Data management regulations are expanding globally, and organizations must understand data sovereignty, defined roles, ownership rights, and retention obligations to stay compliant. This content covers the frameworks and responsibilities that govern how data is collected, protected, and removed.
Data Management
It's more important now than it ever has been before that we manage our data correctly. There are more and more regulations and laws that are being put into place that make sure companies are managing their data well.
Data sovereignty is the idea that there are authorities, like government entities, that create laws and regulations on how we can capture and use data within an area. That area could be just a local or regional level, or perhaps it's a state or province level, it could be a national or country level, or perhaps it's even a global level. But the idea is that if you have data for users within a certain area, then you have to fall under the laws and regulations of that area.
We've defined several data roles, and we do that so that when we talk about data sovereignty and the expectations when it comes to managing the data, we know who's responsible for what and have this common language.
As an example, we have the data subject. Let's say I go to a website and I'm typing in my address because I'm purchasing something and I want something delivered. They are collecting my information, so I am the data subject in this example.
Now somebody is processing that data, is collecting and processing the data - that is the data processors. A lot of times that data processor is also the person who is the data controller, who has a say in what is happening to that data. Not always: sometimes the data controllers pass off the processing to another third party, and so that is the data processors. But often the data controllers, who are in charge of that data, and the data processors are the same entity.
The data controllers are going to appoint data stewards. These are the actual people and groups that are going to be controlling the data, that are going to be using the data, to process the data. We also have the data custodians. They're the ones that are in charge of giving rights and permissions - usually this is like the IT group right here.
Let's look at it from a little different perspective, from an access management standpoint. We want to protect this data, so we have different roles within this. We have the users or stewards of this data who need access to this data so that way they can process information. The problem is, you don't want people to just be able to elect that they need access to this data and get access to that data, and you don't want to open it up to everyone within the company.
So what happens is you appoint a data owner, and the data owner is the one that's going to say yes or no on whether certain people get access to this data or not. They're in charge of making sure that the right people have access to the data, but they're not necessarily in charge of controlling the access list. Whoever is going to technically implement the protections in regards to safeguarding this data, that's going to be some sort of IT admin or system admin. So you've got the data custodians - the data custodians are the ones that are actually managing the access list there.
Of course, we want to audit this process, so we have an auditor. This is an outside party - maybe it's the security department, maybe it's a third party, maybe it's some other company that's coming in to do the auditing - but they're going to make sure that all the rules are being followed and proper access is being maintained.
Many laws and regulations are being put into place, such as GDPR, to control or mandate that there is a Data Protection Officer. This is going to be a single person that's responsible, out of all of these different roles, for making sure that data is being kept safe and protected.
A lot of laws and regulations are now defining who has the data ownership. It used to be just assumed that whoever was the data controller owned that data: they would collect the data and then they would be in charge of controlling that data, and so they own that data. But more and more laws and regulations are saying that if you're collecting data from a subject, they are actually the owners of that data, and you have the right to possibly use that data but the ownership goes back to the data subject.
One of the reasons why that's important is that a lot of laws and regulations are saying that these data subjects have the right to be forgotten. That is, if you're collecting data from them, they can come back and say, I don't want you to keep that data anymore, you must delete that data.
It's really important to understand what data we are collecting from our users, and we may need to perform some sort of data inventory to understand what data we have, so that way if a subject does request for us to remove that data, we're able to do that.
We also need to consider the retention side of things. That is, we may take this data and be responsible for keeping records of that data for a certain period of time, so maybe we put some of this data, after we're done using it, in some sort of archive. This is important for a couple of reasons. We may be legally bound, or maybe our clients are demanding that we keep their data for a certain period of time, so if they need to do a restore or they need to do some sort of accountability check they can do that. But at the same time, there's certain data that we may have to get rid of right away, so we may have to go into those archives and delete data if a customer is requesting it. So it's quite a balance of being able to make sure that we're retaining things for the proper period of time, but also removing data that we shouldn't be collecting any longer.
If you're collecting data from a data subject, then you're responsible for knowing the laws and regulations of the data sovereignty of wherever that data subject lives, and you have to keep that in mind when you're collecting it.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →