Who Owns This? The Privacy Question Most Companies Can’t Answer

My husband and I have been running a household together for years, and we still have to stop and check in regularly on who’s doing what. There are a million small things happening at once, and without checking in, we end up either both handling the same thing or, worse, assuming the other person has it and neither of us does.

This same “who’s doing what” question is also happening inside companies trying to manage multiple privacy priorities.

I was recently in a conversation with a company where legal, marketing, and product were all represented. The question on the table was: who owns the cookie tool? When I asked which cookie tool do you have – nobody had a clear answer.

In addition to not knowing who the owner of the consent software was, this company did not have any pixel governance policies or processes, including onboarding and offboarding. Without a dedicated, known owner, no one knew the last time the consent software had been tested. There were more questions and no clear direction on who had answers.

This company isn’t unique, as I see it time and again (and I talk to a lot of companies).

Ownership confusion is common, not unusual

Another company is getting their pixel governance off the ground. They’ve got new pixels and existing pixels with new use cases going on their site, and to their credit, they know those pixels need to be reviewed before they go live.

For the existing pixel, we determined that because there was never a review process in place before, they can’t just look at what changed with this one pixel. There’s no baseline to compare it to. So the review has to treat it as if everything is new.

For the new pixel, they will need to do a full diligence review.

This then raised the issue of pixel governance (one of my favorite topics) because, in theory, the company really should go backwards and review every pixel already on the site. This is just one slice of an overall TPRM program where vendors processing personal data need to be reviewed. Not all vendors are the same, and most companies take a risk-based approach. In the world of ad-tech, regulators look at these as risky, so I recommend each of them get their very own review.

Have a lot of ad-tech to review on your site? This might be a great time to consider the IAB Diligence Platform (If you’re curious for more info, I’m happy to connect you with the right folks at SafeGuard Privacy).

Many companies just don’t have a solid process around who does what in areas like cookies, TPRM, data inventory (who reviews and updates?), privacy risk assessments (who conducts, reviews, and approves), privacy rights (who processes them?), and we could keep going throughout the privacy program.

Why jumping straight to fixes feels right, and usually isn’t

When companies find a problem like an untested consent banner or a cookie tool nobody can identify, the instinct is to fix it immediately. That instinct makes sense since customers and regulators can see the website. A company’s cookie banner, consent solution, and privacy notice are the most visible, most public-facing parts of a privacy program, which might explain why our inbox is flooded with website audit requests to test the cookie consent solution, privacy rights setup, and privacy notice.

Companies often focus when there’s just a new vendor to review because it’s the urgent item. What often gets missed is the bigger picture – how do we ensure all new vendors or new changes are captured and reviewed? What should the process be? What happens when we review a vendor, and there’s a risk we don’t like – who makes the go/no-go decision?

I could create similar questions for each area of privacy (but I’ll save each one for future issues!). A privacy program needs a strategy much like any other part of business. A strategy helps steer the program and includes the why, who, what, and how.

How a Privacy Charter Helps Companies

A great way to develop a privacy strategy (aside from a privacy program assessment so you know the specific obligations in each jurisdiction) is with a privacy charter. Cool fact – it works whether a company has zero dedicated privacy people or a full team.

A good charter creates the basics of a privacy program and addresses core questions like:

  • Who owns which part of privacy across the business?
  • Who is actually responsible when something needs a decision?
  • What are the internal rules for managing a privacy program?
  • What are the privacy values for a company?
  • Do the policies, standards, and practices align with applicable privacy laws?
  • Are data processing activities aligned with the company’s core values?

A charter can then feed into how to set up the core elements of a privacy program. This is where each area of a privacy program should have a single owner. No, the “privacy team owns it” might not be specific enough to be useful when something comes up.

Who on the team launches the data inventory or reviews the privacy notice? Who actually will perform the privacy risk assessment and then review it?

This is a difficult topic, and many companies struggle with it. It’s why we built a Privacy Program Management Guide that walks through every part of a privacy program, cookie consent, data inventory, privacy notices, third-party risk, training, AI governance, and lays out who typically owns each piece, when it needs attention, and where it shows up across the business. Here’s a sneak peek of just one of the pages.

It’s built so you can go through it section by section and actually assign ownership for your own company instead of guessing.

We know some companies like the DIY approach while others prefer a guide or a full-service approach. If filling this out is giving you a headache, just let us know and we’ll do the heavy lifting for you.

As I’ve said many times over, privacy is a team sport. Teams need coaches to stay accountable and on track. The name in each privacy section box is the person accountable.

Privacy charters help companies set a privacy strategy and create ground rules for the privacy program. With people accountable for the privacy topics/areas/requirements, then companies can start actually doing the work.

What should you do?

In your next meeting, ask someone who is taking care of your favorite privacy areas (and now I’m curious – which one is it? the privacy notice, privacy rights, cookie consent software, data inventory, privacy risk assessments, TPRM, training).

If the answer is I don’t know or just a “team,” it’s time to create (or update) a privacy charter.

Jodi


💡 When you’re ready, here’s how we can help:

⚙ Privacy Advisory & Implementation: We help companies navigate privacy requirements with confidence. Our advisory support covers strategy, operations, and real-world implementation.

⚙ Fractional Privacy Services: We provide fractional privacy leadership tailored to your needs and pace. From program development to day-to-day support, we help you build and sustain a strong privacy program.