June 24, 2019
Dear CISO: Who is Responsible for the Privacy of Data Subjects?
Marketing
June 24, 2019
Marketing

In Theory: The legal team/DPO should lead the privacy policy as well as manage direct interaction with data subjects, such as DSAR management.
Security should lead the implementation of the privacy policy, including how to create, monitor, and protect the organization’s personal data inventory.
In Practice: CISOs have the knowledge, tools and business processes in place to lead an end-to-end process of complying with regulatory requirements. This is because they have been doing it for many years, each one according to the relevant regulations that are part of his area.
However, there is a significant difference between privacy regulations (GDPR, CCPA, etc.) and other regulations. The direct interaction with data subjects that aren’t necessarily registered customers of the organization presents a new challenge for CISOs. Risk and legal departments have owned this type of process for many years and have gained the skills to do it while protecting the interest of the organization they represent.
To summarize:
.png)
Enable Data Security Posture Management (DSPM) for Your Entire Data Estate
October 8, 2025

Why ROT Data Must be Effectively Managed: Definition and Best Practices
September 7, 2024

Navigating the Data Tsunami: Why Network-Centric Discovery is Crucial for Modern Enterprises
November 23, 2023