Welcome to a Data Protection Officer’s Desk

“So, what do you do, Sofia?” – I work in data protection compliance, I answer, and see their face become a puzzle. No more of that: here is what I do on an average day.

6:30am

@jckbck on Unsplash

I am awake but not yet working. My brain has already started thinking about what a colleague asked me yesterday. If I am still pondering it, it usually means it was a technical question with a UK GDPR angle. I have made an educated guess what the answer is and I know part of my day will be understanding the technology behind it. I am both excited at the learning opportunity and anxious how complex software architecture can get for someone outside that area.

7am

Drinking coffee I needed 29 minutes ago.

8am

I scan my inbox and look out for urgent emails. Depending on what the organisation does, “urgent” could mean:

  • an individual / client’s complaint;

  • personal data breach (someone used CC instead of BCC);

  • subject access request from an ex-employee;

  • ICO case officer looking for you;

  • a senior member of the team wants an answer now (i.e, yesterday).

If all is calm on the DPO front, I have the freedom to decide what to put on my to-do list. I start with the harder tasks that require more brain energy while I’m still fresh. I also open up news articles I will read that day in separate tabs. I can’t say I recommend this, it easily gets out of control.

8:30am

I decide to just ask my IT colleague to explain their engineering choices in lay(wo)man’s terms, so I can decide what this means for data protection compliance. It turns out it is not that complicated and I give the answer they need then and there.

9am

The hard task of today is to analyse a new project from a UK GDPR and general privacy perspective. I have been through all lawful bases the client / organisation can rely on for this project, so I will complete a legitimate interest assessment to show the data use furthers business needs without disadvantaging people. I chat a lot to myself in my head.

9:30am

Coffee, black.

@sigmund on Unsplash

11am

I need to speak to a colleague to sense check my logic.

11:45am

I never make it to or past 12pm for lunch.

12:30pm

By the afternoon, people have emailed me with various questions so I reply to them as quickly as possible. I don’t bore them with which section of the law applies, but do note it myself in case it comes up. I like having references.

1:30pm

Looking at the ICO Accountability framework to remind myself what I need to do in the background. I like writing policies and thinking about training; I get to be a little bit creative in what is usually a very dry subject.

2pm

Reading data processing agreements and other contracts.

4pm

It’s time for the news in the tabs I opened in the morning. I wind down for the day reading about recent developments and ultimately find myself more tasks to do.

I enjoy most days of work, which I am grateful for. People think data protection compliance is boring but in practice it is part of most if not all businesses process, so I get to speak to many people of various seniorities, different teams, learn what they do, how, and why. On the good days, I give them an answer that they can use on a daily basis; on the best days, I give them a tangible solution. That’s a tick in my book.

This blog post was inspired by Jess Pembroke.

Previous
Previous

In Defence of Web Analytics Cookies