Document resource
Background Data protection in healthcare is essential but often seen as a compliance obligation rather than a shared responsibility. At St Christopher’s, we set out to take a more engaging, people-focused approach – making data protection feel accessible, relevant, and even enjoyable.Aim To embed a culture of data protection across the organisation by using creative and tailored initiatives that resonate with staff and support real-world application.Method Following initial work on aligning policy and mandatory training, a range of activities were introduced to reflect staff needs and common data challenges, including:A virtual escape room based on real-life scenarios.A hospice-wide awareness survey.Face-to-face, role-specific training sessions.Phishing simulation emails.Sticker campaigns and custom-branded icons.Rap videos with data protection themes.A month-long Cyber Awareness campaign.Visual blogs and infographics.Online tools replacing manual spreadsheets.A themed data protection quiz for social events.A developing ‘Data Protection Handbook’.Accessible privacy notices in video format for children and adults with disabilities.Results These initiatives have contributed to a shift in culture, with greater staff engagement and more frequent conversations around data protection. This is reflected in increased interaction with the Information Governance Committee, more staff approaching the Data Protection Officer directly for advice, and a rise in the number of Data Protection Impact Assessments submitted. Incident reporting has also improved, suggesting heightened awareness and ownership.Conclusion A creative, people-centred approach can help embed data protection into the culture of an organisation. This work demonstrates how even complex compliance areas can be reimagined in a way that feels practical, positive, and widely understood.