Why should boards care about privacy compliance?
1. Determine the appropriate governance model for privacy
Owing to the inherent risks posed by mishandling data, Boards should put in place an appropriate governance model which gives the Board insight into an organisation’s compliance posture. As a first step, the Board should consider appointing a Data Protection Officer (“DPO”), which is a requirement under the Data Protection Act. The DPO should be responsible for compliance and act as the company’s liaison with the Data Commissioner (the regulator). The DPO should take stock of the company’s data inventory, conduct a privacy gaps assessment and propose a compliance implementation roadmap.
2. Ensure privacy reporting metrics are well defined
For effective decision making, the board must ensure that the reporting metrics are well defined. In 2018, IAPP and EY commissioned a privacy governance report to understand, among other things, the nature matters reported to the board. According to the report, most boards received reports on the company’s status of compliance with privacy laws.
- compliance issues remediated within a specified period
- number of privacy complaints (data subjects, regulators)
- number of privacy incidents/ breaches and average time taken to resolve a breach
- results of privacy internal audits
- number of data protection trainings attended






