2.7 Vision, Mission & the Privacy Program Communication Plan
Key Takeaways
- Competency I.B is titled 'communicate organizational vision and mission statement' — the exam treats program communication as a governance duty, not a marketing nicety.
- A privacy vision states the end state the program is working toward; a mission states what the program does day to day; principles translate both into decision rules teams can apply without calling the privacy office.
- Internal awareness and external awareness are separate obligations with separate audiences, channels, cadences and evidence.
- External awareness runs through the privacy notice, a trust centre, transparency reporting, customer due-diligence responses and regulator engagement — each of which must be consistent with the others.
- A communication plan is auditable: named audience, message, channel, owner, cadence and a measure of whether the message landed.
Communication Is a Blueprint Competency, Not a Soft Skill
One of the six Domain I competencies is I.B — communicate organizational vision and mission statement, and it carries a scored range of 4-6 items, roughly the same weight as defining the program's scope. Candidates who treat communication as filler leave points on the table.
The reason it is weighted is operational. A privacy program is executed almost entirely by people who do not work in privacy: engineers choosing defaults, marketers configuring a consent tool, recruiters storing CVs, support agents verifying a caller. They act on what they understand, not on what the policy repository contains.
Vision, mission, principles
| Artifact | Question it answers | Example | Audience |
|---|---|---|---|
| Vision | What end state are we working toward? | "Customers trust us with their data because we consistently do more than the law requires." | Board, executives, external market |
| Mission | What does this program actually do? | "We embed privacy into every product decision, respond to every rights request on time, and evidence our compliance on demand." | Whole organization |
| Principles | How do I decide, right now, without asking? | "Collect the minimum. Default to off. Never repurpose without an assessment. Escalate anything involving children's data." | Practitioners |
Vision without principles produces a poster. Principles without vision produce a checklist nobody believes in. The exam's credited answers usually involve translating the aspiration into a decision rule a non-specialist can apply unaided.
The two halves of indicator I.B.1
The indicator reads: create awareness of the organization's privacy program internally and externally. Those are different jobs.
Internal awareness targets employees, contractors, executives and the board. Its purpose is behavioural: people should know the program exists, what it expects of them, and how to reach it. Channels include executive messaging and visible tone from the top, onboarding briefings, an intranet privacy hub, targeted campaigns tied to launches or regulatory change, team-level briefings delivered by champions, and recognition of good catches. Awareness is not the same as training — training builds a specific capability for a specific role and is measured by competence, whereas awareness maintains general salience and is measured by reach and recall.
External awareness targets customers, prospects, partners, regulators and the public. Its channels are the privacy notice (the primary legal transparency instrument), a trust centre publishing sub-processors, certifications and security posture, transparency reports on government and rights requests, customer due-diligence responses to security and privacy questionnaires, and regulator engagement including prior consultation where a DPIA leaves unmitigated high risk.
The testable failure mode is inconsistency across channels: a trust centre listing sub-processors the privacy notice does not mention, or a sales security questionnaire claiming a certification the organization no longer holds. External statements about privacy practices are enforceable representations — in the US, misrepresenting them is the classic FTC Section 5 deceptive-practice theory. Marketing must not be the only reviewer of privacy claims.
An auditable communication plan
| Audience | Message | Channel | Owner | Cadence | Evidence it landed |
|---|---|---|---|---|---|
| Board | Program maturity, top risks, regulatory exposure | Board pack + verbal briefing | CPO | Quarterly | Minuted decisions and approved budget |
| Executives | Upcoming obligations, launch blockers, escalations | Steering committee | Privacy manager | Monthly | Actions logged with owners |
| All staff | Program exists, principles, how to reach us | Intranet hub, campaigns, onboarding | Privacy manager | Continuous + quarterly campaign | Reach and recall surveys, hub traffic |
| Engineering | Assessment gate, defaults, minimization | Guild sessions, embedded champions | Champion + privacy manager | Per release cycle | Percentage of features with a completed assessment |
| Customers | What we collect, rights, sub-processors | Privacy notice, trust centre | Privacy manager + legal | On change + annual review | Notice version log |
| Regulators | Cooperation, breach and consultation duties | Formal correspondence | DPO | As triggered | Filed correspondence record |
What makes this a governance artifact rather than a to-do list is the last two columns. A plan with no cadence is an intention; a plan with no evidence cannot be audited, and Domain V will eventually ask you to prove the program is working.
Worked scenario
A company launches a personalization feature that quietly widens data collection. Engineering ran the assessment; nobody told support, sales or the notice owner. Within a week support is improvising answers, sales is making claims the DPA does not support, and the published notice is out of date — which is now a transparency failure under Articles 12-14 as well as a communication failure. The credited response is not "send an email." It is to add a launch communication gate to the release checklist: notice updated, trust centre updated, support briefed with an approved answer, sales given accurate messaging, and champions notified — with a named owner for each.
A privacy manager publishes a well-drafted vision statement on the intranet, but engineers keep shipping features with data collection defaulted on. Which addition most directly addresses the gap under competency I.B?
An organization's trust centre lists eight sub-processors, its published privacy notice names four, and a sales security questionnaire response claims a certification that lapsed last year. Beyond the operational sloppiness, what is the most serious exposure?