Skip to main content
Category: Privacy Governance & Design

Process-Oriented Strategies

Also known as: Process-Oriented Strategy Models, Process Orientation Strategies, Process-Focused Strategies
Simply put

Process-oriented strategies are approaches that organize a business around its core workflows rather than isolated departments or tasks, with the aim of making operations more efficient and consistent. They involve defining, aligning, and continuously improving the sequence of steps used to deliver a product or service. The goal is typically to streamline how work flows through the organization so it can meet a specific business objective more effectively.

Formal definition

Process-oriented strategies denote a management approach in which an organization structures and governs itself around clearly defined, end-to-end business processes rather than functional silos, generally prioritizing operational efficiency and lean order flows as a primary objective. In practice they involve developing a system of aligned processes directed toward specific business goals, and commonly draw on established process methodologies such as lean, Six Sigma, reengineering, process improvement, and design principles applied across the organization. Implementation typically requires supporting enablers including training, effective change management, and an appropriate organizational setup, and emphasizes continuous improvement of workflows and performance. Note: this term derives from business process management and organizational strategy literature and is not a defined concept under the GDPR or data protection law; readers applying it in a privacy or compliance context should map it to the relevant legal and accountability requirements separately.

Why it matters

Process-oriented strategies matter because they reorient an organization around the end-to-end workflows that actually deliver products and services, rather than around isolated departments. When work is structured this way, organizations can pursue greater operational efficiency, more consistent output, and leaner order flows, which the evidence suggests is a primary objective of these models. For teams operating under regulatory obligations, the consistency and clarity that come from defined, aligned processes can also make it easier to demonstrate how work is actually carried out.

The relevance to privacy and compliance work is indirect but practical. Process-oriented strategies are not a defined concept under the GDPR or any data protection law; the term derives from business process management and organizational strategy literature. However, because accountability requirements generally expect controllers and processors to show how personal data is handled across their operations, an organization already structured around clearly defined, continuously improved processes may find it easier to map those workflows to legal and accountability requirements. That mapping is a separate exercise and should not be assumed to follow automatically from process orientation alone.

Because this is a management concept rather than a legal one, its benefits are framed in efficiency and performance terms rather than compliance terms. Organizations should treat any privacy or data protection alignment as a distinct step, subject to assessment against the applicable legal framework, rather than an inherent feature of adopting a process-oriented approach.

Who it's relevant to

Compliance and Data Protection Leads
Compliance and data protection professionals may encounter process-oriented strategies as an organizational context in which data-handling workflows are defined and aligned. Because the concept is not part of the GDPR or data protection law, these teams should treat the mapping of business processes to legal and accountability requirements as a separate, deliberate exercise rather than an outcome of process orientation itself.
Operations and Process Managers
Those responsible for designing and improving workflows are the most direct audience. Process-oriented strategies give them a framework for structuring the organization around end-to-end processes, drawing on methodologies such as lean, Six Sigma, reengineering, and process improvement to pursue efficiency and leaner order flows.
Change Management and Organizational Leaders
Leaders overseeing organizational structure and transformation are relevant because implementation typically requires supporting enablers, including training, effective change management, and an appropriate organizational setup. Cultivating process orientation is generally a sustained effort rather than a one-time change.
Engineers and System Designers
Engineers building the systems that support core workflows may work within a process-oriented approach, where design principles are applied across the organization and continuous improvement of workflows and performance is emphasized. Where those systems handle personal data, any privacy considerations should be assessed against the applicable legal requirements separately.

Inside Process-Oriented Strategies

Inform
A process-oriented privacy design strategy focused on providing data subjects with timely, clear, and accessible information about how their personal data is collected, used, and shared. It supports the transparency principle and typically underpins compliance with information obligations, such as those generally associated with Articles 13 and 14 GDPR. Verify the specific article requirements against the current official text.
Control
A strategy centred on giving data subjects meaningful means to exercise agency over their personal data, including mechanisms to access, rectify, erase, restrict, object to, or port data where applicable. This supports the exercise of data subject rights, though the availability of specific rights depends on the legal basis and context of processing.
Enforce
A strategy directed at committing to and operationalising a privacy policy within the organisation, ensuring appropriate governance, accountability structures, and enforcement mechanisms exist to uphold privacy commitments. This generally aligns with the accountability principle under GDPR.
Demonstrate
A strategy focused on being able to evidence compliance with the privacy policy and applicable legal requirements, for example through documentation, logging, records of processing, and audit trails. This supports the ability to show accountability to supervisory authorities and other stakeholders.

Common questions

Answers to the questions practitioners most commonly ask about Process-Oriented Strategies.

Are process-oriented strategies the same as the data-oriented strategies in privacy by design?
No. Process-oriented strategies and data-oriented strategies are typically presented as two distinct groupings within privacy design strategy frameworks. Data-oriented strategies generally focus on how personal data itself is handled (for example, minimising, hiding, separating, or abstracting data), whereas process-oriented strategies generally focus on how the organisation governs, structures, and communicates its data processing activities. Treating them as interchangeable conflates two categories that are usually described as complementary rather than identical. Readers should consult the specific framework they are relying on, as the exact groupings and terminology can vary between sources.
Does adopting process-oriented strategies mean an organisation is compliant with the GDPR?
Not necessarily. Process-oriented strategies are a design and governance concept, not a compliance certification, and their presence does not by itself demonstrate compliance. Compliance under the GDPR is context and risk dependent and turns on factors such as the identified legal basis, the specific processing activities, and the accountability evidence an organisation can produce. Process-oriented strategies can support compliance efforts, but whether any given implementation is adequate is subject to assessment against the applicable legal requirements and, where relevant, regulator guidance.
How do process-oriented strategies relate to the accountability principle?
Process-oriented strategies are generally aligned with accountability because they concern how processing is demonstrated, governed, and communicated. In most cases they help an organisation structure the internal measures and records it may need to show that it has considered and addressed privacy in its processes. However, the strategies are a conceptual aid rather than a prescribed list of accountability obligations, so organisations should map any implementation to the specific accountability requirements that apply to them.
At what point in a project should process-oriented strategies be applied?
These strategies are typically most effective when considered early and applied throughout the lifecycle of a system or processing activity, in keeping with a design-led approach. Applying them from the outset generally allows governance and communication measures to be built into how processing is structured rather than retrofitted. The appropriate depth and timing will depend on the nature, scope, and risk of the processing, and should be determined through assessment for each project.
How can an organisation translate a process-oriented strategy into concrete measures?
In practice, organisations generally move from the strategy concept to specific tactics and then to concrete controls suited to their context. This can involve defining internal policies, assigning responsibilities, establishing records and review procedures, and setting out how information about processing is communicated to individuals and internally. The exact measures are context dependent, and organisations should ensure any chosen controls map to the legal obligations that actually apply to their processing rather than adopting a generic checklist.
How do process-oriented strategies interact with a Data Protection Impact Assessment?
A Data Protection Impact Assessment, addressed in Article 35 of the GDPR, is a structured assessment used where processing is likely to result in a high risk to individuals. Process-oriented strategies can inform how an organisation approaches such an assessment and how it governs and documents its processing, but the two are distinct: the strategies are a design concept while the assessment is a specific instrument that may be legally required in defined circumstances. Whether an assessment is required in a given case should be determined against the applicable criteria and current guidance.

Common misconceptions

Process-oriented strategies are an alternative to, or replace, data-oriented strategies (such as minimise, hide, separate, and abstract).
Process-oriented strategies are generally intended to complement data-oriented strategies rather than substitute for them. In most cases both categories are applied together to achieve privacy by design, with data-oriented strategies addressing the data itself and process-oriented strategies addressing organisational and procedural handling.
Implementing process-oriented strategies is sufficient on its own to demonstrate full GDPR compliance.
These strategies are design-level concepts derived from privacy engineering literature and guidance, not statutory requirements in themselves. They can support compliance with principles such as transparency and accountability, but compliance is context and risk dependent and must be assessed against the applicable legal obligations and the current official text.
The Control strategy means every processing activity requires consent from the data subject.
Enabling data subject control does not equate to consent as a universal legal basis. Consent is only one of the distinct Article 6 lawful bases, and the rights a data subject can exercise (and the mechanisms needed) vary depending on the legal basis and processing context. Special category data may also require an additional Article 9 condition.

Best practices

Apply process-oriented strategies (inform, control, enforce, demonstrate) alongside data-oriented strategies so that procedural and technical safeguards reinforce one another.
Provide layered, clear, and accessible privacy information to satisfy the inform strategy, and periodically review notices against the applicable information obligations in the current official text.
Build accessible, tested mechanisms for data subjects to exercise their rights under the control strategy, while confirming which rights apply given the relevant legal basis and context.
Operationalise the enforce strategy through documented governance, defined responsibilities, and internal enforcement of the privacy policy rather than treating the policy as a static document.
Maintain records, logs, and audit trails under the demonstrate strategy so accountability can be evidenced to supervisory authorities on request.
Treat these strategies as design guidance and validate their implementation against current legal requirements and regulator guidance, noting that expectations may diverge between regulators and evolve over time.