28 July 2026 · 6 min read · Data, Digital and Cyber Security
The Protection of Personal Information Act asks a deceptively simple question: can you account for the personal information your organisation holds, and can you justify each use of it. Most organisations discover during preparation that they cannot, and that is the real value of getting ready.
Start with a data inventory
Before policies, before training, list what you actually hold. Which systems store personal information, whose information it is, why you collected it, who can see it, and how long you keep it. This inventory is tedious to build and impossible to fake, which is precisely why regulators ask for it.
Appoint and empower an Information Officer
Every responsible party has an Information Officer by default, usually the person in charge. What matters is whether that role has been made real, with the time and authority to answer requests, log incidents, and say no to a use of data that cannot be justified.
Test your breach response before you need it
A breach is not the moment to invent a process. Decide in advance who is told, within what time, and who decides whether the Regulator and affected people must be notified. Walk through one realistic scenario as a group. The gaps you find in a calm room are far cheaper than the ones you find in a real incident.
Make training specific
Awareness training that stays general changes nothing. Tie it to the actual systems and forms your people use, so a clerk knows what to do when a customer asks to see their record, and a manager knows why a spreadsheet of ID numbers should not sit on a shared drive.
BMC Training runs practical programmes in Data, Digital and Cyber Security. See the courses in this area.