Implementing the GDPR within an organisation, be it small or large, and handling simple or complex processes, is primarily about knowledge and change management.

As such this is best compared to the process of implementing fiscal rules and regulations. Both GDPR accountability and fiscal accountability require the cooperation of all employees, the registration of each relevant occurrence, complete transparency and an iterative approach that is based on a Plan-Do-Check-Act cycle.

The Privacy Factory has translated this cycle into a role-based GDPR implementation strategy, executed by the Inspector, Policy maker, Planner and Controller roles.

