Published On: September 17th, 2024/Categories: The GDPR Guy/17.5 min read/

#24 – It’s time to kill the privacy champion

Connecting with your audience as a compliance person can be tough, so we have the privacy champion model to save the day. Or so you’d think. In this episode I explain why privacy champions fail and what we should do instead to get the organisation engaged with privacy and loving you.

Audio

Transcript

Hello and welcome to the GDPR Guy. I’m Carl Gottlieb, your host and resident privacy advisor.

Today I want to talk about champions. Specifically privacy champions, but most of what I’ll say can be applied to other champions too. And what do I mean by champions? Well, the idea is you have these little ambassadors dotted around the organisation to represent your function and do some of your dirty work. Sounds a bit weird, right?

So let’s go back to the beginning and talk about where this comes from.

We can all agree that company wide initiatives such as security, privacy and compliance are challenging, particularly because you’ve got dedicated teams or individuals trying to get everyone else in the organisation to act a certain way. It’s not like when you’ve got the Finance manager telling the Finance team how to do their sums, or the Marketing manager telling the Marketing team which crayons they should use. You’ve got Mrs Security and Mr Privacy telling the whole company how to be safe with data. And that creates some weird dynamics and some challenging problems.

Firstly, on the dynamics, you’ve got someone from outside your team telling YOU how to do your job. You’ve just joined the HR department as an internal recruiter, and you’re responsible for reviewing CVs and resumes sent to you by random candidates, and in walks Mr Privacy telling you not to open attachments from people you don’t know. Now aside from wanting to punch them in the face, you’re left confused and resenting what sounds like stupid advice getting in the way of you doing your job. And who is this person? And why the hell is this DPO telling me what to do with my data, and what the hell is a DPO anyway?

Having people from outside your team telling YOU how to do your job can feel weird.

Likewise, for the security or privacy person, getting your message across to all and sundry can be incredibly challenging. You’ve got some important advice to give to everyone but how do you tailor it to each audience member? How do you say it in their language that resonates with them? How do you get them on your side? And who are these people you need to connect to? Where are they? What language do they speak? And how do you know you’ve got to everyone?

Being a central compliance person that needs to get out to everyone in the company is tough.

And this is where privacy champions come into play.

The theory is that rather than you having to get to everyone, you create a web of ambassadorial champions that spread the good word of privacy out to their respective team. For instance you’d have someone in the Marketing team who is formally designated as the Marketing Privacy Champion and you would empower them with some of your tasks, such as educating team members on privacy and reporting privacy issues back up the chain. You have your club of privacy champions spread across the organisation. You work with them, they work with their team. Everyone’s happy. Problem solved.

Or so you’d think.

The problem is it doesn’t work.

It should, but it doesn’t.

The main issue with the champion model is that it creates more work. More work for you as a privacy leader and more work for the champion. Assuming you can get someone to become a champion, which is a fairly big assumption, you’ve got to keep them empowered, motivated, on track and ultimately delivering as your local delegate. But people have jobs to do. Marketing has marketing to do, and like it or not, delivering on their own work will always trump helping with yours. You’ve basically given them more work with more responsibilities but with no reward. Nobody is getting paid more to be a privacy champion, that’s for sure.

Privacy will never be their priority and neither should it be, so it will always get deprioritised in favour of other work, leading to gaps. And gaps are precisely the thing you’re trying to avoid. And worse, because you’re now reliant on this model of relaying information back and forth, you’ve lost any connection to all the people on the ground that the champion was meant to handle.

When the engagement drops even the slightest bit, their privacy expertise starts to get diluted so you end up with champions on paper, but not really champions at all. They just become conduits at best and at worst become bottlenecks. And on top of that, you eventually get staff turnover, meaning your champion has now left the business and you’ve got to start onboarding someone else.

All of this means you’re now having to actively manage these champions to get the best results, which is yet another drain on your time.

In my view the biggest problem champions create is a cultural one. It does the exact opposite of what you’d expect, in that you’d planned on champions creating a culture of compliance, but instead, you just created a big virtual privacy team with no compliance culture on the ground, because everyone’s interface with compliance is so diluted.

I’ve seen this play out numerous times, especially in Marketing teams where they have a great demand for privacy input. You’ll often have a team leader, probably someone in Marketing Operations that becomes the privacy champion. They’re full of enthusiasm as they create a spreadsheet of country by country email marketing rules for their team to follow. They run a zoom call with their team to train them on it. Then silence.

It’s like a light being switched off. They met their immediate privacy need, and now they’re back to focusing on their day job and have seemingly lost all interest in keeping the compliance momentum going. And next thing you know, your champion has got another job elsewhere and you’re facing the prospect of repeating the process once more.

Privacy champions sounds like a great model in theory but it usually just fails a slow and silent death. And that’s why we need to kill the privacy champions now. We need a different model that actually works.

And as with most things in life, the simple solution is usually the right one.

The one model that I see work every time, because people genuinely like it, is direct engagement. Yes, actually speaking directly to the people that matter. Revolutionary, I know.

Now you’d think that this can’t scale, and would fail in all organisations but the smallest of size. But you’d be wrong.

You as a compliance person need to be speaking directly with everyone on the ground. This doesn’t have to actually be one-to-one, but it has to feel one-to-one for the person you’re speaking to.

I have a particular client whose CEO does this every single week to the whole company. And they’re a public company so they’re all pretty busy. But the CEO is there every single week in the office auditorium, and on zoom, taking live Q&A on literally any topic, from anyone in the company, and engaging back with them directly. He’s removing any barrier between you and the CEO, ensuring you get to hear directly, from him, the complete, accurate, and unvarnished truth, and you’ve got the freedom to engage as you want.

And us compliance folk need to do the same.

The office hours model works amazingly well if you get it right. So if you can do anything I’d do this. Find a window in your diary that you can commit to every week. Maybe even twice a week depending on the size, need and time zone requirements of your company. Create a booking slot in that window, and then have an open session that anyone in the company can book into and join. It needs to be a safe zone where anything can be discussed, and the more I think about it, the smaller and more insignificant the topic the better. You want it so that as soon as people have the tiniest thought about privacy, the tiniest idea or question about a future plan for data, they think of booking in to freely chat about it with the privacy person.

That’s how you get those product and engineering folk at the super early stages because there’s no process. No procedure or gate in the software development lifecycle that tells them to fill in a DPIA or some other risk assessment. All they need to think about, is to just go and chat with the experts. And this works perfectly for legal and security teams too.

People hate procedure and forms. And they love free advice from experts without judgement. And people love to talk. They love another person listening to their ideas and grand plans. People want validation. And that’s why people like coming to office hours sessions.

The other neat thing is when slots overlap, and one person is sat there waiting for their turn, and as a result ends up listening to their colleagues talk with privacy. You get loads of benefits from this, such as cross pollination of knowledge as they learn what their peers are doing. And they see first hand how well their colleague was helped by Privacy, so they feel positive that their experience will be the same. It’s self reinforcing. It’s an incredibly positive vibe experience, leading to people wanting to come back for more.

So much so that I often see the same people coming back week after week because they want to chat about something new, that really a slack message would have sorted, but they just want that direct engagement.

Humans want relationships with humans. We crave that direct engagement.

Extending this out into the learning and development world, or “training” as you and I would know it, annual compliance training is kind of the easy bit. But ongoing awareness – that stuff in between to maintain staff knowledge, that can be the hard part. And once more, that’s where direct engagement is the most effective technique. Don’t tell me that posters around the office do that much, other than ticking a box to say you’ve done some more awareness stuff this month. But you getting into the Finance team’s weekly meeting to talk directly, is going to bolster that human relationship. It’s going to move you from being a name or maybe even just a job title, to becoming a colleague that is real, is an actual human, is trustworthy and most importantly is friendly for them to want to work with.

You’re no longer the DPO. You’re Carl.

Regarding the office hours model, if you’re a Google Workspace house then ideally use the Google appointments feature of Google Calendar. Microsoft 365 has this with Microsoft Bookings or you can use dedicated pieces of software like Calendly. Maybe start with an hour window with four separate 15 minute bookable slots for people to book.

And the neat thing is you can add your privacy colleagues as fellow hosts, so that they can take the session if you can’t. And the booking software can manage sessions around your existing calendar so there are no clashes.

And if you want to get really fancy, change your DPIA or PIA process so that instead of people having to fill in any forms themselves, they do it during the office hours session with you alongside.

Direct engagement takes pain and procedure away from your colleagues and moves compliance from process to conversation. And selfishly, as a compliance person you look like a rockstar consultant as people wheel in, get fixed, and disappear off to tell their colleagues how great the experience was.

What’s not to love?

It’s time to kill the privacy champion and get engaging.

Thanks for listening.

More Episodes of The GDPR Guy

 

Share This Post!

About the Author: Carl Gottlieb
Carl Gottlieb
I'm the trusted privacy advisor to leading tech companies, helping them gain maximum advantage through the right privacy strategy. My consultancy company Cognition provides a range of privacy and security services including Data Protection Officers, in-depth assessments and virtual security engineers. Get in touch if you'd like to learn more.

Related articles