Data Protection Diaries 3: We Have Policies… So Why Aren’t We Compliant? 

This week I want to touch on a favourite response I hear in relation to organisations thinking they are compliant…. 

“We’ve got all the policies in place, so we must be compliant.” 

I completely understand why people think that. After all, if you’ve invested time writing policies, surely that’s half the battle? 

Well… not quite. 

Having policies is important. In fact, they’re an essential part of good governance and being able to evidence accountability to Data Protection requirements….. 

But policies sitting on a SharePoint site or tucked away in a folder don’t protect personal data. People do. 

One of the first questions I ask organisations is: 

“How many of your staff actually know these policies exist?” 

Often there’s an awkward silence. 

The IT Manager knows. The Compliance Officer knows. Senior management probably know and if they at least have a governance group established they will have had to approve those policies. 

But what about the person working in HR? 

The customer service adviser? 

The finance team? 

The marketing department? 

If they don’t know the policies exist, they certainly aren’t using them to help make everyday decisions. 

Even if staff know the policies are there, there’s another question to ask. 

“Do they actually understand them?” 

I’ve read policies that are beautifully written from a legal perspective, but if you handed them to the average employee, they’d struggle to explain what they actually mean in practice. 

Policies shouldn’t just explain organisational rules. They should help people understand what those rules mean for ‘their’ job. 

An HR manager doesn’t process data in the same way as someone working in Finance. 

A Marketing Manager faces different privacy risks from an IT Administrator. 

A receptionist handles personal information differently from a senior executive. 

So why do we expect one generic policy to answer everyone’s questions? 

Good policies don’t just tell people what they can’t do but they should explain what good looks like. This then helps staff understand how their behaviour can affect customers, colleagues and the organisation. 

Most importantly, they help people make better decisions when no one is standing beside them telling them what to do. 

This is where awareness and culture become just as important as documentation. 

As a Data Protection Officer, I’d much rather hear a member of staff confidently explain how they protect personal data in their daily role than know they’ve clicked “I have read the policy” during their annual training. 

Understanding leads to good behaviours and good behaviours reduce risk. 

And reduced risk helps protect both individuals and organisations. 

So here’s the question I’d leave you with. 

If I walked into your organisation tomorrow and stopped the first employee I met, could they answer these simple questions? 

“ What is your organisation’s Data Protection Policy trying to achieve?” 

“ How does it apply to your role?” 

“ What would you do if you spotted a data protection risk or made a mistake?” 

If the answer is “probably not”, then perhaps the issue isn’t your policies. 

Perhaps it’s how they’re communicated, understood and embedded across your organisation. 

Because compliance isn’t measured by the number of policies you have. 

It’s measured by how people behave every single day. 

Author – Irene Coyle, Data Protection Officer, OSP Cyber Academy

Shopping Basket