Which statement BEST distinguishes a privacy programme from a data governance programme within an organisation subject to multiple privacy regulations?
- AA privacy programme operates inside the legal function, while data governance is an information technology programme accountable to the chief information officer for technical metadata catalogues.
- BA privacy programme is a one-off implementation aligned to a single regulation, while data governance is a continuing programme that maintains a data dictionary and lineage records.
- CA privacy programme is concerned with protecting confidentiality of all sensitive records, while data governance is concerned with ensuring availability of operational systems to authorised users.
- DA privacy programme focuses on the lawful handling of personal data and individual rights, while data governance defines accountability, quality and stewardship for all enterprise data assets. Correct
Why A is wrong: Reporting lines vary by organisation and are not the defining difference; framing the distinction as departmental ownership misses that both programmes are cross-functional and that privacy obligations cover technical, legal and operational domains.
Why B is wrong: Privacy programmes are continuing, not one-off, and must address overlapping regulations across jurisdictions; presenting privacy as static reflects a common misconception that ignores the need for ongoing monitoring and updates.
Why C is wrong: This conflates privacy with information security confidentiality and reduces data governance to availability; both programmes have broader purposes than these two security attributes and the answer ignores personal data and stewardship.
Why D is correct: This captures the conceptual split that the CISA blueprint draws: the privacy programme is built around personal data lifecycle obligations and data-subject rights, whereas data governance addresses the broader management of data as an enterprise asset across quality, lineage and stewardship.