Welcome to a Data Protection Officer’s Desk
“So, what do you do, Sofia?” – I work in data protection compliance, I answer, and see their face become a puzzle. No more of that: here is what I do on an average day.
6:30am
@jckbck on Unsplash
I am awake but not yet working. My brain has already started thinking about what a colleague asked me yesterday. If I am still pondering it, it usually means it was a technical question with a UK GDPR angle. I have made an educated guess what the answer is and I know part of my day will be understanding the technology behind it. I am both excited at the learning opportunity and anxious how complex software architecture can get for someone outside that area.
7am
Drinking coffee I needed 29 minutes ago.
8am
I scan my inbox and look out for urgent emails. Depending on what the organisation does, “urgent” could mean:
an individual / client’s complaint;
personal data breach (someone used CC instead of BCC);
subject access request from an ex-employee;
ICO case officer looking for you;
a senior member of the team wants an answer now (i.e, yesterday).
If all is calm on the DPO front, I have the freedom to decide what to put on my to-do list. I start with the harder tasks that require more brain energy while I’m still fresh. I also open up news articles I will read that day in separate tabs. I can’t say I recommend this, it easily gets out of control.
8:30am
I decide to just ask my IT colleague to explain their engineering choices in lay(wo)man’s terms, so I can decide what this means for data protection compliance. It turns out it is not that complicated and I give the answer they need then and there.
9am
The hard task of today is to analyse a new project from a UK GDPR and general privacy perspective. I have been through all lawful bases the client / organisation can rely on for this project, so I will complete a legitimate interest assessment to show the data use furthers business needs without disadvantaging people. I chat a lot to myself in my head.
9:30am
Coffee, black.
@sigmund on Unsplash
11am
I need to speak to a colleague to sense check my logic.
11:45am
I never make it to or past 12pm for lunch.
12:30pm
By the afternoon, people have emailed me with various questions so I reply to them as quickly as possible. I don’t bore them with which section of the law applies, but do note it myself in case it comes up. I like having references.
1:30pm
Looking at the ICO Accountability framework to remind myself what I need to do in the background. I like writing policies and thinking about training; I get to be a little bit creative in what is usually a very dry subject.
2pm
Reading data processing agreements and other contracts.
4pm
It’s time for the news in the tabs I opened in the morning. I wind down for the day reading about recent developments and ultimately find myself more tasks to do.
I enjoy most days of work, which I am grateful for. People think data protection compliance is boring but in practice it is part of most if not all businesses process, so I get to speak to many people of various seniorities, different teams, learn what they do, how, and why. On the good days, I give them an answer that they can use on a daily basis; on the best days, I give them a tangible solution. That’s a tick in my book.
This blog post was inspired by Jess Pembroke.