Role-play

Pretend you are the data protection officer

Pretend you are the data protection officer so soft lawful-basis stories and retention theater fail before a processing change absorbs them.

Optimistic data packages optimize for "we can ship the feature." The DPO seat does the opposite. It asks which purpose lacks a lawful basis, which retention claim is aspirational, which transfer path invents adequacy, and which DPIA was skipped because the calendar was tight. A fluent privacy one-pager is not evidence that the processing can survive a regulator, an enterprise diligence call, or a careful customer.

This is a useful move before a new telemetry plan, a cross-border transfer, or a vendor that will touch personal data: after you describe the upside, seat a careful DPO perspective and make it try to decline. The output you want is a short list of material objections, the exhibits each needs, and the edits that would survive them.

Mandate and constraints

Name a real mandate: clear a processing change without inventing consent, keep retention aligned with what systems can actually delete, or defend a transfer claim without dual-counted safeguards. Give constraints: the evidence standard for purpose limitation, the jurisdictions you will not invent coverage for, and the residual risk you will refuse to hide. Without constraints the seat becomes cartoonish. With constraints it produces questions you might actually hear in a privacy review, a customer security questionnaire, or a regulator inquiry.

Write the seat into the prompt as a named role with a mandate. Example: "Data protection officer: list the top reasons to delay this processing change, the claim with the weakest legal basis, the retention or transfer gap that worries you most, and the ten diligence questions you would send after review. Stay inside a realistic mandate and avoid invented adequacy."

Outputs that count

  • Top reasons to challenge, delay, or reject this processing package.
  • The claim that looks strongest and is least evidenced.
  • The system, vendor, or region that would break first under scrutiny.
  • What would make you accept residual privacy risk in writing.
  • The ten hardest questions you would send after the meeting.

Run that brief in Pingpong against the real processing description, RoPA extracts, vendor DPAs, and deletion runbooks. Follow with a home-team response pass so you leave with edits and source packs, not only fear. When the decision is a customer-facing privacy claim, run this seat after product and security attacks so it can use earlier objections as ammunition.

When the plan leans on a single consent banner, a single DPA template, or a single "we delete on request" promise, force the seat to price concentration risk in writing. Ask what happens if the banner fails to fire, if the vendor refuses a deletion, or if sampling finds data the RoPA never listed. Concentration that only appears in a footnote still counts. Pair with pretend you are the legal ops lead, stress-test a privacy policy update, stress-test a data retention policy, pretend you are the CISO, and the war-game decisions hub. See how to run a Pingpong.