prioritised internally.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





