Everyday Privacy Duties
Most GDPR duties land on whoever opens the email.
What Is Everyday Privacy Duties?
Most GDPR obligations land on whoever opens the email, and they are decided in the first few minutes. You work one ordinary morning. A forwarded complaint is really an erasure request that never says GDPR, so it has to be recognised, logged and routed. A colleague misdirects a full customer export into your inbox and copies an outside company, and the 72-hour clock starts the moment anyone is aware. A teammate has been pasting customer complaints into a free online tool. The close covers the two-tier fines under Article 83.
What You'll Learn in Everyday Privacy Duties
- Recognise a data subject request regardless of wording, form or channel, and route it instead of answering it
- Name the principal rights under Articles 12 to 23 and record which one a request exercises
- Report a suspected or actual personal data breach internally without undue delay, without judging severity first
- Explain when the 72-hour notification clock starts and why quiet deletion is the worst available response
- Identify the everyday shapes a breach takes, including misdirected email, lost devices and over-broad sharing
- Refuse to place personal data in unapproved tools, and explain the processor contract and transfer obligations behind that rule
- Describe the consequences of failure, including Article 83 fines, processing bans, reputational and employment-law effects
Everyday Privacy Duties — Training Steps
-
An Ordinary Tuesday
Nothing on this morning's list says privacy on it. There is a forwarded customer complaint, a file somebody sent you by mistake, and a message from a colleague who has found a clever shortcut. All three carry an obligation, and in each case the obligation belongs to you in the first few minutes, before anyone senior has heard about it.
-
A Complaint, or Something More
Lena Fischer in Customer Support has forwarded a complaint she is not sure how to answer.
-
Is This a Request
Lena's instinct was that this was not a normal unsubscribe. She was right, and what it actually is decides who deals with it.
-
Logging It Properly
The privacy office runs an intake form for exactly this. Logging a request takes about a minute, and it is what starts the formal clock and puts the case in front of someone who can assess it.
-
Filing the Request
The form asks three things: which right is being exercised, how it reached us, and what she actually asked for in her own words. The right matters because each one has its own rules. Quoting her wording matters because a paraphrase can quietly narrow what she asked.
-
Reading What You Filed
The form is gone and the receipt is what remains. It carries your three answers back to you word for word, plus a case reference and a due date. That record is the point of the whole exercise: it is the evidence the request was recognised on the day it arrived, and the reply gets built from it.
-
A File You Should Not Have
The second item is an email that was never meant for you.
-
The First Five Minutes
The file is sitting in your inbox. Whatever you do in the next few minutes is the organisation's response time, because right now you are the only person who knows.
-
Reporting It
You do not need to know whether this will end up being notifiable to a regulator. That is exactly the judgement you are not required to make, and waiting until you are sure is how the deadline gets missed. Report what you know now.
-
Reading What You Reported
The form is gone and the report stands on its own. It shows what you said, including what you were careful not to claim, and it comes back with a timestamp and a countdown. Both are now on the record, and neither depends on what the assessment eventually concludes.
Security Framework Coverage
CIS Controls
- CIS 3 Data Protection
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.DS Data Security
GDPR
- Art. 5 Principles relating to processing of personal data
- Art. 33 Notification of a personal data breach to the supervisory authority