Everyday Privacy Duties

Everyday Privacy Duties

The three reflexes that decide whether a small problem stays small: recognise a rights request whatever words it uses, report a misdirected file instead of quietly deleting it, and keep customer data out of tools nobody has approved.

What Is Everyday Privacy Duties?

Most GDPR obligations do not land on lawyers. They land on whoever opens the email, and they are decided in the first few minutes. This exercise puts a learner through one ordinary morning at an online marketplace. A forwarded customer complaint turns out to be an erasure request that never uses the word GDPR, and has to be recognised, logged and routed rather than answered. A colleague misdirects a full customer export into the learner's inbox and copies an outside company, and the right move is to report it immediately without opening, forwarding or quietly deleting it, because the 72-hour clock starts the moment anyone becomes aware. A teammate messages about a free online tool he has been pasting customer complaints into, which quietly makes an unassessed provider a processor with no contract. The exercise closes with what all three would have cost: the two-tier fine framework under Article 83, orders to stop processing, published enforcement, and the employment consequences of concealing an incident.

What You'll Learn in Everyday Privacy Duties

Everyday Privacy Duties — Training Steps

  1. An Ordinary Tuesday

    Nothing on this morning's list says privacy on it. There is a forwarded customer complaint, a file somebody sent you by mistake, and a message from a colleague who has found a clever shortcut. All three carry an obligation, and in each case the obligation belongs to you in the first few minutes, before anyone senior has heard about it.

  2. A Complaint, or Something More

    Lena Fischer in Customer Support has forwarded a complaint she is not sure how to answer.

  3. Is This a Request

    Lena's instinct was that this was not a normal unsubscribe. She was right, and what it actually is decides who deals with it.

  4. Logging It Properly

    The privacy office runs an intake form for exactly this. Logging a request takes about a minute, and it is what starts the formal clock and puts the case in front of someone who can assess it.

  5. Filing the Request

    The form asks three things: which right is being exercised, how it reached us, and what she actually asked for in her own words. The right matters because each one has its own rules. Quoting her wording matters because a paraphrase can quietly narrow what she asked.

  6. Reading What You Filed

    The form is gone and the receipt is what remains. It carries your three answers back to you word for word, plus a case reference and a due date. That record is the point of the whole exercise: it is the evidence the request was recognised on the day it arrived, and the reply gets built from it.

  7. A File You Should Not Have

    The second item is an email that was never meant for you.

  8. The First Five Minutes

    The file is sitting in your inbox. Whatever you do in the next few minutes is the organisation's response time, because right now you are the only person who knows.

  9. Reporting It

    You do not need to know whether this will end up being notifiable to a regulator. That is exactly the judgement you are not required to make, and waiting until you are sure is how the deadline gets missed. Report what you know now.

  10. Reading What You Reported

    The form is gone and the report stands on its own. It shows what you said, including what you were careful not to claim, and it comes back with a timestamp and a countdown. Both are now on the record, and neither depends on what the assessment eventually concludes.