Skip to content
Amrani Academy
GDPR FoundationsLesson 14 of 14

5. Putting it into practice

Workplace scenarios

Scenario 1: The unexpected access request

A former employee emails the general office inbox: "Please send me copies of everything you hold about me, including my HR file and any emails that mention me." The message never uses the words "Subject Access Request", and it lands in an inbox nobody is specifically responsible for.

What good looks like: whoever spots the email recognises it as a Subject Access Request, even though it doesn't use that phrase. A rights request is valid however it arrives and in whatever words. They log it and pass it to the data protection lead the same day, because the one calendar month clock started when the request arrived, not when someone got round to reading it properly.

Scenario 2: The marketing shortcut

A colleague in sales suggests emailing a special offer to every address in the customer database. "We already have their emails from their orders, so we're fine, right?" Most of those addresses were collected purely to send order confirmations and delivery updates.

What good looks like: someone raises purpose limitation before the campaign goes out. Data collected to fulfil orders cannot simply be reused for marketing without a proper basis for that new purpose. The team checks with the data protection lead whether a suitable basis exists, and ensures every marketing message includes a clear way to opt out, since an objection to direct marketing must always be honoured.

Scenario 3: The misdirected spreadsheet

An HR officer means to send a spreadsheet of staff sickness absence records to the payroll manager, but the email address auto-completes to a supplier contact with a similar name. They notice a minute after pressing send.

What good looks like: the officer reports it to the data protection lead immediately, rather than hoping nobody notices. Sickness records are special category data, so this could be a reportable breach. The organisation assesses the risk quickly, asks the recipient to delete the email and confirm they have done so, and decides whether the ICO needs to be notified within 72 hours of becoming aware. Fast, honest reporting keeps every containment option open.

Scenario 4: The over-collecting form

A team designing a new customer enquiry form adds fields for date of birth and marital status, "because it might be useful for analysis later." Neither field is needed to answer an enquiry.

What good looks like: a colleague asks the simple data minimisation question: do we actually need this to handle the enquiry? The answer is no, so the fields come out before launch. Data that is never collected can never be breached, never needs securing, and never needs deleting, which makes minimisation the cheapest control there is.

Course contents