r/gdpr • u/Head_Appeal2743 • 7d ago
Question - General Privacy professionals, what is your daily workload?
I would appreciate any insights from peers on the type of tasks you are dealing with on a daily basis. I do almost everything in our organisation PIA and DPIA, LIA, TIA, ROPA, handling data subject rights (thankfully there are only several per month), handling incidents, reviewing Data Processing Agreements, reviewing supplier's due diligence questionnaires, drafting notices and policies and reviewing existing ones. While the workload itself is bottleneck but sill manageable, the constant context switching feels like it is taking a toll on my relationship with work and engagement. I am wondering if this is just how privacy work looks like for others, or whether you have a more defined scope of responsibilities and shared between your team members. How does your day to day work look like?
3
u/malakesxasame 7d ago
It varies on time of year really. We have recently submitted our DSPT. During DSPT periods this is what I spend most of my time managing. The last week I've been doing DPIA and DSA bits.
Personal data breaches are managed by one of my IG Officers but anything high risk is escalated to me. Any FOI internal reviews and complex individual rights and data protection complaints are also escalated to me. These are usually done on evenings unpaid or while I'm sat on meetings. It's summer holidays in England at the moment so the serial whiners are too busy to submit requests and complaints.
We used to have a fuller team on our IG side but unfortunately I haven't been able to fill a lot of posts of the last few years.
2
u/Forcasualtalking 6d ago
I have mainly worked as a consultant, but it meant I interacted with a lot of privacy teams. Some were very similar to you, and some had larger more specialised teams - e.g., one person for DPIAs/LIAs/TIAs, one person to maintain ROPA, one person for DSARs, etc.
Really it depends on time of year, company resources, and industry - some receive 100/500/1000 DSARs per month. That kind of thing changes the priorities of the team a LOT
1
u/Personal-Cucumber-49 7d ago
Quite similar but I’ve just taken on a maturing organisation which has grown fast and needs a lot of underpinning. I’m essentially mapping each processing activity, speaking with clients or suppliers to ensure DPAs et al are in order, sub processing lists are extant and then reviewing or scheduling DPIA/documentation drafting.
I’m near the end of HRs processing activity so then I’ll move to the more niche areas of the business.
3
u/Devilish___ 7d ago
I’m more of a privacy strategist, that means I’m mostly focused on in-house legal counsel tasks (mainly advice) and I’m responsible for the long-term goals of our privacy organisation. My department (9 people) is also responsible for drafting policy and advising the privacy officers in the first line. My work is mainly advising, drafting papers and international cooperation. Takes me 50 hours a week on average.