top of page

What is a data protection programme?


In our blogs and when talking to clients we often refer to a “data protection programme”, but we realise you may be wondering what we mean by this…

Data protection programme

To comply with your various obligations under data protection laws there are a number of things that you must have in place.

As explained in our blog “Bloody Data Protection! A risk-based approach” there is no “one size fits all” approach to data protection – meaning that there is also no standard document stack.

But there are various things which all businesses will need to have in place to ensure data protection compliance – although the content and extent of each will vary depending on the business and the data it processes.

What this involves:

This will include:

  1. Data flows – see “Bloody Data Protection! Where to I start?”

  2. Risk assessment – see “Bloody Data Protection! A risk-based approach”

  3. Staff training

  4. Internal documents such as:

  5. Board decisions

  6. Policies (e.g. risk management policy, records management and retention policy)

  7. Procedures (e.g. dealing with data subject requests, data breach procedure)

  8. Templates (e.g. responses to data subjects, data protection impact assessment)

  9. External documents such as:

    • privacy policy

    • contracts with suppliers.

So when we use the term “data protection programme” it is all of these things together that we mean!

We have strategic and operational DPO experience of delivering programmes so get in touch if you need help creating and/or implementing a data protection programme within your business. Email or call 01202 729444.

bottom of page