One of the main reasons programmes that involve personal data become delayed or go over budget is because there hasn’t been proper planning for handling personal data as part of the programme design. Often, organisations will plan their timelines around technical or organisational changes. But, they will not necessarily consider how to handle the personal data their programme must also cover.

This causes problems because statutory requirements like data protection impact assessments are often done whilst the programme is ongoing. This can be a blocker to technical or organisational change, as these must be approved and recorded before progress can be made. At an extreme if something like A DPIA is not approved, the whole programme could be in trouble.
The GDPR itself recognises this challenge. It encourages organisations to put personal data in the front at the front and centre of their thinking by introducing the concept of privacy by default and privacy by design
Privacy by Default and By Design
- The GDPR expect organisations to put in place appropriate organisational and technical measures to manage and protect personal data at the design stage
- Data protection must also be a factor in building and implementing new systems and processes
- It helps reduce future costs and the risks of a data breach
This means personal data should be at the core of the design stage alongside planning for budgets timelines and other factors that are critical to programme success
Examples of Programmes
Examples of these kinds of programmes include:
- transferring personal data to a new IT system or processing platform
- when employees being TUPEd over to a new organisation in large numbers
- a large scale data sharing partnership is being entered into with another organisation
It also means the programmes you to think carefully about the kind of discovery they need to undertake in order to find out what personal data may be involved in the programme that they’re delivering. For example it is not enough to say does this data set contain personal data. You should be much more granular at the planning stage and explore whether that personal data actually contains personal identifiers whether the GDPR actually applies. For example, the data set could only include the data of people who are deceased and whether there are any sensitivities around personal data such as data relating to health or criminal convictions
Even if datasets turn out to not to contain GDPR regulated or personal data assurance needs to be done confirming that this is correct before the programme can move on to the final stages of delivery. Another thing that needs to be understood is data flows or what point is personal data come into the organisation how long is it retained who has access to it what are the appropriate security measures
Some Key Questions
Finally you need to understand what framework the personal data is being captured and processed through. For example
- Who is the data controller and who is the data processor?
- Is there a contract or data sharing agreement in place?
- What’s the lawful basis for the data processing is it consent or is it for a statutory function
When delivering your programme you may also wish to consider factors that may not seem immediately relevant to the delivery of the programme itself. These include updating privacy information and your record of processing activity
Without considering these factors at the programme design stage you risk reaching the GDPR or causing unnecessary reputational risk to your organisation. You may also risk the programme going overtime or over budget or creating a need for scope change whilst the programme is ongoing.
Key risks
- Not fully understanding the personal data your programme encompasses until programme delivery is advanced, causing delays and extra costs
- Being unable to provide proper assurance that the programme is maintaining appropriate technical and organisational security measures during the programme and post-delivery
- A lack of trust or confidence among stakeholders (including data subjects) that the programme is capable of delivering
Sign Up Here:
Getting this right means bringing in appropriate subject matter expertise at the very start of programme planning. They will help you develop an appropriate checklist or milestones for delivery and success for any transfer of personal data or any programme that involves the processing of personal data. Remember, regulators like the Information Commissioner will take into account the level of data protection by design you have implemented if there is ever a complaint or a data breach.
Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.
Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: