You are the privacy team. There may be no complete inventory, no dedicated budget and no agreed intake route—only contracts, product questions, incidents and requests arriving from different directions. The temptation is to begin by writing policies. Resist it until you understand which processes, people and decisions those policies need to govern.
The first-quarter goal is not completeness. It is a defensible view of risk, a survivable incident process and a repeatable way for work to reach you.
Before day one: define the mandate
Clarify who sponsors the role, what authority it has, whether it is acting as a statutory or formal DPO, which entities and jurisdictions are in scope, and what independence or reporting arrangements apply. Do not accept personal accountability for controls owned by the business, security, HR, product or procurement.
- Which decisions you advise on, approve, escalate or only monitor.
- How material risks and overdue actions reach leadership.
- What capacity, budget and specialist support are available for incidents or high-risk matters.
Days 1–30: listen, map and triage
Meet the leaders and operators who touch personal data. Ask each what the function does, which systems and vendors it relies on, where data comes from and goes, what causes complaints, which deadlines worry them and what changes are planned.
| Workstream | Action | Output by day 30 |
|---|---|---|
| Mandate and governance | Confirm scope, sponsor, reporting line, decision rights and escalation. | One-page charter and sponsor cadence |
| Stakeholders | Meet security, legal, HR, product, marketing, procurement, IT, audit and customer operations. | Stakeholder map with owners and concerns |
| Applicability | Map entities, people, locations, sectors and services to likely regimes. | Applicability register with assumptions |
| Processing | Build a minimum RoPA from real process walkthroughs and existing evidence. | Initial activity inventory with known gaps |
| Existing controls | Collect notices, contracts, request logs, incidents, training and assessments. | Control and document inventory |
| Risk | Capture urgent exposures, deadlines and upcoming change. | Prioritised privacy risk register |
Use evidence, not interviews alone
Compare conversations with vendor spend, SSO applications, cloud inventories, website tags, contracts, incident records and rights-request history. Mark uncertainty openly. An incomplete record labelled as incomplete is more useful than a polished register built on guesses.
Triage by consequence and urgency
| Priority | Typical trigger | Response |
|---|---|---|
| Immediate | Live incident, regulator deadline, rights request nearing expiry, unlawful collection or active high-risk launch. | Escalate, assign owner, record decision and work to the deadline. |
| High | Sensitive or large-scale processing, children, monitoring, weak vendor terms, missing transfer route or no incident capability. | Assess within the quarter and agree treatment dates. |
| Medium | Control exists but is inconsistent, manual or weakly evidenced. | Standardise through the operating plan. |
| Foundational | Policy refresh, taxonomy cleanup or optimisation with no immediate exposure. | Schedule after urgent and high-risk gaps. |
Record why an item received its priority, who owns the underlying process and what would change the rating. Privacy should coordinate and challenge; the business owner should own the treatment.
Days 31–60: make the worst day survivable
Prioritise minimum viable controls for events that become complaints, losses or missed deadlines quickly. Three commonly deserve early attention: incidents, individual rights and high-risk vendors or changes.
| Control | Minimum viable state | Evidence |
|---|---|---|
| Incident response | Named team and deputies, clocks matrix, decision log and notification templates. | Approved playbook and tabletop action log |
| Rights requests | One intake route, identity checks, tracker, search owners, response templates and escalation. | Case register and tested workflow |
| Vendor intake | Risk questions, processing roles, data, countries, security, sub-processors and contract route. | Completed assessments for highest-risk vendors |
| High-risk change | DPIA screening embedded in product, procurement and architecture intake. | Screening decisions and linked assessments |
| Transparency and consent | Current notices mapped to processing; optional consent controls tested. | Versioned notice and interface evidence |
| Retention | Priority rules mapped to systems, owners, holds and deletion mechanisms. | Rule specifications and first execution sample |
Run a realistic exercise
Do not declare a process operational because a document exists. Run one incident tabletop and one rights-request simulation using the people, systems and clock that would apply. Record failures and assign fixes.
Days 61–90: build the operating rhythm
Move from individual heroics to predictable routes and recurring decisions. Privacy questions should enter through procurement, change, incident and request processes rather than depending on colleagues remembering to contact you.
| Cadence | Purpose | Participants or output |
|---|---|---|
| Weekly intake review | Triage new requests, changes, vendors, incidents and deadlines. | Privacy, legal, security and relevant owners |
| Monthly risk review | Review high risks, overdue actions, exceptions and decisions required. | Sponsor and accountable business owners |
| Monthly champions call | Share changes, surface issues and reinforce local ownership. | Named privacy contacts in major functions |
| Quarterly programme review | Assess metrics, capacity, roadmap and material changes. | Leadership report and approved priorities |
| Annual plan | Sequence assessments, training, assurance and control improvements. | Funded roadmap with explicit exclusions |
What good looks like at day 90
- A written mandate, sponsor cadence and escalation route.
- An applicability map and minimum RoPA with owners and known gaps.
- A risk register separating urgent, high, medium and foundational work.
- Incident and rights-request workflows tested at least once.
- A risk-based vendor and change intake process.
- A small set of agreed metrics and an executive report.
- A 12-month roadmap showing priorities, dependencies, capacity and deferred work.
- A decision log recording advice, approvals, exceptions and risk acceptance.
Measure control, not activity volume
| Measure | What it reveals |
|---|---|
| Requests by type, age and deadline status | Demand, bottlenecks and missed-service risk |
| High risks without owner or due date | Governance and accountability gaps |
| New vendors or changes screened before approval | Whether privacy is embedded upstream |
| Overdue DPIA, contract and remediation actions | Where advice is not converting into control |
| Processing activities with owner and review date | Inventory quality and accountability |
| Exercise findings closed on time | Whether testing produces improvement |
Avoid celebrating the number of policies written, assessments opened or training invitations sent. Measure whether high-risk work is identified early, owned, completed and evidenced.
Protect capacity and independence
A team of one cannot attend every meeting or personally operate every control. Publish intake criteria, standard response times and escalation rules. Use templates for repeatable advice, office hours for lower-risk questions and external support for incidents, complex transfers, investigations or specialist assessments.
- Keep one visible backlog with priority, owner and deadline.
- Separate advisory responsibility from business control ownership.
- Record decisions so settled questions are not repeatedly reopened.
- Escalate when capacity creates a material compliance risk.
- Build a peer network and identify trusted specialist support before an emergency.
- Schedule focused work and recovery time after incidents or intense deadlines.
Common first-quarter mistakes
- Writing a complete policy suite before understanding the business.
- Accepting ownership for security, HR, product or vendor controls.
- Building a perfect RoPA from interviews without reconciling systems and spend.
- Trying to fix every gap rather than documenting prioritisation.
- Reporting activity counts without explaining risk or decisions required.
- Allowing urgent work to erase the roadmap every week.
- Waiting for a real incident to test escalation and notification.
References and scope
- Regulation (EU) 2016/679 (GDPR), including Articles 30, 33 and 37–39 where applicable.
- Digital Personal Data Protection Act, 2023 (India), including duties, rights and Significant Data Fiduciary requirements where applicable.
General information for practitioners, not legal advice or a universal role description. Responsibilities depend on applicable law, formal appointment, organisational structure, sector and risk. Confirm the mandate and obtain qualified advice where required.