2.7 Vision, Mission & the Privacy Program Communication Plan

Key Takeaways

  • Competency I.B is titled 'communicate organizational vision and mission statement' — the exam treats program communication as a governance duty, not a marketing nicety.
  • A privacy vision states the end state the program is working toward; a mission states what the program does day to day; principles translate both into decision rules teams can apply without calling the privacy office.
  • Internal awareness and external awareness are separate obligations with separate audiences, channels, cadences and evidence.
  • External awareness runs through the privacy notice, a trust centre, transparency reporting, customer due-diligence responses and regulator engagement — each of which must be consistent with the others.
  • A communication plan is auditable: named audience, message, channel, owner, cadence and a measure of whether the message landed.
Last updated: August 2026

Communication Is a Blueprint Competency, Not a Soft Skill

One of the six Domain I competencies is I.B — communicate organizational vision and mission statement, and it carries a scored range of 4-6 items, roughly the same weight as defining the program's scope. Candidates who treat communication as filler leave points on the table.

The reason it is weighted is operational. A privacy program is executed almost entirely by people who do not work in privacy: engineers choosing defaults, marketers configuring a consent tool, recruiters storing CVs, support agents verifying a caller. They act on what they understand, not on what the policy repository contains.

Vision, mission, principles

ArtifactQuestion it answersExampleAudience
VisionWhat end state are we working toward?"Customers trust us with their data because we consistently do more than the law requires."Board, executives, external market
MissionWhat does this program actually do?"We embed privacy into every product decision, respond to every rights request on time, and evidence our compliance on demand."Whole organization
PrinciplesHow do I decide, right now, without asking?"Collect the minimum. Default to off. Never repurpose without an assessment. Escalate anything involving children's data."Practitioners

Vision without principles produces a poster. Principles without vision produce a checklist nobody believes in. The exam's credited answers usually involve translating the aspiration into a decision rule a non-specialist can apply unaided.

The two halves of indicator I.B.1

The indicator reads: create awareness of the organization's privacy program internally and externally. Those are different jobs.

Internal awareness targets employees, contractors, executives and the board. Its purpose is behavioural: people should know the program exists, what it expects of them, and how to reach it. Channels include executive messaging and visible tone from the top, onboarding briefings, an intranet privacy hub, targeted campaigns tied to launches or regulatory change, team-level briefings delivered by champions, and recognition of good catches. Awareness is not the same as training — training builds a specific capability for a specific role and is measured by competence, whereas awareness maintains general salience and is measured by reach and recall.

External awareness targets customers, prospects, partners, regulators and the public. Its channels are the privacy notice (the primary legal transparency instrument), a trust centre publishing sub-processors, certifications and security posture, transparency reports on government and rights requests, customer due-diligence responses to security and privacy questionnaires, and regulator engagement including prior consultation where a DPIA leaves unmitigated high risk.

The testable failure mode is inconsistency across channels: a trust centre listing sub-processors the privacy notice does not mention, or a sales security questionnaire claiming a certification the organization no longer holds. External statements about privacy practices are enforceable representations — in the US, misrepresenting them is the classic FTC Section 5 deceptive-practice theory. Marketing must not be the only reviewer of privacy claims.

An auditable communication plan

AudienceMessageChannelOwnerCadenceEvidence it landed
BoardProgram maturity, top risks, regulatory exposureBoard pack + verbal briefingCPOQuarterlyMinuted decisions and approved budget
ExecutivesUpcoming obligations, launch blockers, escalationsSteering committeePrivacy managerMonthlyActions logged with owners
All staffProgram exists, principles, how to reach usIntranet hub, campaigns, onboardingPrivacy managerContinuous + quarterly campaignReach and recall surveys, hub traffic
EngineeringAssessment gate, defaults, minimizationGuild sessions, embedded championsChampion + privacy managerPer release cyclePercentage of features with a completed assessment
CustomersWhat we collect, rights, sub-processorsPrivacy notice, trust centrePrivacy manager + legalOn change + annual reviewNotice version log
RegulatorsCooperation, breach and consultation dutiesFormal correspondenceDPOAs triggeredFiled correspondence record

What makes this a governance artifact rather than a to-do list is the last two columns. A plan with no cadence is an intention; a plan with no evidence cannot be audited, and Domain V will eventually ask you to prove the program is working.

Worked scenario

A company launches a personalization feature that quietly widens data collection. Engineering ran the assessment; nobody told support, sales or the notice owner. Within a week support is improvising answers, sales is making claims the DPA does not support, and the published notice is out of date — which is now a transparency failure under Articles 12-14 as well as a communication failure. The credited response is not "send an email." It is to add a launch communication gate to the release checklist: notice updated, trust centre updated, support briefed with an approved answer, sales given accurate messaging, and champions notified — with a named owner for each.

Test Your Knowledge

A privacy manager publishes a well-drafted vision statement on the intranet, but engineers keep shipping features with data collection defaulted on. Which addition most directly addresses the gap under competency I.B?

A
B
C
D
Test Your Knowledge

An organization's trust centre lists eight sub-processors, its published privacy notice names four, and a sales security questionnaire response claims a certification that lapsed last year. Beyond the operational sloppiness, what is the most serious exposure?

A
B
C
D