Earlier this week, I was asked by a client to take some mandatory trainings so I could satisfy their compliance requirements. It was the usual bundle: Workplace Harassment, Cybersecurity, and, of course, Privacy trainings. These are essentially now ubiquitous for anyone that is employed or contracted by a large organization with a mature HR functions.

As I was taking the Privacy Training, I nearly threw my laptop away from me in frustration. On a fairly basic question regarding jurisdiction and the EU GDPR, I found myself writing "WRONG, WRONG, WRONG!" on my notebook in capitals. Underlined.

WRONG. WRONG. WRONG!!!

The training continued to do the usual question and answer sequence, giving a hypothetical of a nice marketing associate who was just asking questions in good faith about whether he could do something with some sensitive personal data he had collected. The answer the training forced me to give each time was "No, talk to the Privacy Team who will then tell you 'No.'"

What a message to send to someone their first couple days on the job with your company.

Privacy Training is something of a source of frustration for me. Part of running any successful privacy program is ensuring your employees receive sufficient training to understand that the personal data they maintain is both not theirs and is highly regulated under a variety of laws. Trying to find good training materials provided by third party content providers (preferably ones that integrate with your LMS platform) is a little bit like trying to find a needle in a haystack. There's always a number of problems with them. Here's a couple that stand out to me:

  • Being wrong on the law. Privacy is dynamic. It's constantly changing. We stand on quicksand, I tell people. You don't need to go into the minutiae of the law, but you do need to get the basics right. Getting something fundamental like jurisdiction and applicability on this one explains a lot of conversations I've had over the years, including with other lawyers, explaining why the GDPR doesn't apply to the proposed data use even if you think it does and want to make it part of the contract. No. Be accurate.
  • Too much technical jargon. This one is really hard. We live in a land of acronym soup. GDPR. CCPA. LGPD. HIPAA. DPIA. CPPA. LIA. TIA. DSARs. And on and on and on. That doesn't mean your customer support or marketing or sales team wants to live in that soup with you. Your job as a privacy professional is to communicate to other teams and other people, sometimes in other countries and across language barriers, what the requirements are. You're a professional translator. The best privacy pros lean into their communication skills. What training you push out on the organization is part of the message you're sending about privacy.
  • Overemphasis on consulting the Privacy Team. I see this also with the HR and cybersecurity trainings. No one is empowered or guided to make a decision. It's always "go talk to the subject matter experts." This to me screams of domain capture. I don't operate that way and don't think successful companies do. I think you have to empower people so you don't become a bottle neck and slow down things that ought not to be slowed down. The job is building guardrails, not walls.

This training revealed a new one for me though:

  • Becoming the Department of No. If your message to an employee operating in good faith is "No," you're sending a message that you are a roadblock and people won't want to work with you. Instead of coming to talk to you like bullet #3 emphasizes above, they'll just start avoiding you. You have to come up with strategies to get people to Yes, even if in the end they decide the work to get to that Yes is too much effort and the end result is a No. Reserve your No's for times that matter, for high stakes issues that will have real significant risk. You cannot die on every hill or you won't have a job long.

My solution to the training woes for the first couple of years when GDPR and CCPA were fresh was to create my own, give it to one audience, film it, and let the HR team put it on the intranet and roll it into their LMS platform. I have found some training solutions out there in recent years because the content has become better but like all corporate trainings, they do tend to remain sterile and dry.

They key as always is to find something that fits your company and risk profile but also sends the message you want to send as a leader about how your company handles data.

If you need someone to help you train your staff on privacy laws who won't be dry and boring, please reach out to me at Brandi@BennettTechLaw.com for help.