TechKnowSurge
NIST NICE K0678 NIST NICE K0681 ISC2 CISSP 2.4 CompTIA SecurityX 1.4 NIST NICE K1192 NIST 800-53 PM-23 ISC2 CISSP 2.1
VideoSecurityFree

Compliance, Privacy, and Data Roles

Data privacy compliance is a growing priority for organizations worldwide, shaped by evolving laws and regulations that define how personal data must be collected, managed, and protected. This content covers core privacy concepts, data subject rights, key regulatory frameworks like GDPR, and the defined roles organizations must fulfill to remain compliant.

Complete this video to capture a CTF flag worth 1 point.

About this video

Data privacy has become one of the most consequential areas of compliance for modern organizations, driven by a growing body of legislation that governs how personal information is collected, processed, and protected. At its core, privacy refers to an individual's freedom from unwanted observation or intrusion, and laws like the EU's General Data Protection Regulation extend that principle into the digital space, establishing enforceable standards that apply to any organization handling data about individuals within a given jurisdiction — regardless of where the organization itself is headquartered. This concept of data sovereignty ensures that a U.S. or Australian company collecting data on EU residents must still comply with GDPR, making jurisdictional awareness a critical competency for compliance professionals. A central theme across most major privacy frameworks is the question of data ownership. Even when an organization generates or processes data about an individual, ownership typically resides with the data subject — the person the information pertains to. This gives data subjects a range of enforceable rights, including the right to access their data, the right to erasure, data portability across service providers, and the right to be notified in the event of a breach. Regulatory models differ in how they approach consent: some operate on an opt-out basis, prohibiting contact only after a subject has explicitly declined, while others require affirmative consent before any marketing or data use can occur. Compliance frameworks also establish clearly defined data roles to ensure accountability throughout the data lifecycle. Data controllers determine how and why data is used, while data processors handle the technical execution — such as payment processing — and may be separate entities entirely. Data custodians are responsible for the security and integrity of stored data, and data stewards ensure ongoing accuracy and quality. Understanding these distinctions is essential for IT and security professionals, as each role carries specific legal and operational responsibilities that shape how an organization must structure its data governance practices.

What you'll learn

What's covered

Data Privacy & Compliance

Aligned to

NIST NICE
K0678 Knowledge of privacy laws and regulations
K0681 Knowledge of privacy principles and practices
K0681 Knowledge of privacy principles and practices
K1192 Knowledge of organizational privacy policies and procedures
ISC2 CISSP
2.4 Manage data lifecycle
2.1 Identify and classify information and assets
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements
NIST 800-53
PM-23 Data Governance Body

Key terms

Data Subject
An individual whose personal data is being collected and processed by another party.
Data Controller
The entity that determines the purposes and means of processing personal data and is responsible for its lawful use.
Data Processor
An entity that processes personal data on behalf of the data controller, sometimes as a third party.
Data Custodian
The IT or administrative group responsible for technically managing access rights and permissions to data.
Data Steward
A person or group appointed by the data controller to actively manage and use data in day-to-day operations.
Right to Access
A consumer right that allows individuals to request and view the personal data an organization has collected about them.
Right to Be Forgotten
A regulatory right that allows data subjects to request the deletion of their personal data from an organization's records.
Data Portability
A consumer right that allows individuals to have their personal data transferred from one service provider to another.
Breach Notification
The legal obligation for a data collector to inform data subjects when their personal data has been compromised in a security incident.
Data Sovereignty
The concept that data is subject to the laws and regulations of the geographic region in which it originates or is collected.

Topics

Data Privacy Gdpr Data Subject Rights Compliance Data Governance Privacy Regulations Cybersecurity

Transcript

How companies manage data is a hot topic right now, and there are more and more laws and regulations that are either coming out or being altered to make sure that we're thinking about and managing our data correctly.

Privacy

Privacy just means free from being observed or disturbed. Let me give you some examples of this. If you are at home, you don't necessarily want somebody knocking on your door all the time trying to sell you something, or calling you on the phone all the time trying to talk with you and sell you something. You don't want all of those disruptions, so you have a certain level of privacy. Same thing with online and with technology: you have a certain right to some privacy, and that's what laws and regulations help enforce.

Although laws and regulations are quite different depending on where you're from, there is some commonality amongst many of these. So we're going to talk about some common privacy concepts, about privacy and ownership and the different rights that these owners, or data subjects, have, and about the different data roles.

Data sovereignty

As I mentioned, depending on where you're from you could have different privacy laws that protect you. For instance, if you're in the European Union you have GDPR, and that's one of the newer privacy laws and regulations that are out there that protect its citizens.

This idea of data sovereignty means that you get protected against the laws and regulations of wherever you're located at. So for instance, if you're in the European Union, then you're protected by GDPR even if it's an American company that's collecting the data, or an Australian company that's collecting the data — they still have to comply with the laws and regulations that GDPR sets out.

Ownership

One of the key factors in a lot of these privacy laws revolves around ownership. If there is a company out there that's collecting data — we call it the data collector — then they don't necessarily own that data that they are collecting, even if they are the ones that created that data. If they created that data based off of a data subject — that's you and I, the citizen, whoever they're collecting the information about — then the ownership relies on the data subject. So if they're collecting information about the data subject, then they don't necessarily have ownership over that data, and the data subject gets to make the call on how this company can use that data.

Rights the data subject has

For instance, data subjects often have a right to access. That is, they can ask this company, this data collector, and say what information do you have on me, and then they have to provide that data to the data subject.

There's also a concept of right to be forgotten. That is, the data subject can say to the data collector, I don't want you to store information on me, and then they have to remove that information from their data stores. The reverse is true as well: there are data retention laws, which means that if you're holding data on somebody, you can't necessarily just delete that data without this data subject's permission. That doesn't always apply, but that is something that is out there — sometimes there are data retention requirements.

There's this idea also of data portability, where the data subject can take their data from a data collector and move it to another company. We see this in cases like medical records: you're not stuck going to the same medical facility. If they're doing a terrible job, you can tell them I want to switch to another company, I want to take my medical care to another place, and so you have the right for the data records at this health care facility to be moved to another health care facility.

Many of these laws address discrimination — that you can't utilize this data to discriminate against a data subject. A lot of times it also addresses data breach notification: that if this information were to ever be stolen, this data collector would have to notify the data subject that the information was stolen, that there was a data breach and the information was taken.

Opt out versus consent

Many of these laws have an opt-out approach. That is, the data collector cannot contact or market to the data subject if the data subject says I don't want you to reach me, I'm opting out of you communicating with me, of you selling stuff to me, and you aren't allowed to use my data to market to me. That's an opt-out approach.

Other policies and laws have more of a consent approach. That means that they can't market to you even to begin with unless they get permission from the data subject — the data subject has to say yes, you can actually send me marketing material, and only then can the data collector do that.

Data roles

Many of these laws and policies also define what data roles are. This is so we have a common set of language and understand our roles and responsibilities when it comes to our part and how we play into these policies. So let's take a look at some of the common data roles that you can see out there.

  • We already mentioned the data subject: who the information is being collected about.
  • We also mentioned the data controllers: who is collecting that data. The controllers are the ones that are actually saying what's going to happen with the data.
  • It could be different than the person, or the entity, actually processing the data, so there are data processors that are out there. For instance, a lot of times companies will send you, if you're purchasing something, to a data processor to actually do the processing of that credit card, so it doesn't necessarily touch this data controller aspect to it.
  • There are also data custodians. These are the ones that are in charge of the security of the data that's being collected, to make sure that it's being collected and processed in the appropriate way, that it remains secure, that it has the proper permissions on it, and all of that.
  • There are also the data stewards, who are the ones to make sure that the data is remaining accurate, that the data that's being collected is accurate to the best that the company can.

I can tell you from experience that a lot of these laws and regulations put quite a bit of strain on many different IT departments. There are quite a few things that we need to do to make sure we manage this data correctly. But after all, that is for the best, because essentially what we're doing is protecting our customers from the same thing that we want to be protected from, from companies who hold our data. So we need to be good stewards.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →