Making GDPR Decisions You Can Defend (and When to Get a Second Opinion)

Sometimes the GDPR can appear unclear or that it doesn’t give you a straight answer to the question you have. Below is a practical guide how you can make defensible data protection decisions in the face of uncertainty.

@markuswinkler on Unsplash

Why the GDPR Can Cause Uncertainty

The GDPR is a law, and laws have to be clear and understandable.

However, the GDPR is a law that is principles-based, not rules-based. This means practitioners know the destination but the route isn’t set.

In other words, you know that you should, for example, only use the minimum data necessary for your purpose, but the law does not tell you how much is too much or too little – you have to decide that considering your organisation and environment.

This “freedom” leaves room for interpretation. Where there is interpretation, there is always room for disagreement and uncertainty, too.

Of course, the GDPR (and the UK Data Protection Act 2018 if you’re in the UK) is supported by industry and regulatory guidance, namely to help with this interpretation. This is ideally backed by case law and enforcement decisions, and / or, I’d like to say, with the opinion of experienced practitioners who have seen the law in play for many years.

Another factor affects the UK GDPR specifically is that some of the key tests for "doing it right" — proportionality, for example — are EU law concepts that the UK has simply absorbed into its own regime. So what counts as proportionate isn't black or white. It flexes, sometimes considerably, across industries and technologies.

All of this does not mean to say that if you’re uncertain or don’t have a clear-cut answer, you’re doing it wrong. But you do need to be able to explain why you made the decision you did.

Finding GDPR Answers

Today, my educated guess is that most people, whether they have a specialist in-house or not, ask large language models like ChatGPT, Claude, etc. first when the GDPR is unclear.

AI tools have replaced our previous favourite, the search engines, because even when you Google something, you still need to do some research, compile a few resources and make up your mind. An AI tool does this for you and hands you an answer… but could you defend it?

People who are worried about defensibility and accuracy can review:

  • The law itself – read, re-read the GDPR, and every time there is a reference to [national law], find the exact reference in your data protection national law. Do not skip this step.

  • Regulator guidance — authoritative but often general, slow to update, and not tailored to specific use cases (if I think about UK guidance). I find it gives you more direction but still not the answer unless the question is still fairly simple.

  • Industry peers and forums — useful for pattern-matching and a quick sense-check ("how is everyone else handling this?") but risky if treated as compliance proof. This is helpful for experienced data protection practitioners, but even if you rely on this, you still need something to back the peer opinion up.

  • Internal DPOs or privacy leads — responsible DPOs know they don't know everything, so they'll go and find the best resource rather than guess.

  • Specialist privacy consultants — recommended if you don’t have anyone in-house but want a practical, operational judgement calls.

  • External legal counsel — go-to for high-stakes or litigation-risk decisions, not “general” data protection questions per se.

What a GDPR Second Opinion Actually Means

I have seen people make data protection calls when they are not sure of the answer anyway because they are not GDPR practitioners.

I dare say this is wrong because data protection compliance is like any other compliance – for example, you wouldn’t make an important financial decision without asking specialist, so your thinking about the GDPR should be the same.

If you are the data protection practitioner, asking for a help doesn’t make you less capable. I always say there are no silly questions, just things that you don’t know yet.

So when you are getting a second opinion, bear in mind that:

  • It's not about getting "permission" to do anything. You will still have to weigh up all arguments.

  • A second opinion is evidence of reasonable judgement — it shows you took the question seriously and sought informed input.

  • It matters most for the process, not just the outcome — how a decision was reached is important if someone looks at the outcome.

  • It can come from a person (lawyer, DPO, consultant) or a structured process (documented risk assessment, DPIA review). I always rely on something documented because you can show your work and thought process.

  • It's particularly valuable when a decision is novel, high-risk, or likely to be scrutinised later.

  • A second opinion doesn't eliminate risk — it demonstrates accountability, which is what GDPR actually requires.

When You Should Get a Second Opinion on a GDPR Decision

Checking your work is not a bad thing. Paying someone to give you specialist and practical advice is money well spent; it’s peace of mind.

Where I see it being particularly relevant is if:

  • The decision involves a new or unusual use of data (new tech, new data type, new purpose).

  • The potential impact on individuals is significant — special category data, vulnerable groups, large-scale processing.

  • Internal opinions are genuinely split, or no one feels confident enough to sign off.

  • The decision could attract regulatory attention or public scrutiny if challenged.

  • You're relying on a novel interpretation of legitimate interest, consent, or a derogation.

  • The cost of being wrong (fines, reputational damage, loss of trust) clearly outweighs the cost of asking.

The bar can be much lower if you’re not a specialist and need external help – then you might just want it dealt with and away from your desk, which is also a very valid reason to get a second (or a first) opinion.

A Framework for Making GDPR Decisions You Can Defend

I have two law degrees so am very dependent on what the law says. If I can’t reference everything I say with a section of a law (ideally also industry guidance), I do not say it.

If the law doesn’t quite say it but guidance does, I will make that point and allow myself to make a decision but will flag what the theory says, or doesn’t, for that matter.

You want to be able to pin point exactly where your decision came from. This is the problem with AI research and tools – you may have the general resource but can you point to the exact paragraph? If I want to quote a judge, I don’t rely on their quote until I have personally found the paragraph where they have said what I want to rely on. This is the precision you should work with.

Other general tips include:

  • Define the question precisely. Vague problems get vague (indefensible) answers.

  • Identify the relevant legal basis or principle. Name what you're relying on, not "this should do”.

  • Document your reasoning at the time, not retrospectively; contemporaneous notes carry far more weight.

  • Assess proportionality and risk to individuals, not just risk to the organisation.

  • Record what you considered and rejected, and why. This shows genuine deliberation.

  • Set a review trigger. Note when this decision should be revisited (new use case, new data type, regulatory update).

You can use industry templates, checklist and software to record all of this.

What Good GDPR Advice Actually Looks Like

I accept this may look different to different practitioners; however, what I think good GDPR advice looks like is a bit like what I think a good legal analysis looks like:

  • State the question you need answering and explain what you’re going to consider to answer it.

  • Lay out the GDPR principles and rules that are at play and how they may affect the problem you’re out to solve.

  • Be objective and critical of your own thoughts – “on the one hand, answer A seems plausible… however, answer B would mean that… so based on our organisation / risk / reputation, we think answer C is actually the best… because Article X supports this best.”

  • Good advice is specific to your facts, not a generic restatement of the regulation.

  • It comes with reasoning you could show a regulator, not just a yes/no answer.

  • It distinguishes between legal risk and commercial risk, and is honest about both.

  • It tells you what you can't be sure of, not just what you can

Good advisors help you build a defensible position, not just a compliant-sounding one. Any advice is “just” advice, which can be followed or ignored. Whichever one is chosen, both the person giving and signing it off should be confident to put their name to it, knowing that it’s sound.

Previous
Previous

Good Faith and Respect for the GDPR are not a Lawful Basis

Next
Next

Baby Sleep Consultants Are Responsible for Vulnerable Families and Their Data