The Conventional Wisdom
When COVID-19 hit, many privacy thought leaders advocated for Chief Privacy Officers to have a seat at the executive table. The idea was that during crises, rapid data-sharing decisions are needed, and privacy officers should guide these choices, balancing public health against individual rights.
It's a compelling vision: privacy officers as strategic advisors shaping emergency responses. However, observing how emergency data sharing unfolded reveals a different story. For example, telecommunications companies in Germany, Brazil, and China granted governments access to cellphone location data, while the Dutch Supervisory Authority called for emergency legislation first, and Canadian Prime Minister Justin Trudeau refused entirely. This suggests that most privacy officers shouldn't be making these calls in the boardroom. They should focus on more valuable contributions.
Why We Disagree
The boardroom framing misunderstands what privacy officers excel at. When you involve a privacy officer in an emergency board meeting about sharing customer location data with health authorities, you're asking them to make a political risk calculation disguised as a compliance question.
This isn't a privacy decision; it's a values decision.
During COVID-19, the choice to share or withhold location data wasn't mainly about GDPR Article 6 lawful basis selection or whether processing met the necessity test under Article 9. It was about national policy, public trust, and political consequences. Germany shared data, Canada didn't. Both had competent privacy officers and were bound by similar legal frameworks under GDPR and PIPEDA.
The difference wasn't privacy expertise; it was political will.
When you ask privacy officers if customer data should be shared to track a pandemic, you're really asking: "What reputational risk will we face if we say yes? What if we say no and people die? What will our customers think?" These are legitimate executive questions, but they're not privacy questions. They're business strategy questions involving personal data.
Privacy officers who try to answer them are working outside their expertise. Worse, they're neglecting the work only they can do.
The Evidence
During emergency data sharing, privacy officers didn't make the yes-or-no decision. Executives made that call based on government pressure, public sentiment, and competitive positioning.
Privacy officers contributed the constraints. They mapped what was technically possible under existing legal frameworks. They identified which Article 6 bases could apply (legal obligation, public interest, vital interests). They documented why consent wasn't viable for emergency processing. They drafted the supplementary measures needed if data crossed borders. They built the retention rules so location data didn't become a permanent surveillance archive.
The Dutch Supervisory Authority's call for emergency legislation before any sharing occurred reflects this distinction perfectly. They didn't say "never share" or "always share." They said "build the legal framework first." That's the privacy officer's actual contribution: defining the guardrails, not choosing the destination.
When privacy officers try to be strategic advisors on whether to share data during a crisis, they dilute their authority on the questions they're uniquely qualified to answer. If you've spent political capital arguing against sharing location data and you lose that argument, how much credibility do you have left when you need to enforce a 30-day retention period?
What to Do Instead
Privacy officers should stay out of the "should we" conversation and own the "if we do, here's how" conversation completely.
Before the board meeting, prepare three scenarios:
Scenario one: We share aggregated, anonymized movement patterns. Document the Technical and Organisational Measures required, the retention period, the supervisory authority notification requirements if this qualifies as high-risk processing, and the supplementary measures needed for any cross-border transfers.
Scenario two: We share individual-level location data under legal obligation. Map the specific legal basis, draft the required transparency notice updates, identify the data minimization constraints (which fields, which time windows), and specify the data importer agreements needed if government systems are involved.
Scenario three: We decline to share. Outline the documentation required to demonstrate you considered the request, the public communications needed to explain the decision, and the regulatory consultation process if a supervisory authority challenges the refusal.
Hand executives the scenarios. Let them choose. Then you implement whichever path they select with full compliance rigor.
This approach does three things the boardroom-advisor model doesn't:
You maintain independence. When you're not the person who decided to share data, you can enforce the constraints without political contamination.
You demonstrate expertise. Executives don't need another voice saying "this is risky." They need someone who can operationalize whatever risk they decide to take.
You create an audit trail. When a supervisory authority asks why you shared location data during COVID-19, "the board decided it was necessary" is much weaker than "we implemented sharing under Article 6(1)(e) public interest basis, applied these specific data minimization controls, and enforced this retention rule."
When the Conventional Wisdom IS Right
Privacy officers shouldn't be excluded from strategic discussions entirely. There's one scenario where the boardroom seat makes sense: when the decision itself is a compliance decision.
If the question is "which consent management platform should we buy," the privacy officer belongs in that conversation because the answer directly determines your ability to demonstrate freely given consent under GDPR Article 7.
If the question is "should we launch this product in California before CPRA takes effect," the privacy officer's input is strategic because timing directly affects your regulatory obligations.
But "should we share customer data during a pandemic" isn't a compliance question. It's a policy question that triggers compliance obligations. Privacy officers should shape those obligations, not make the policy.
The role confusion happens because data protection regulations use normative language. GDPR says processing must be "necessary" and "proportionate." That sounds like it's asking privacy officers to make value judgments. It's not. It's asking them to document that someone made a value judgment and implemented it within legal constraints.
Your job isn't to decide whether tracking COVID-19 justifies location data sharing. Your job is to ensure that if your organization decides it does, the sharing happens lawfully, transparently, and with appropriate safeguards. That's not a smaller responsibility. It's a more defensible one.



