TechKnowSurge
NIST 800-53 PM-23 ISC2 CISSP 2.1 NIST CSF GV.RR-02 CompTIA SecurityX 1.4 NIST 800-53 PT-1 NIST CSF GV.OC-03 ISC2 CISSP 1.4 CompTIA Security+ 5.4
VideoSecurityFree

Data Roles

Understanding data roles and terminology is essential for navigating the laws, regulations, and standards that govern how organizations collect, manage, and protect information. This content covers the standard definitions for roles such as data controller, data subject, data steward, data custodian, data processor, and data protection officer.

Complete this video to capture a CTF flag worth 1 point.

About this video

When laws, regulations, contracts, and standards all use the same terminology, there is a reasonable expectation that those terms carry consistent meaning. In practice, that is not always the case. Definitions for foundational concepts like personally identifiable information (PII) vary across different legal and regulatory frameworks, and even a single authoritative source such as NIST defines certain terms differently depending on which publication is being referenced. Recognizing this variation is important when applying compliance requirements across multiple jurisdictions or standards. Despite these inconsistencies, a set of commonly accepted data roles forms the foundation of most governance and compliance frameworks. The data controller is the organization or entity that decides what data will be collected and how it will be used. The data subject is the individual about whom data is being collected. Data stewards are responsible for maintaining data quality and ensuring data is used appropriately, while data custodians focus on the secure storage and handling of that data. These two roles may be assigned to separate teams within the same organization. Data processors are entities — often third parties — that handle the actual processing of data on behalf of the data controller. This separation of roles between controller and processor is a common arrangement in modern data ecosystems and carries distinct legal implications under various frameworks. Additionally, regulations such as the General Data Protection Regulation (GDPR) require organizations to designate a Data Protection Officer (DPO), a single individual who is legally accountable for the organization's compliance with data protection obligations. Unlike stewards or custodians, who may represent teams, the DPO carries personal legal responsibility for how the organization manages and protects personal data.

What you'll learn

What's covered

Data Roles & Terminology

Aligned to

NIST 800-53
PM-23 Data Governance Body
PT-1 Policy and Procedures
ISC2 CISSP
2.1 Identify and classify information and assets
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
NIST CSF
GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements.
CompTIA Security+
5.4 Summarize elements of effective security compliance.

Key terms

Data Controller
The entity that determines the purposes and means of processing personal data and is responsible for its lawful use.
Data Subject
An individual whose personal data is being collected and processed by another party.
Data Steward
A person or group appointed by the data controller to actively manage and use data in day-to-day operations.
Data Custodian
The IT or administrative group responsible for technically managing access rights and permissions to data.
Data Processor
An entity that processes personal data on behalf of the data controller, sometimes as a third party.
Data Privacy Officer
DPO
The organizational role responsible for overseeing data protection strategy and ensuring compliance with privacy laws and regulations. The DPO advises on data handling practices, manages privacy risk, and serves as the point of contact for data subjects and regulatory authorities.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.

Topics

Data Governance Data Privacy Gdpr Compliance Personally Identifiable Information Data Protection Officer Data Roles

Transcript

Whether we're talking about a law, a regulation, maybe it's some sort of set of standards, perhaps it's a contract we have written, we have to be talking about the same thing. So when we use certain terminology, we have to make sure we understand what that terminology means, and we define certain things like data roles.

Terminology is not consistent across standards

Now, a lot of the laws and regulations and standards that are out there have the same terminology, but there are some differences. So I just wanted to let you know that we're going to cover some of the standard ones that are out there, but that doesn't mean that it's the same thing across all of these different laws and regulations. There are some variations that are out there.

Let me just give you an example of this. Personally identifiable information, or PII, is defined in so many ways. I've seen a lot of different sources out there and they all define things a little differently, and how they categorize what's PII information is all defined a little differently. So it can get really confusing.

An example of this is NIST right here. NIST is one of these standards for cyber security that's out there. They produce a lot of resources out there so that way we can keep things secure, and it's one of the main sources of information around cyber security. And we see here that they define cyber security in many different ways depending on which document you read. And this is the standard — they're setting the standards out there — but even they have different ways that they define this. So really there's not necessarily a clear definition always with some of these different definitions, with some of these different terminologies.

The standard data roles

With that being said, let's define some of these data roles out there and the standard definitions for them.

First up is the data controller. Data controllers are the entities that determine, hey, I'm going to collect this data, and determine what's going to happen with that data. They're in charge of the data, and so usually it's some sort of organization like a business. So this business is maybe collecting information, and they're the ones who are in charge of that information.

A data subject is who the information is being collected from or about. And so in this case right here we have a user, and we're collecting information about this user, so that's the data subject.

The data controller could be assigning who is the data stewards and who is the data custodians, and this could be two different groups. The data stewards are the ones to make sure that the quality of the data, and how the data is being used, is accurate — their main concern is with the quality of that data. The data custodians is more concerned with things like the security, and making sure that the data is kept in a secure manner. So that's the data custodians.

Now a lot of times the data controllers are also processing the information, but the data processor could be different. This could be like a third party that the data controller has hired to actually do the processing of the data. Maybe the data goes directly to the data processor, gets processed and then utilized. And so there are data processors out there — that's this third-party entity that is being utilized in all of this.

Some of these laws and regulations also define other roles as well. For instance, GDPR requires that a company have a Data Protection Officer, or a DPO. Now what the problem is, is if you have data stewards and data custodians, that could be a team of people, but what they want is a single person that will be held accountable if the company is doing things illegally. So now this person, this Data Protection Officer, is legally responsible for the maintenance of protecting the data.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →