Executive insight
GDPR is not a ban on using data — it is a demand for accountable choices
Privacy risks rarely begin with a lack of policy. They begin when an organisation collects, shares or reuses personal data without a clear purpose, named ownership or an informed decision about risk.
Personal data can create considerable value. It can improve services, support better decisions, prevent fraud and make operations more efficient.
GDPR permits this. But it requires the organisation to explain why the data is needed, establish a valid legal basis and demonstrate that the processing is necessary, proportionate and secure.
The leadership question is therefore not simply: “Are we compliant?” It is: “Can we defend the choices we have made?”
Why this requires leadership attention
Privacy is often delegated to legal, security or IT specialists. These functions are essential, but they cannot decide the organisation’s risk appetite, priorities or acceptable trade-offs.
The most serious risks arise when responsibility is fragmented. One team collects the data, another procures the system, a supplier processes the information and management assumes that someone else has verified the whole arrangement.
The consequences can extend beyond regulatory sanctions. Poor privacy governance may cause harm to individuals, disrupt operations, damage trust and prevent an organisation from using valuable data when it is genuinely needed.
What the rules permit
GDPR does not require consent for every use of personal data. Depending on the situation, processing may be based on consent, a contract, a legal obligation, vital interests, a task in the public interest or a legitimate interest that does not override the individual’s rights.
The appropriate basis must be selected before processing begins. It cannot be chosen afterwards merely to justify an existing practice.
Within this framework, organisations can:
- use the personal data necessary to deliver agreed services;
- meet legal and regulatory obligations;
- protect systems, prevent fraud and maintain information security;
- pursue legitimate organisational interests after assessing the effects on individuals;
- analyse properly anonymised information that can no longer be linked to an identifiable person.
The governing principles remain the same: defined purposes, data minimisation, accuracy, limited retention, transparency, security and accountability.
What the rules constrain
An organisation cannot collect personal data simply because it may become useful later. Nor can it automatically reuse information for a new and incompatible purpose.
GDPR particularly constrains:
- excessive or speculative data collection;
- unclear secondary use of customer, employee or citizen data;
- indefinite retention without a documented need;
- access being granted more widely than required;
- sharing with suppliers without defined responsibilities and safeguards;
- international transfers without an applicable transfer mechanism;
- processing sensitive information without both a legal basis and the additional conditions required for special-category data;
- solely automated decisions that have legal or similarly significant effects, except in limited circumstances and with appropriate safeguards.
Individuals must also receive clear information about the processing and be able to exercise applicable rights, including access, correction, objection and erasure.
The risks leadership should examine
The primary risk is not the volume of data alone. It is the combination of sensitivity, scale, access, technical dependency and consequences for the individual.
- Do we know what personal data the organisation actually uses?
- Is every material use connected to a defined purpose and legal basis?
- Are responsibilities clear between us and our suppliers?
- Can we remove data when the purpose has ended?
- Are privacy and security requirements built into new services from the start?
- Could profiling or automated decisions unfairly affect an individual?
- Would we recognise and manage a personal data breach quickly enough?
A data protection impact assessment is required where processing is likely to create a high risk to people’s rights and freedoms. It should be completed before processing begins and maintained as circumstances change.
A practical first response
- Map one important process from collection to deletion.
- Identify the purpose, legal basis, systems, recipients and accountable owner.
- Remove unnecessary data and access.
- Review supplier agreements, transfers and incident responsibilities.
- Decide whether the remaining risk requires a formal impact assessment or management decision.
A personal data breach that is likely to create a risk for individuals must normally be reported to the supervisory authority without undue delay and, where feasible, within 72 hours of discovery. High-risk breaches may also require notification to the affected individuals.
Questions for the leadership team
- Which use of personal data would be most difficult to explain publicly?
- Where are we relying on assumptions instead of evidence?
- Who has authority to stop processing when the risk is unacceptable?
- Can we demonstrate that privacy choices are followed in practice?
Good privacy governance does not prevent an organisation from using data. It creates the conditions for using it lawfully, responsibly and with confidence.
Official sources
- European Commission — Principles of the GDPR
- European Commission — Legal grounds for processing data
- European Commission — When a Data Protection Impact Assessment is required
- European Commission — Personal data breaches
This article provides general leadership guidance and is not legal advice. Sector-specific and national rules may add further requirements.
From insight to action
Create a defensible picture of your privacy governance
Start by mapping one important flow of personal data, its purpose, legal basis, ownership, recipients, retention and controls. Independent senior support can help leadership connect legal requirements with practical governance and operational risk.