Site icon TheCyberThrone

CISSP Domain 2 – Privacy Roles – Data Controller vs Processor vs Subject

Advertisements

When personal data is involved, one question matters more than anything else:

Who is responsible?

Not who stores the data.
Not who processes it.

But who decides what happens to it.

Why This Matters

In cybersecurity, protecting data is important.

But in privacy, accountability is everything.

Many organisations struggle not because they lack controls—

But because they lack clarity on:

CISSP tests this distinction very clearly.

A Simple Analogy: A Food Delivery Platform

Think of a food delivery app:

Now map this to data:

Each role is different.

Each has a distinct responsibility.

Data Controller – The Decision Maker

The Data Controller determines:

Responsibilities include:

Key CISSP principle:

The Controller is accountable.

They define the “why” and “what”.

Data Processor – The Executor

The Data Processor acts on behalf of the controller.

Responsibilities include:

Examples:

Important:

Processors do not decide purpose.

They execute it.

Data Subject – The Individual

The Data Subject is the person whose data is being processed.

They are not part of the system.

They are the reason the system exists.

Rights typically include:

CISSP focus:

Privacy is about protecting the individual.

The Core Difference

Let’s simplify:

Or even simpler:

Why This Structure Matters

Without clear roles:

With clear roles:

How This Appears in the CISSP Exam

CISSP will test this in scenarios like:

Your approach:

  1. Identify decision-making authority
  2. Identify execution responsibility
  3. Identify ownership of personal data

Key Takeaway

If you remember one concept, remember this:

The controller decides.
The processor executes.
The subject is protected.

🎧 Listen to the Podcast

This article is part of the CISSP Blogpost and Podcast Series.

The podcast explains this concept using real-world analogies and exam-focused scenarios in a structured format.

Search on Spotify:

PK’s Chronicles

Final Thought

Privacy is not just about securing data.

It’s about understanding:

Because without clarity in roles—

There is no accountability.

Think roles.
Think responsibility.
Think like a CISSP.

Exit mobile version