Everyday Privacy Duties

Everyday Privacy Duties

Most GDPR duties land on whoever opens the email.

What Is Everyday Privacy Duties?

Most GDPR obligations land on whoever opens the email, and they are decided in the first few minutes. You work one ordinary morning. A forwarded complaint is really an erasure request that never says GDPR, so it has to be recognised, logged and routed. A colleague misdirects a full customer export into your inbox and copies an outside company, and the 72-hour clock starts the moment anyone is aware. A teammate has been pasting customer complaints into a free online tool. The close covers the two-tier fines under Article 83.

What You'll Learn in Everyday Privacy Duties

Everyday Privacy Duties — Training Steps

  1. An Ordinary Tuesday

    Nothing on this morning's list says privacy on it. There is a forwarded customer complaint, a file somebody sent you by mistake, and a message from a colleague who has found a clever shortcut. All three carry an obligation, and in each case the obligation belongs to you in the first few minutes, before anyone senior has heard about it.

  2. A Complaint, or Something More

    Lena Fischer in Customer Support has forwarded a complaint she is not sure how to answer.

  3. Is This a Request

    Lena's instinct was that this was not a normal unsubscribe. She was right, and what it actually is decides who deals with it.

  4. Logging It Properly

    The privacy office runs an intake form for exactly this. Logging a request takes about a minute, and it is what starts the formal clock and puts the case in front of someone who can assess it.

  5. Filing the Request

    The form asks three things: which right is being exercised, how it reached us, and what she actually asked for in her own words. The right matters because each one has its own rules. Quoting her wording matters because a paraphrase can quietly narrow what she asked.

  6. Reading What You Filed

    The form is gone and the receipt is what remains. It carries your three answers back to you word for word, plus a case reference and a due date. That record is the point of the whole exercise: it is the evidence the request was recognised on the day it arrived, and the reply gets built from it.

  7. A File You Should Not Have

    The second item is an email that was never meant for you.

  8. The First Five Minutes

    The file is sitting in your inbox. Whatever you do in the next few minutes is the organisation's response time, because right now you are the only person who knows.

  9. Reporting It

    You do not need to know whether this will end up being notifiable to a regulator. That is exactly the judgement you are not required to make, and waiting until you are sure is how the deadline gets missed. Report what you know now.

  10. Reading What You Reported

    The form is gone and the report stands on its own. It shows what you said, including what you were careful not to claim, and it comes back with a timestamp and a countdown. Both are now on the record, and neither depends on what the assessment eventually concludes.

Security Framework Coverage

CIS Controls

  • CIS 3 Data Protection

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.DS Data Security

GDPR

  • Art. 5 Principles relating to processing of personal data
  • Art. 33 Notification of a personal data breach to the supervisory authority