Skip to main content
PRACTICE GUIDE · ROLLOUT

Rolling Out Software: Acceptance Decides

Compliance software is placed in front of people who never asked for it. We show what a rollout actually fails on, which five feelings sit behind that and what a start looks like that plans for acceptance.

How it works today in most organizations

The decision is made at the top. An audit is coming up, a customer demands evidence, or management finally wants the topic in order. A tool is selected, a contract signed, and the assignment passed down: the data protection officer is to roll this out. There is budget, but no time.

What follows runs the same way in many organizations. A circular email to all department heads announces the new system, politely worded, noting that documentation will henceforth be kept centrally and verifiably. A 60-minute session shows the entire application: processing activities, systems, tasks, reports, permissions. Twenty people sit in the video call, two ask a question. At the end comes the sentence that decides the rollout: "Please enter your processing activities by Friday."

After that, nothing happens. Not out of resistance, but one reason at a time. For three participants the invitation with the login details sits in the spam folder, and nobody follows up. Two log in, see an empty overview with a "New processing activity" button and close the tab. HR carries on maintaining "Records_HR.xlsx" on the department drive: the file works, and nobody has explicitly switched it off. Purchasing waits until things have settled, and IT points out that it keeps its system list in its own tool anyway. Nobody declines, nobody objects, nobody begins.

Follow-up questions keep running through the old channel. One business unit sends its details as a reply email to the data protection mailbox, another as a filled-in Word template from last year. The data protection officer transfers both into the new system personally, because that is faster than chasing people. Exactly here the role tips over: software in which the business units work becomes software in which one person types for everyone.

The moment it becomes apparent

It becomes apparent with the first report. Three months after the start, twelve of sixty processing activities are filled in, ten by the same person. No business unit has completed a task – the task list is empty, because nobody ever assigned one. The license has run for a quarter, the process is the same as before, only the interface is new.

The rollout did not fail on a missing feature. Everything needed was there: forms, tasks, reminders, reports. It failed on a circular email, a group training session and the assumption that people use a tool because it exists. The reasons are not technical, they sit with the people involved – and can be named.

The analysis

Five Reasons Why Nobody Starts

None of them is technical. They still decide whether anything happens after the training session.

See collaboration in preeco

The fear of looking ignorant while filling in the form

A business unit is asked to name the legal basis, the categories of recipients and the retention periods – terms it was never taught. Anyone who fears documenting something incorrect would rather write nothing. Empty fields are therefore rarely disinterest, they are caution.

The unit's own spreadsheet was proof of ownership

The file on the department drive demonstrated that this unit has its topic under control. Handing it over does not feel like relief, it feels like a loss of control. As long as the file lives on, it remains the truth – and the new system a second copy.

Extra work with no recognizable benefit of its own

From the point of view of the business units, compliance is always somebody else's work. Filling in the form costs an hour, the benefit accrues to the data protection officer or in the audit. If nobody shows what becomes of the details, the task competes with day-to-day business and loses.

An activity log looks like surveillance

The log of all activities satisfies the accountability requirement under Art. 5(2) GDPR. Unexplained, it reads differently: as evidence of who works how fast. Anyone who fears that writes only what is beyond reproach – or nothing at all.

Whoever does not know where to start does not start

The first screen after the invitation shows an empty overview and a menu with twenty items. There is no question to be answered and no sequence. This disorientation lasts about two minutes, then the tab is closed again.

The target process in six steps

A rollout that holds up differs from a failed one not in the tool, but in reckoning with people. These six steps describe the sequence.

1. Begin with one unit, not with all of them. Choose the department whose documentation is furthest along, and roll out there completely. One finished unit is more convincing than sixty half-started ones. It also supplies the examples everyone else can follow.

2. Assign responsibility by name. A circular email addresses nobody, so nobody answers. Talk to the head of the unit first, then every processing activity gets a person responsible by name. Tasks are assigned to that person, the system notifies them by email, and open tasks appear on their start page.

3. Keep the first task small. Not "enter your processing activities", but: "Check the three systems recorded for your department and add the recipients." Fifteen minutes of work with a visible end. The first completed task decides the second.

4. Ask inside the tool, not by email. Details are collected through data collection forms: assigned to users or emailed to external people, with a due date, a comment and a notification on completion. Multi-page questionnaires show and hide pages and questions depending on previous answers, so nobody sees fields that do not concern them.

5. Switch the old spreadsheet off deliberately. Parallel operation is not a transition phase, it is a daily decision against the new system. Set a date from which the file is archived read-only, and state why. Without that date the file wins, because it is more convenient.

6. Make the first benefit visible. After four weeks you need a result that data protection does not read: a status report or an export of the overview table as XLSX on the table in the management meeting. Anyone who has once seen their own entry show up there will fill it in next time without a reminder.

What the interface can take on and what it cannot

An interface can make the entry point small. A personal start page shows your own open tasks after login instead of the whole system. A task board by status makes progress visible without anyone counting. Help texts sit where the question arises, and the global search is reachable from any view with Cmd/Ctrl + K. The system reminds you of deadlines itself.

What an interface cannot do: set priorities. If management announces the rollout and then never mentions it again, the task ranks below day-to-day business, in any tool. No dashboard replaces the sentence "This is part of your job", and no automation replaces a head of unit who says it.

Before and after in direct comparison

Criterion Before: rollout by circular email After: rollout with a plan
Announcement Email to everyone, no addressee Conversation with the head of unit, then assignment to individuals
First task "Enter your processing activities by Friday" One concrete task with a due date, done in 15 minutes
Responsibility "Data protection does that" One person responsible by name per processing activity
Entry into the interface Empty overview, full training on every feature Start page with your own open tasks, help texts in the form
Follow-up questions Email thread in the data protection mailbox Data collection form with a due date and a comment
Progress visible Only by manual counting Task board by status, dashboard, export as XLSX
Language of the participants One interface in the corporate language Interface language per user, separate from the document language
Parallel operation Old spreadsheet runs on indefinitely Switch-off date is set and explained

In practice

This Is What It Looks Like in preeco

Three building blocks that keep the entry point small for the people involved.

What the switch means in practice

The first few weeks cost more time than the old state, not less. In that phase you clarify what the spreadsheet left open: who is responsible for this processing activity in substance, which system is really behind it, who is a recipient. That clarification is the work – entering the details afterwards is the smaller part. Saying so openly loses less trust than promising relief from day one. Plan that phase in with the people involved instead of treating it as a teething problem.

Three mistakes that make the rollout unnecessarily hard

Starting every unit at the same time. Addressing sixty people with the same email does not produce sixty contributors but sixty unread tasks. One unit after another takes longer in the calendar and shorter in the result.

Confusing the training with the rollout. A one-off session covering every feature does not stick, because nobody has a concrete task at the time. What works is separate training for administrators and end users, and after that help texts where the question comes up.

Not explaining the activity log. It serves accountability, not performance monitoring. Say so beforehand instead of justifying it after the first question, and agree the rollout with the works council as for any other IT system.

How to tell that the rollout is tipping over

  • The task list in the system is empty although work is outstanding.
  • Details arrive as an email or a Word file, not through a form.
  • You enter yourself what a business unit was supposed to enter.
  • The old spreadsheet has a newer modification date than the entry in the system.
  • In meetings the system is called "your tool", not "our records".

If one of these applies, another circular email will not help. What helps is picking one unit, naming one person and assigning one small task. A rollout is not saved by repeating it, but by shrinking it until it works in one place.

FAQ

Frequently Asked Questions About the Rollout

In most cases what is missing is not the willingness, but an addressee and a beginning. As long as a task goes to "everyone", nobody feels responsible; as long as the first screen shows an empty overview, there is no entry point. A small task assigned by name with a due date changes behavior more reliably than another training session.

Technically, provisioning is quick: in the cloud and in the private cloud the environment is ready within 48 hours on working days. The organizational rollout is the actual task, and its duration depends on the number of units, the quality of the preparatory work and the backing of management. There are no reliable average figures for that, which is why we do not quote any.

No, and it is usually counterproductive. What makes sense is training for the administrators at the start and an end-user training session whenever a unit actually begins. Both formats are part of onboarding, supplemented by individual training, video tutorials as well as documentation and help texts inside the application.

With an announced switch-off date, not with a request. The existing content is taken over first, so that nobody loses work; after that the file is archived read-only and the reason is communicated. If the file stays editable, it stays the leading source.

The purpose of the log is the traceability of changes to documents – a requirement of the accountability principle under Art. 5(2) GDPR. Explaining it in advance takes the edge off the topic. As with any other IT system, the rollout should be agreed with the works council. In addition, confidentiality classes can be activated, which make sensitive content accessible only to the user groups that need it.

Plan Your Rollout With Us

Bring your units and your schedule. In 30 minutes we go through which unit to start with and which first task works.