Strategic Business Leader · IT systems security and control
Data Protection, Privacy and Information Security Policy for SBL
Updated 11 October 2026 · Fact-checked
Data protection law, such as GDPR, sets rules on how organisations collect, use and keep personal data. An information security policy turns those rules into staff behaviour and technical controls, often guided by ISO 27001. In SBL, you identify the data risks in the scenario, then recommend compliance actions, controls and training.
Understand Data Protection, Privacy and Information Security Policy
Personal data is information that identifies a living person, directly or in combination with other data. Names, email addresses, location data and online identifiers all count. Privacy is the individual's right to control what happens to that data. Data protection is the set of legal and practical rules that protect that right.
The best-known regulation is the EU General Data Protection Regulation (GDPR). It also applies to organisations outside the EU that offer goods or services to people in the EU, or monitor their behaviour. This makes it relevant to the global businesses in SBL cases. Other countries have their own laws, so in an exam say 'data protection law such as GDPR' unless the scenario names a regime.
GDPR works through principles. Data must be processed lawfully, fairly and transparently. It must be collected for specified purposes, be adequate and limited to what is needed, be accurate, and be kept no longer than necessary. It must be processed securely, and the organisation must be able to show it complies. This last point is called accountability. Individuals also have rights, including access to their data, correction, erasure in some cases, and objection to certain processing.
Law says what must be achieved. An information security policy says how the organisation will do it. It is a formal document, approved by senior management, that sets out the aims, roles, rules and consequences for protecting information. It covers areas such as access, passwords, device use, data classification, incident reporting, third-party suppliers and backup.
ISO 27001 is an international standard for an information security management system (ISMS). It is a risk-based approach: identify information risks, choose controls, monitor, and improve continually. An organisation can be certified against it, which gives customers and regulators some comfort. Certification does not guarantee compliance with GDPR or that no breach will occur.
Policies fail without people. Most breaches involve human error, such as phishing, lost devices or weak passwords. So staff training, awareness campaigns, clear accountability and a security-aware culture are as important as technical controls. Leaders must set the tone, because staff copy what they see senior managers do.
Key rules to remember
- GDPR data protection principles
- Lawfulness, fairness and transparency | Purpose limitation | Data minimisation | Accuracy | Storage limitation | Integrity and confidentiality | Accountability
- Use these as a checklist against the scenario. Pick the ones the facts breach rather than listing all seven by rote.
- Information security objectives (CIA)
- Confidentiality + Integrity + Availability
- Confidentiality: only authorised people see data. Integrity: data is accurate and unaltered. Availability: data is accessible when needed.
- ISO 27001 cycle
- Assess risk → Select controls → Implement → Monitor and review → Improve
- A continuous, risk-based management system, not a one-off project.
- Content of an information security policy
- Purpose and scope | Roles and responsibilities | Acceptable use rules | Access and classification | Incident response | Training | Monitoring and sanctions | Review
- A useful structure when asked to recommend or draft policy content.
- Three layers of protection
- People + Process + Technology
- Good answers cover all three, not just technical controls.
How to solve Data Protection, Privacy and Information Security Policy questions
Use this method for any question on data protection, privacy or security policy. It keeps your answer tied to the scenario and earns professional skills marks.
- 1Read the requirement and note the verb. 'Evaluate', 'recommend' and 'explain' need different depth.
- 2Pick out the scenario facts: what personal data is held, where, who has access, which countries are involved, and any past incidents.
- 3Identify the legal and regulatory exposure. Name the relevant regime, such as GDPR, and link the facts to specific principles or individual rights.
- 4Identify the information risks using confidentiality, integrity and availability, and separate human, process and technical causes.
- 5Recommend actions: a clear policy, an ISMS approach such as ISO 27001, technical controls, supplier checks, an incident response plan and staff training. Tie each one to a fact.
- 6Consider the wider consequences: fines, loss of customer trust, reputational damage, ethics and the board's responsibility.
- 7Give a reasoned conclusion or priority, noting cost and practical limits. Write in the required format, such as a briefing note or report, with a professional tone.
Quickest way: Principle, risk, control, people
When to use it: When time is short and you need a structured answer in a few minutes.
- Principle: name the data protection principle or right at stake from the scenario.
- Risk: state the harm, such as breach, fine, loss of trust or operational disruption.
- Control: give one policy, process and technical fix linked to that risk.
- People: add training, accountability and leadership tone.
- Close with a one-line priority or recommendation to show judgement.
Common mistakes in Data Protection, Privacy and Information Security Policy
Listing the seven GDPR principles with no link to the case.
Students recall the list from study notes and write it out to feel safe.
Fix: Select only the principles the scenario facts breach and quote the fact beside each one.
Treating security as purely a technology issue.
IT controls feel concrete and easy to describe.
Fix: Always cover people and process too: policy, training, responsibilities, monitoring and culture.
Claiming ISO 27001 certification means the company is fully GDPR compliant or cannot be breached.
Students overstate what a standard delivers.
Fix: Say it shows a managed, risk-based approach and gives assurance, but compliance with law and breach prevention still need ongoing effort.
Writing a generic policy with no owner, scope or consequences.
Students describe good intentions instead of the document's working parts.
Fix: Include scope, roles, specific rules, incident reporting, sanctions and a review cycle.
Ignoring the international dimension of the case.
Students assume one country's rules apply everywhere.
Fix: Check where customers, staff and data processing are located and note that several regimes may apply.
Stopping at 'there is a risk of a fine'.
Fines are the best-known consequence, so students stop there.
Fix: Add reputational damage, customer loss, operational disruption, ethical duties and board accountability, and say which matters most.
Worked examples
Example 1
Medico Ltd runs health-tracking apps in several countries, including EU states. A recent report shows staff keep customer health data on personal laptops, the data is kept indefinitely, and no staff training has been given. The board asks you for a briefing note on the data protection issues and your recommendations. (15 marks, indicative)
Show the solution
- Identify the regime: Medico offers services to EU residents, so GDPR is likely to apply even if it is based elsewhere. Health data is particularly sensitive, which raises the risk.
- Link facts to principles: data on personal laptops weakens integrity and confidentiality (security principle). Indefinite retention breaches storage limitation. No training and no evidence of controls weakens accountability.
- Assess the consequences: possible regulatory fines, loss of customer trust in a health context, reputational harm and possible loss of users and partners.
- Recommend policy: approve an information security policy covering acceptable use, device rules, data classification, retention periods and incident reporting.
- Recommend technical and process controls: company-managed devices or secure remote access, encryption, access limits, a data retention schedule with secure deletion, and supplier checks.
- Recommend people measures: mandatory induction and regular refresher training, named accountability at senior level and sanctions for breaches.
- Consider ISO 27001 as a framework to manage this systematically and give assurance to customers, while noting it takes time and cost.
- Conclude with priority: first secure the data on personal devices and set retention limits, because these carry the highest immediate exposure.
Answer: Medico likely falls under GDPR. Its main failings are insecure storage on personal laptops, indefinite retention and no training. Recommend an approved information security policy, device and encryption controls, a retention schedule, supplier checks, training with accountability, and consider ISO 27001. Prioritise securing devices and limiting retention.
Example 2
Explain the role of an information security policy and the factors that determine whether it will be effective in an organisation. (10 marks, indicative)
Show the solution
- State the role: the policy sets management's intent and rules for protecting information, so that confidentiality, integrity and availability are maintained and legal duties are met.
- Explain what it should contain: scope, roles and responsibilities, rules on access, passwords, devices and data handling, incident reporting, and sanctions.
- Link it to standards: ISO 27001 expects a documented policy within a risk-based management system that is reviewed and improved.
- Effectiveness factor 1: visible senior management support and approval, so staff treat it as important.
- Effectiveness factor 2: staff awareness and training, because many breaches come from human error.
- Effectiveness factor 3: clear ownership, monitoring and enforcement, such as audits and consistent sanctions.
- Effectiveness factor 4: regular review as threats, technology and law change, and practical rules that staff can follow without working around them.
- Conclude: a policy on paper achieves little. It works only when backed by leadership, training, controls and monitoring.
Answer: An information security policy sets management's rules for protecting information and supports legal compliance. It is effective when it is clear, supported by senior management, communicated through training, owned and monitored, enforced consistently, practical, and reviewed regularly.
Exam tips
- Always name the regime the scenario points to, such as GDPR, and link it to facts. Do not write a generic essay on data protection.
- Cover people, process and technology in recommendations. Markers reward balanced, practical advice.
- Use the format asked for, such as a briefing note, and keep a professional, measured tone to earn professional skills marks.
- Show judgement: prioritise actions, mention cost and practicality, and consider ethics and the board's responsibility.
- Avoid overclaiming. Say 'is likely to apply' or 'helps demonstrate' when the scenario does not give full legal detail.
Practice questions from IT systems security and control
- Kestrel Logistics has found that a developer who writes changes to its inventory system can also move those changes into the live environmen…
- Pelham Engineering and its overseas subsidiary exchange confidential design files by email. Management wants any recipient to verify both th…
- Marlow Bank has identified that a ransomware attack on its payment system has a high impact but a low likelihood, because of strong existing…
- Calder Logistics runs its order system from a single data centre. The board asks the IT director to document how the company would restore i…
- Kestrel Logistics runs its order system on a single server in its head office. A flood destroys the server room. Management has a documented…
Data Protection, Privacy and Information Security Policy in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Data Protection, Privacy and Information Security Policy: frequently asked questions
Do I need to memorise GDPR articles for SBL?
No. SBL tests whether you can apply data protection principles to a business scenario. Know the principles, individual rights and accountability idea, and use them with case facts.
What is ISO 27001 in simple terms?
It is an international standard for managing information security through an information security management system. It is risk-based and continuous: assess risks, choose controls, monitor and improve. Organisations can be certified against it.
What should an information security policy include?
It should state its purpose and scope, assign roles, set rules for access, devices and data handling, explain incident reporting, and set out training, monitoring and sanctions. It should be approved by senior management and reviewed regularly.
Why is staff training so important in data protection?
Many breaches arise from human error such as phishing, weak passwords or lost devices. Training makes staff aware of their duties and of the risks. It also helps the organisation show accountability.