Beyond GDPR Knowledge: What Great Information Governance Practitioners Do Differently
- fabiodocarmoesouza7
- 4 days ago
- 2 min read
Information Governance practitioners are often called upon when the answer is not obvious. A new system is being introduced. Information needs to be shared. A subject access request has become complicated. A data breach has occurred, and the organisation needs to decide what happens next.
In these moments, knowing the legislation is essential, but knowledge alone is not enough.
The real value of an effective IG practitioner lies in how they interpret a situation, ask the right questions and help colleagues reach a practical, proportionate and defensible decision.
Knowledge is only the starting point
Understanding UK GDPR, confidentiality, information rights, records management and accountability provides the foundation.
However, policies and legislation cannot anticipate every workplace situation.
When reviewing a new project, for example, a practitioner must look beyond whether a form has been completed or a lawful basis has been recorded.
They need to ask:
What information is being used, and why?
Is all of it genuinely necessary?
Who will have access?
Have the individuals affected been properly informed?
What could go wrong?
Could the same outcome be achieved with less risk?
These questions turn Information Governance from a paperwork exercise into meaningful risk management.
They understand before they advise
Before recommending controls or raising concerns, practitioners need to understand what colleagues are trying to achieve, the pressures they are facing and the people who may be affected.
Advice must protect individual rights and confidentiality while also recognising operational reality.
That balance requires professional judgement, not simply an ability to recite rules.
They make complexity understandable
An effective practitioner translates that complexity into clear action. They explain what the risk is, why it matters, who could be affected and what practical steps could reduce it.
Different audiences also need different forms of advice. Senior leaders may need to understand the organisational impact, while project teams and frontline staff need clear actions they can apply.
DPS’ approach to training is designed around this practical application, helping learners understand not only the requirements of Information Governance, but why they matter in real situations.
They recognise the bigger picture
A data breach may involve cyber security, staff training, contracts, records management and incident response. A new technology project may raise questions about transparency, access, confidentiality and data sharing.
Effective practitioners understand these connections and know when to involve colleagues such as the DPO, SIRO, Caldicott Guardian, IT team or senior leadership.
They also look beyond the immediate issue. When something goes wrong, they ask what the organisation can learn and what needs to change.
These skills can be developed
That is why practitioner-level development must go beyond general awareness training.
The BCS Tech 10-accredited Information Governance Practitioner Certification Programme supports professionals who want to strengthen their knowledge and apply it with greater confidence in the workplace. The programme covers areas including UK GDPR, confidentiality, DPIAs, information sharing, information rights, incident response and key governance responsibilities.
The next cohort starts in September 2026
Joining the September 2026 cohort gives you the opportunity to develop your knowledge in a structured way and strengthen how you apply it in practice. The programme will support you in approaching Information Governance decisions with greater confidence, clarity and professional judgement.
.png)



Comments