Data Governance Roles

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:15 PM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

An organization determines that customer information should only be used for specific business purposes and establishes the requirements for how that information may be processed. Which role is primarily responsible for making these decisions?

A. Data Custodian
B. Data Subject
C. Data Controller
D. Data Processor

C. Data Controller

Data Controller → Why and how is personal data processed? Determines the purposes and means of processing personal or business data.

2
New cards

A database administrator configures access controls, encryption, backups, and other technical safeguards according to the organization's data-protection requirements. Which data governance role best describes this individual?

A. Data Owner
B. Data Subject
C. Data Custodian
D. Data Controller

C. Data Custodian

Data Custodian: The IT or technical staff responsible for the physical and system infrastructure, such as data storage, backups, encryption, and access control implementation.

3
New cards

Which role is responsible for establishing and enforcing business rules and policies governing how data should be managed and protected?

A. Data Steward
B. Data Custodian
C. Data Subject
D. Data Processor

A. Data Steward

Data Steward → What rules/policies should govern the data?

4
New cards

Which role has ultimate responsibility and accountability for a particular set of organizational data?

A. Data Custodian
B. Data Owner
C. Data Processor
D. Data Subject

B. Data Owner

Data Owner → Who has ultimate accountability/authority over it?

5
New cards

A data owner establishes a requirement that confidential customer records must be encrypted. A security administrator then configures the database to enforce encryption. Which role is the security administrator performing?

A. Data Owner
B. Data Controller
C. Data Steward
D. Data Custodian

D. Data Custodian

Data Custodian → Implementing the controls

6
New cards

A company creates a policy stating that employee records must be retained for seven years and must only be accessed by authorized personnel. Which role would primarily be responsible for developing and maintaining these data governance rules?

A. Data Subject
B. Data Steward
C. Data Custodian
D. Data Processor

B. Data Steward

Data Steward → What rules/policies should govern the data?

7
New cards

An organization has established policies describing how sensitive data must be classified, retained, accessed, and protected. Which role is primarily responsible for maintaining these data governance rules?

A. Data Subject
B. Data Custodian
C. Data Steward
D. Data Processor

C. Data Steward

8
New cards

A database administrator configures role-based access controls based on requirements established by the organization. Which role is the administrator performing?

A. Data Steward
B. Data Custodian
C. Data Subject
D. Data Owner

B. Data Custodian

Data Custodian: Actually implements the controls

9
New cards

Which statement BEST describes the difference between a data steward and a data custodian?

A. The steward owns the data, while the custodian is the person the data describes.

B. The steward establishes and manages data governance requirements, while the custodian implements controls to protect the data.

C. The custodian establishes and manages data governance requirements, while the steward implements controls to protect the data.

D. The steward is responsible for collecting data, while the custodian determines who owns it.

B.

10
New cards

A data steward determines that employees should only have access to customer information necessary for their job functions. Who would typically be responsible for configuring the technical access controls that enforce this requirement?

A. Data Custodian
B. Data Subject
C. Data Controller
D. Data Processor

A. Data Custodian

11
New cards

Data Owner

Ultimately responsible for a data asset

12
New cards

Data Steward

Determines the rules/policies governing the data

13
New cards

Data Custodian

Actually implements the controls that are required to meet the policy/rule requirements set by the Data Steward

14
New cards

Data Controller

Determines the purposes and means of processing the data. WHY the data is being processed.

15
New cards

Data Processor

Processes/uses the data on behalf of and strictly according to the instructions of the Data Controller.

16
New cards

Where does the Data Processor get its instructions from?

A. Steward

B. Controller

C. Owner

D. Subject

B. Controller

17
New cards

Where does the Data Processor get its instructions from?

The Data Controller

18
New cards

Data Subject

The person who’s data is being processed/used/is about

19
New cards

Data Protection Officer (DPO)

A high-level compliance manager overseeing an organization's overall data privacy framework and regulatory adherence

20
New cards

DPO

Data Protection Officer.