The governance organisation of tomorrow
Accountability is an operational discipline, not a documentation exercise. How the privacy operating model extends across privacy, cyber, and AI, and the system that makes it real.
By Nicholai Pfeiffer·Managing Partner, White Label Consultancy
A few years ago I wrote a piece called The Privacy Organisation of Tomorrow. The argument was simple. Accountability under the GDPR is not a documentation exercise. It is an operational discipline. Organisations that treated it as paperwork produced a lot of good intentions and very little they could actually demonstrate. The ones that got it right did something harder: they redesigned how work was owned, so that responsibility for data protection lived with the people doing the work, not with a central function trying to inspect quality in after the fact.
I still believe every word of that. What has changed is the scope of the problem. In 2020 the pressing accountability regime was the GDPR. Today the same organisation is also answerable under the EU AI Act for how it builds and uses AI, under NIS2 for how it manages cyber risk, and under DORA if it operates in financial services. The obligations differ in detail, but the organisational challenge is identical. Each regime asks you to assess before you act, to keep records of your reasoning, to assign clear ownership, and to prove, on request, that you did all of this properly and in good time.
The problem has not changed, it has multiplied
The core failure I described in 2020 is still the most common one I see. Organisations introduce new processes without defining the roles required to maintain them, and without assigning clear responsibilities to those roles. The result is an organisation that has defined its good intentions and stopped there. The processes exist on paper. Nobody owns them in practice.
Now multiply that across three domains. A single product launch can trigger a data protection impact assessment, a security review, and, increasingly, an AI risk classification. If each of those lives in a different tool, owned by a different team, with a different idea of who signs off and by when, you do not have three times the assurance. You have three times the ambiguity. The accountability principle does not care how busy you are. It asks who was responsible, what they assessed, and whether they can show it.
Two axes of organisational design, applied everywhere
The original article leaned on two ideas that travel very well across domains.
The first is the three lines of defence. The first line owns and operates the controls. The second line sets requirements and monitors compliance with them. The third line provides independent assurance. This separation is what keeps an organisation honest, and it works the same way whether the risk is a data breach, an insecure system, or a badly governed AI model.
The second is the distinction between strategic, tactical, and operational work. The strategic layer sets direction, ambition, and resourcing. The tactical layer plans the activities needed to get there. The operational layer carries them out, day after day. Most programmes are strong on strategy and weak on the operational layer, which is precisely where accountability is won or lost. Strategy that never reaches a named person, with a task and a deadline, is just a slide.
Put the two axes together and a design emerges. No single person carries the whole burden of privacy, or security, or AI governance. Instead, responsibility is broken down to the level of who does what by when, and assigned to the first-line roles best placed to carry it. This is what lets an agile organisation move quickly. Teams navigate most decisions themselves, because the guardrails and the ownership were designed in advance, rather than waiting on a central function to sign off every step.
The expert must stay close to the work
There is a tension in this model that I explored in a companion piece, Can the DPO be involved in operational matters?. If you push ownership out to the first line, where does that leave the expert? The comfortable reading of the GDPR is that the Data Protection Officer belongs in the second line, monitoring and reporting, kept at arm's length from operational decisions to avoid a conflict of interest.
I argued then, and still argue, that this reading is wrong. Article 38 requires that the DPO is involved, properly and in a timely manner, in all issues relating to the protection of personal data. The EDPB guidance is emphatic that the DPO should be involved from the earliest stage possible, treated as a discussion partner, and present where decisions with data protection implications are taken. The DPO advises, influences, and, where overruled, records a dissenting view to top management. What the DPO must not do is take the first-line decision. That is the real meaning of no conflict of interest, and the Proximus case confirmed that parking the DPO in a second-line compliance role does not make the conflict problem go away.
This is the crux, and it generalises cleanly. The same paradox now applies to the CISO under NIS2 and to the AI governance lead under the EU AI Act. In each case the expert must be embedded in first-line work early enough to shape it, close enough to advise on real decisions, yet clearly separated from ownership of the decision itself. Distribute ownership, but keep the expert engaged. Get either half wrong and you have either a bottleneck or a blind spot.
Why this breaks without a system
Here is the part the original articles could not answer. The operating model is sound, but it is genuinely hard to run by hand.
Consider what it actually demands. Ownership has to be distributed to named first-line roles and tracked. Experts have to be pulled in early, and their advice, and any dissent, recorded. The three lines have to stay separated, so that the people who advise are not the people who decide, and the people who assure are independent of both. You have to be able to prove, later and on demand, that the expert was involved in a timely manner, that the risk was assessed before the product shipped, and that the deadline was met. And you have to do all of this at once across privacy, cyber, and AI, where the same underlying activity often carries obligations under more than one regime.
Spreadsheets cannot distribute ownership. Email cannot demonstrate that involvement was timely. A shared drive cannot hold a segregation of duties. The moment the model spans more than one domain, the manual version collapses under its own coordination cost, and the organisation drifts back to the thing I warned against in 2020: defined good intentions with no operational reality behind them.
How Pritect operationalises the model
This is the gap Pritect was built to close, and the mapping to the argument above is close to one for one.
Ownership becomes explicit and trackable. Privacy, security, and AI obligations are broken into assessments and tasks assigned to the responsible first-line roles, so who does what by when stops being an aspiration on a slide and becomes something the organisation can see and manage.
Documentation is produced at scale. Records of processing, impact assessments, and risk assessments are generated through structured, AI-assisted workflows. That directly attacks the original problem, that the historic way of working never produced the volume or the quality of documentation the accountability principle requires.
Segregation of duties is enforced, not merely intended. The design keeps advising and assuring separate from deciding and owning, so the three lines of defence hold in practice. That is what protects the expert from the conflict of interest a purely second-line posture never actually resolves.
The three layers connect. Executive oversight sits at the strategic layer, planning and scheduled obligations at the tactical layer, and operational task workflows underneath. Monitoring and drift detection give the second line a live view, and an audit trail gives the third line something independent to test. Direction set at the top reaches a named person with a task and a deadline at the bottom.
One model spans three domains. Because privacy, cybersecurity, and AI governance share a common backbone of regulatory reference data and controls, the same operating model runs across all three. A single activity that carries obligations under the GDPR, NIS2, and the EU AI Act at once can be assessed once and governed coherently, rather than three times in three disconnected tools.
Where this leaves us
The organisation of tomorrow is not the one with the largest compliance team. It is the one that has designed accountability into how work is owned, kept its experts close to the operational front line without compromising their independence, and given all of it a system of record that can prove the story on demand.
The argument I made for privacy in 2020 has aged well, and the intervening regulation has only made it more urgent. What has changed is that the operating model now has to carry privacy, cyber, and AI together. Getting the design right is still the first move. Making it real, and keeping it real through time, is where a platform earns its place. If you want help drawing that organisational blueprint, it is exactly the work we do at White Label Consultancy.
Watch one activity flow through data protection, AI governance, cybersecurity, and enterprise risk on a single record.
