An enterprise security manager is defining an updated data governance and privacy enforcement framework to ensure compliance with global regulations. Match each data governance role or privacy mechanism on the left to its corresponding operational responsibility or functional objective on the right.
- Data OwnerHolds ultimate business accountability for specifying data classification levels and defining access rules based on sensitivity.
- Data CustodianImplements technical safeguards, manages encryption keys, configures access control lists, and performs database backups.
- Data Protection Officer (DPO)Oversees organizational privacy compliance, evaluates Data Protection Impact Assessments (DPIAs), and acts as regulatory liaison.
- Data ControllerDetermines the overall legal basis, scope, and business purpose for processing personal data belonging to data subjects.
Answer
Data Owner pairs with defining classification and access requirements. Data Custodian pairs with implementing technical controls, key management, and backups. Data Protection Officer (DPO) pairs with privacy compliance oversight, DPIA evaluation, and supervisory liaison. Data Controller pairs with determining the purpose and legal basis for data processing.
The correct pairings accurately reflect standard governance frameworks. The Data Owner is accountable for data classification and policy setting. The Data Custodian implements technical protection mechanisms and manages daily system operations. The DPO provides regulatory oversight and leads privacy impact assessments. The Data Controller establishes the lawful purpose and parameters for personal data collection and processing.
Step-by-Step Solution
Key Concept
Data Governance Roles and Responsibilities