Question

Difficulty: Very hardData Governance, Classification, and Privacy Controls

An enterprise is establishing an updated data privacy and governance framework to ensure compliance with global data protection regulations and internal control standards. Match each data governance role or privacy entity on the left with its corresponding primary operational responsibility on the right.

  • Data OwnerDetermines the legal basis, business classification tier, and retention criteria for data assets.
  • Data CustodianImplements technical safeguards, access control list enforcement, and backup routines.
  • Data Protection Officer (DPO)Independently monitors regulatory compliance, conducts impact assessments, and liaises with supervisory authorities.
  • Data ProcessorProcesses personal information solely under the explicit instructions of a third-party data controller.

Answer

The correct pairings are: Data Owner matches with determining legal basis, business classification tier, and retention criteria; Data Custodian matches with implementing technical safeguards, access control lists, and backup routines; Data Protection Officer (DPO) matches with independently monitoring regulatory compliance, conducting impact assessments, and liaising with supervisory authorities; Data Processor matches with processing personal information solely under explicit instructions of a third-party data controller.
In enterprise data governance and privacy management, roles are split between executive accountability, technical management, compliance oversight, and external processing. The Data Owner determines data classification and business rules. The Data Custodian implements the technical protections requested by owners. The Data Protection Officer provides independent regulatory compliance monitoring and conducts privacy assessments. The Data Processor handles data on behalf of a controller according to strict contractual directives.

Step-by-Step Solution

1
Analyze the operational scope and accountability of governance roles versus technical roles.
Identified that the Data Owner specifies requirements (classification, legal basis) whereas the Data Custodian executes technical security controls (backups, access controls).
Business accountability rests with ownership, whereas operational technical management rests with custody.
2
Evaluate the regulatory oversight function defined by global privacy statutes.
Paired the Data Protection Officer (DPO) with independent monitoring, DPIAs, and regulatory liaison duties.
The DPO role is mandated to maintain independence from operational data processing decisions to avoid conflicts of interest.
3
Differentiate between entity-level privacy roles (Controller vs. Processor).
Paired Data Processor with processing data under the direct instruction of the controller.
Data Processors lack authority to determine processing purpose or retention timelines independently.

Key Concept

Data Governance Roles and Privacy Responsibilities
Rate this question