← Scenario Library

IT admin discovers conflicting gender data across three systems

Systems & Data Free

Diagnostic domain: Systems & Data Integrity


Alex
Alex (They/them)

This persona tests how organisations handle conflicting identity data, whether discrepancies are treated as sensitive personal data, and how binary system design creates indirect discrimination, privacy exposure and dignity harm.

What Has Happened

Alex, the IT systems administrator, runs a data integrity audit and discovers that one employee is recorded as 'female' in HR, 'male' in the pension system, and has no gender marker in payroll. They are unsure whether to flag this, to whom, and what data protection rules apply.

Why This Is Difficult

This is difficult because records or linked systems can expose sensitive information without warning; rigid rules or system categories are narrowing the available options; the role-holder may be unsure what good practice looks like in the moment.

Your Role

You are the HR, IT, payroll, or data owner responsible for fixing the record and limiting disclosure.

The Key Question

Decide whether there a documented protocol for handling gender data discrepancies across systems.

Practitioner Access Required

This content is available to Practitioner subscribers. Visit our pricing page to upgrade to one of our subscription plans.

Key Questions
  1. Is there a documented protocol for handling gender data discrepancies across systems?
  2. Does the data protection policy address the sensitivity of gender history as special-category data?
  3. Who is the designated data controller for gender-related fields, and how should IT escalate?
Stakeholder Perspectives

Subject Risks

  • privacy breach or involuntary disclosure
  • loss of dignity, trust, or access
  • data visibility and former-name exposure risk

Cisgender & Other Considerations

  • other stakeholders may be affected by poor records discipline, but not entitled to unnecessary disclosure

Role-Holder Risks

  • must avoid ad hoc decision-making
  • must distinguish discomfort from misconduct
  • must preserve audit integrity without exposing sensitive history
  • must minimise visible access to legacy data

Organisational Risks

  • consistency, legal, data, governance, and reputational exposure if handled badly
Balancing Framework
What would a proportionate response look like that respects dignity, privacy, role clarity, and legitimate stakeholder concerns without defaulting to humiliation, outing, blanket exclusion, or informal improvisation?

Stakeholders Affected

Primary subject Organisation Staff / role-holder

Legitimate Interests in Tension

Dignity Privacy Fair treatment Data minimisation Accuracy Need-to-know access
Balancing Principle: Respect all stakeholders, but do not universalise one stakeholder's comfort into another's exclusion.
Risk Dimensions 9
Visibility Mode Administratively Visible

Exposure comes through records, systems, or administrative processes rather than appearance.

Association Impact None

No significant impact on third parties.

Commercial Salience Medium

Moderate commercial or reputational risk if mishandled.

Administrative Exposure Audit Or Reporting Chain
Binary System Coercion Medium

Moderate pressure โ€” systems default to binary but alternatives exist.

Data Propagation Risk Medium

Some risk of sensitive data flowing between connected systems.

Protective Vigilance Low

Minor self-protective behaviour โ€” occasional caution.

Role-Holder Uncertainty Medium

Staff have some guidance but may hesitate or lack confidence.

Post-Incident Narrative Risk Internal Only

Any fallout stays within the organisation.