GDPR as Governance Reset: Why a Compliance Deadline Exposed Every Broken Process We Owned

Essay·Giovanni Leonardi·August 2018·15 min read

The regulation did not reform our data governance; it simply removed our permission to keep pretending we had any.

Executive Summary

Twenty-fifth of May came and went. The inboxes emptied of re-consent pleas, the countdown clocks were unplugged, and a great many organisations quietly told themselves the hard part was over. It was not. The deadline was never the point. What the preparation for it exposed — in the months of frantic data mapping, the awkward conversations about lawful basis, the discovery that nobody could actually say where personal data lived or why — was the true state of our governance. And the true state, for most of us, was worse than we had been willing to admit.

This essay argues that the General Data Protection Regulation has functioned less as a privacy law and more as a governance reset: an externally imposed diagnostic that forced organisations to confront the broken processes they had spent years routing around. The uncomfortable observation beneath it is that the regulation achieved in eighteen months what a decade of internal transformation programmes could not. It did so not because its drafters were wiser than our change directors, but because it carried two things no internal mandate ever has — a non-negotiable external deadline and a financial threat large enough to hold a board’s attention.

The reset is real, but it is not automatic. The same regulation that catalysed genuine reform in some organisations produced elaborate theatre in others: records of processing written once and never opened again, consent mechanisms redesigned to survive an audit rather than to mean anything. What separated the two was never the quality of the legal advice. It was whether the organisation treated the exercise as a compliance project to be closed or a governance opportunity to be kept open. We are, in August 2018, standing in the narrow window when that choice is still live. This is a reflection on what the reset exposed, why it took an outside force to expose it, and what is worth doing before the window closes.

The morning the mapping stopped being a formality

There is a particular moment that recurred across the readiness programmes of the past two years, and it is worth describing precisely because it is where the real story of GDPR begins. It is the morning, somewhere around the middle of the exercise, when the data mapping stops being a documentation formality and becomes an interrogation.

It usually arrives in a workshop that was scheduled for an hour and runs to three. Someone from the legal team has asked what should have been a simple question — where does customer data enter this process, and on what basis do we hold it — and the answers have started to unravel. The marketing function is running campaigns off a database that no current employee remembers commissioning. The customer records include people who last transacted eleven years ago, retained because deleting them was never anyone’s job. A revenue-reporting spreadsheet, emailed monthly, turns out to carry the personal details of several thousand individuals in a file with no owner, no access control, and no place in any system diagram. The room goes quiet, and the quiet is the sound of an organisation realising it does not know itself.

I have watched that quiet settle in more rooms than I can count, and it is always the same. It is not the silence of people who have done something wrong. It is the silence of people who have discovered that the map they have been navigating by bears little relation to the territory. The mapping exercise, sold internally as a box to be ticked before a deadline, does something the organisation had never before had a reason to do: it follows the data. And following the data means following the actual processes — not the ones in the procedure manuals, but the ones people really use — through every hand-off, every shadow spreadsheet, every quietly maintained workaround that keeps the business running. Every broken process the organisation had learned to live with is suddenly visible, because personal data flows through nearly all of them.

The regulation asked one question the organisation had never been forced to answer end to end: where does this data go, and why? The scramble to answer it was not a privacy exercise. It was the first honest audit of how the enterprise actually works.

This is the first thing GDPR exposed, and the most important. Not that we were non-compliant — that was never in doubt. That we were, in a specific and measurable sense, not in control of our own operations. The regulation did not reform our data governance; it simply removed our permission to keep pretending we had any.

Consent as the mirror

If the data mapping exposed the plumbing, the debate over lawful basis exposed something closer to the business model. This was the conversation that made GDPR uncomfortable in a way that spreadsheets never could.

For years, “consent” had been a comfortable word precisely because no one examined it. A pre-ticked box, a buried clause in a terms-of-service document, an assumption that continued use implied agreement — these had been treated as consent because it was convenient to treat them so. GDPR’s insistence that consent be freely given, specific, informed, and unambiguous did not introduce a new idea. It introduced a mirror. And in the mirror, a good many organisations saw that entire activities they depended on rested on permission they did not actually have.

Consider the marketing function that discovered, in the course of the readiness programme, that perhaps two-fifths of its addressable database could not be shown to have consented to anything in a way that would survive scrutiny. The instinctive response was to treat this as a legal problem — to find a lawful basis other than consent, to lean on legitimate interest, to re-paper the arrangement. Sometimes that was legitimate. Often it was the beginning of theatre. Because the real signal in that discovery was not legal at all. It was that a channel the business had reported as an asset was, in part, an illusion — a list of people who had never meaningfully agreed to be on it, counted for years as if they had.

The organisations that learned the most from GDPR were the ones that resisted the urge to make the mirror go away. They asked the harder question: if a large part of this list is not real, what else that we report as an asset is similarly hollow? That is not a compliance question. It is a governance question, and a strategic one, and it is exactly the sort of question internal transformation had spent years failing to force.

The deadline that did what strategy could not

Here we reach the reflection at the centre of this essay, and it is not a comfortable one for anyone who has spent a career inside change programmes.

Every organisation of any size has run initiatives to fix its data. Master data management programmes. Information governance frameworks. Data quality drives. Enterprise architecture efforts to document the systems landscape. Most of us have led or lived through several. And most of them, if we are honest, delivered a fraction of what they promised before quietly losing momentum, their steering committees thinning, their sponsors reassigned, their deliverables shelved. We know how to write a data governance policy. We have never been very good at making one stick.

GDPR made it stick — or came closer than anything before it — and the reasons why are worth sitting with, because they say something unflattering about how organisations actually change.

  • An internal data governance programme has a diffuse benefit and a concentrated cost. The people who must do the work — clean the records, document the flows, accept new constraints on how they use data — bear a real and immediate burden, while the benefit accrues to the organisation as a whole, later, and invisibly. This is the classic shape of a change that is always worth doing and never quite gets done.
  • GDPR inverted that arithmetic. It attached a concentrated, immediate, personally felt cost to not doing the work: a fine of up to four per cent of global annual turnover, a number large enough that it stopped being a matter for the information governance team and became a matter for the board and the audit committee. For the first time, the diffuse benefit had a sharp-edged, quantified downside standing behind it.
  • And it carried a fixed external deadline that no internal politics could move. A transformation programme’s milestones are negotiable; they slip, and everyone understands that they slip. The twenty-fifth of May did not slip. A deadline that cannot be moved concentrates effort in a way that an aspiration never can.

“We did not lack the knowledge to govern our data. We lacked a reason urgent enough to act on what we already knew. Brussels supplied the reason.”

This is the deeper force the Key Challenge points to, and it deserves to be named plainly. The gap between transformation intent and transformation reality is rarely a gap in knowledge. We generally know what good looks like. The gap is one of activation energy — the organisation cannot generate, from within, enough urgency to overcome the concentrated cost of change. An external regulation with a hard deadline and a board-level penalty is, in effect, a machine for manufacturing that urgency. That is an uncomfortable thing to admit, because it implies that our most effective transformation catalyst of the decade was not designed by any of us. It was imposed on us.

The theatre trap

I have argued that GDPR functioned as a governance reset, and I believe it. But an essay that only made that case would be a rigged one, because the most serious objection to it is not that it is wrong — it is that it was frequently, visibly, expensively not what happened. Honesty requires meeting that objection at its strongest.

The strongest version runs like this. GDPR was not a governance reset at all; it was a compliance tax. It consumed enormous quantities of transformation budget and senior attention, and in return it produced documents. Records of processing activities that were compiled at heroic effort and have not been opened since May. Data protection impact assessments completed as a formality. Privacy notices rewritten by lawyers to be legally watertight and humanly unreadable. Consent banners engineered to secure a click rather than to inform a choice. On this view, GDPR did not fix broken processes; it added a new layer of process on top of them, and called the layer governance. The mapping exercise found the mess, and then the organisation photographed the mess, filed the photograph, and left the mess exactly where it was.

This objection is not a straw man. It describes, accurately, what happened in a large share of organisations, and anyone who claims otherwise has not been paying attention. So the question is not whether the theatre was real. It was. The question is what separated the organisations that got a reset from the organisations that got a photograph of their own dysfunction.

The answer, in my observation, has almost nothing to do with the quality of legal advice and almost everything to do with who owned the exercise and what they were trying to achieve. Where GDPR was run as a legal remediation project — scoped to achieve defensible compliance by a date, then close — it produced compliance by that date, and then closed, and the mess stayed. Where it was run as a governance opportunity that happened to have a legal deadline attached, the deadline was used as leverage to do the thing the organisation had wanted to do for years and never could. Same regulation. Same records of processing. Entirely different outcome, determined not by the law but by the framing.

Run as a compliance project Run as a governance reset
Scoped to a defensible position by 25 May Scoped to a durable capability, with 25 May as leverage
Owned by legal and closed on completion Owned by the business and kept open
Records of processing as an audit artefact Records of processing as a living operating map
Success = no fine Success = the organisation finally knows how it works

The regulation, in other words, was necessary but not sufficient. It supplied the forcing function. It could not supply the intent. That had to come from inside — which returns us, awkwardly, to the same internal will that had been failing to act all along. GDPR did not remove the need for genuine transformation leadership. It created a rare moment in which such leadership could actually get traction. Whether that moment was seized or wasted was, and remains, a choice.

What the reset made visible that we should not let fade

The most valuable output of the whole exercise was not a compliant state. It was a picture — the first accurate, enterprise-wide picture many organisations had ever possessed of how their data, and therefore their operations, actually work. The tragedy of the theatre is not the wasted effort. It is that this picture, having been produced at great cost, is now being allowed to go stale.

Three things came into view during the readiness programmes that are worth holding onto deliberately, because nothing else in the normal run of operations will keep them visible.

  1. A true map of the data estate. For a brief moment, someone in the organisation could actually trace where personal data entered, where it flowed, where it rested, and where it left. That map decays the instant it stops being maintained. Kept alive, it is the foundation of nearly every data initiative the organisation will ever attempt — analytics, migration, rationalisation, security. Left to rot, it becomes another shelved artefact and the next programme starts the discovery again from scratch.
  1. A named owner for data. The requirement to appoint a data protection officer did something subtle and important: it created, often for the first time, a single person with an enterprise-wide remit over how data is handled. In many organisations the DPO is now the only individual who can see across the silos. That vantage point is precious and fragile. Treated as a compliance functionary, the role withers into a checker of boxes. Treated as the nucleus of data governance, it becomes the standing capability that every previous programme tried and failed to establish.
  1. A shared vocabulary for a hard subject. For the length of the readiness programme, the whole organisation — legal, marketing, technology, operations, the board — was forced to talk about data in the same terms at the same time. Lawful basis, data minimisation, purpose limitation, retention. These are not merely legal concepts; they are governance disciplines, and for once everyone had learned them together. That shared language is the cheapest thing to lose and the hardest to rebuild.

The instinct now, three months past the deadline, is to stand the programme down, thank the team, and return the borrowed people to their day jobs. That instinct is the theatre reasserting itself. The reset is only a reset if what it exposed stays exposed.

The uncomfortable lesson, and the open question

I want to end not with a recommendation but with the reflection the subject actually demands, because this is an essay and not a plan.

The lesson of GDPR, for those of us who lead transformation, is genuinely uncomfortable. It is that our organisations, left to their own devices, do not reform their foundations. They optimise around their broken processes, they route their people past the workarounds, they carry the hollow assets on the books, and they do this indefinitely, because the cost of confronting the mess is concentrated and immediate while the benefit of fixing it is diffuse and deferred. It took a regulation drafted in Brussels, with a hard deadline and a four-per-cent penalty, to generate enough activation energy to make us look. That should trouble anyone who believes transformation ought to be led from within.

And yet the more hopeful reading is available too, and I hold it alongside the uncomfortable one rather than in place of it. GDPR proved that the reset is possible — that these organisations, so resistant to internal change, can in fact confront their broken foundations when the conditions are right. The conditions were an external deadline, a board-level financial stake, and a cross-functional mandate. Those conditions can, in principle, be manufactured internally. A transformation leader who understands why GDPR worked understands the recipe: attach a concentrated, near-term, personally felt consequence to inaction; fix a deadline that politics cannot move; give the effort an owner with an enterprise-wide remit. The regulation did not have magic the rest of us lack. It had a mechanism, and the mechanism can be learned.

The open question — and it is genuinely open, from where we stand in the summer of 2018 — is whether we will learn it, or whether we will simply wait for the next regulation to do the work for us. The signs are mixed. Other jurisdictions are visibly drafting privacy laws of their own; the direction of travel suggests that the regulatory forcing function will keep arriving, on data and perhaps on much else, whether or not we develop the internal capability to act without it. It would be convenient to let it. It would also be an abdication. The organisations that emerge strongest from this period will be the ones that treat GDPR not as a debt discharged but as a demonstration — proof, delivered at considerable expense, that they are capable of governing themselves, if only they can find the will to do it before someone in Brussels finds it for them.

The deadline is behind us. The reset, for those willing to keep it open, has barely begun.


More from Transformation