Best Practice Report

Chief Privacy Officers Coordinate Enterprise Data Protection

August 7th, 2007
Jennifer Albornoz Mulligan
With contributors:
Michael Rasmussen , Khalid Kark


Forrester recently interviewed 21 chief privacy officers (CPOs) to better understand the roles and responsibilities of their positions. We found that the CPO role is primarily employed by organizations for three specific areas of responsibility: 1) setting corporate strategy and policy; 2) educating employees and third parties; and 3) assessing the effectiveness of the organization's privacy protection. CPOs seldom have an extensive budget or a team of more than four — even in the largest organizations with hundreds of thousands of sensitive records. They must be unbiased and have excellent interpersonal collaboration and negotiation skills to be successful. Ideally the CPO reports to an enterprise risk executive to maintain independence. Moving forward, CPOs will expand their purview beyond just employee and customer records. Because inappropriately used corporate intellectual property also harms corporations and requires similar sensitive handling procedures, CPOs will acquire responsibility to protect corporate records along with personal information.

Want to read the full report?

Contact us to become a client

This report is available for individual purchase ($1495).

Forrester helps business and technology leaders use customer obsession to accelerate growth. That means empowering you to put the customer at the center of everything you do: your leadership strategy, and operations. Becoming a customer-obsessed organization requires change — it requires being bold. We give business and technology leaders the confidence to put bold into action, shaping and guiding how to navigate today's unprecedented change in order to succeed.