Convincing the board to invest in data protection
I once sat through a board update where the CFO’s eyes visibly glazed over the moment I mentioned “GDPR.” Not “fine” or “breach.” I could see him mentally filing me under the same category as the fire safety rep who comes round once a year to check the extinguishers: necessary, tolerated, but absolutely not where the proper money goes.
If you’ve experienced something similar, and if you’re a DPO you may well have, you’ll know the problem isn’t that senior leadership doesn’t care about data protection. The problem is they’ve may have filed it in the seldom opened drawer labelled “compliance cost”. Your job is to get data protection moved into a different drawer. Here’s how I’ve gone about it…
Don’t open with the law
I know the instinct. You’ve got the Article 5 accountability principle loaded and ready, a slide with “4% of global turnover” in red letters, and you’re going to make them understand the stakes. Try to resist this. Boards already know compliance is table stakes. Telling them “we have to do this” is the fastest way to a polite nod and being quietly deprioritised the moment budgets get tight. Keep the regulatory citations for the appendix. Also, they may have heard the ICO rarely issues fines, so lead with the business impact the board can act on.
Speak their language
Frame your case around money, reputation and risk: the outcomes the board is there to govern. Skip the fines, or at least don’t dwell on them, because enforcement is patchy and boards half-know it. Instead, talk about the operational cost: the weeks lost to breach response, the legal fees, the fact your best people spend a fortnight firefighting instead of doing their actual jobs.
Talk about customer trust, because it’s hard to earn and expensive to rebuild once it’s gone. If you sell into business clients, talk about procurement. A weak data protection posture slows deals down or can kill them outright.
Best of all, use your own internal numbers. Nothing sends a board to sleep faster than an industry statistic. But internal evidence makes time and cost immediate and relevant. For example, “Our last DSAR took 120 hours of staff time” will get you further than giving broad stats from a research firm they’ve never heard of.
Link data protection to the board’s current priorities
Every board has an obsession of the quarter — AI, expansion, cost-cutting, a big new product launch. Don’t compete with it. Attach yourself to it. Expanding into new markets? Show them what has to be built before they can legally operate there, and how much more it costs to retrofit later. Rolling out AI tools? This is your moment. Boards are nervous about AI risk. Data minimisation and impact assessments may not be glamourous, but they reduce specific risks and help avoid expensive redesign later.
Under pressure to cut costs? Point out avoidable expense and loss of time and resources due to by poor data practices. Duplicated data collection, a data map nobody can actually read, data subject access requests which take three departments days to fulfil. Make data protection the thing which helps them do what they want to do, not the thing standing in the doorway with a clipboard.
Tell a good story
I’ve gained far more traction with a short, slightly uncomfortable anecdote, than with any spreadsheet I’ve ever built. The marketing campaign that nearly launched using unconsented records. The supplier contract that quietly created a data protection risk nobody had noticed for years. Boards remember these. They probably won’t remember your risk heat map.
Ask for something specific
“We need more resource for data protection” is easy to nod at and forget. “We need one analyst to clear our DSAR backlog, at a cost of £X, which is currently costing us Y hours a month and exposing us to complaint risk” is much harder to wriggle out of.
Give them options if you can. A bare minimum, a recommended level and more ambitious version, each with a cost and clearly stated benefits. This turns your ask into a decision they get to make, rather than a demand they choose to reject.
If it doesn’t land the first time, adapt your approach and go again
It won’t always work first time. Mine certainly didn’t with that particular CFO. What changed things wasn’t a better slide deck. It was showing up regularly with a short, honest update; a near-miss here, a regulatory development there. Until data protection stopped being an occasional interruption and started being part of the furniture. By the time I needed real investment, I wasn’t starting from a cold pitch, I had earned a track record.
Real influence comes from regular, concise updates, not one exceptional presentation. So stop asking the board to comply and start showing them what good data protection actually protects. Do this consistently enough and the budget conversation gets a great deal easier. Even for the CFOs who once looked at you like you’d mentioned the fire extinguishers.