
Many organisations think GDPR compliance means having a privacy policy on their website and hoping they never hear from the Data Protection Commission. Alas, this is not the case.
During the first conversation with a client, I tend to ask a set of quite open questions; we later get to the specifics of Data Protection Impact Assessments, Privacy Notices and so on. But If I were assessing whether a business had thought seriously about GDPR, these are five general questions I would expect it to be able to answer.
1. What Personal Data Do We Actually Hold?
You cannot manage information you don’t know you have. Every business should understand what categories of personal data it collects about customers, employees, suppliers and other individuals. That doesn’t mean memorising every database or spreadsheet. It means knowing what information exists, where it is stored, and who within the organisation is responsible for it. Without that basic understanding, complying with GDPR becomes much more difficult. We’re going to have to put all of this into a Register of Processing Activities, once it is formalised. But the first step is to simply know about it.
2. Why Are We Collecting It?
This is probably the most important question of all because every category of personal data should have a clear purpose. If an organisation cannot explain why it is collecting certain information, it should urgently ask whether it needs to collect it at all. Purpose drives almost every other GDPR obligation, from deciding whether CCTV is justified to determining appropriate retention periods and responding to Subject Access Requests. If the purpose is unclear, the compliance position is usually muddy at best.
3. How Long Do We Need to Keep It?
One of the most common mistakes businesses make is keeping information indefinitely because storage is cheap. Unfortunately, the cost of data storage is rarely the real issue. The real cost appears later, when an organisation experiences a data breach, receives a Subject Access Request, or has to explain its retention practices to the regulator.
Good retention policies reduce both legal risk and administrative cost.
They also make organisations more efficient by ensuring they are not managing large volumes of information that no longer serve any legitimate business purpose. These policies don’t come from the nature of the media or the document – there isn’t a set retention period for CCTV, or for emails. Instead, it comes from understanding the answer to the previous question. If we know why we’re collecting and holding data, we can clearly identify the moment when we don’t need it for that purpose any more.
4. What Happens If We Discover a Data Breach Tomorrow?
Few businesses seem to know there is a 72-hour reporting deadline under the GDPR. Fewer have thought about what actually happens inside the organisation during those first hours. Who needs to be told? Who assesses the breach? Who decides whether the Data Protection Commission must be notified?
If those questions have not been answered in advance, valuable time can be lost while people try to work out who is responsible. Good governance means having a process in place before something goes wrong, not trying to design one in the middle of a crisis.
5. Could We Explain Our Decisions to the Data Protection Commission?
This is the question that ties everything together. If your organisation receives a letter from the Data Protection Commission asking why your business installed CCTV, retained certain records, or processed particular categories of personal data, could you explain your reasoning? Could you demonstrate that someone considered the risks, weighed the alternatives and documented the decision?
Absolute perfection in making decisions is not always possible, particularly where businesses have to balance competing interests. But thoughtful decisions usually are possible. Regulators expect organisations to think carefully about the choices they make and to be able to explain how those decisions were reached.
Good GDPR Is About Good Governance
Good GDPR compliance comes from understanding why information is collected, limiting what is retained, planning ahead for problems, and being able to explain the decisions that have been made.
The businesses that find GDPR easiest are rarely those with the largest legal departments. It’s usually the ones that understand their own information best. So organisations that can answer these five questions confidently generally have a good foundation upon which they can build a culture of good data governance.

