Privacy Metrics For The Right Audience

Picture a board paper from the privacy office. It reports subject access requests closed, average turnaround in days, and the number running late. The board reads it, nods and asks nothing. None of it is wrong. All of it belongs one tier lower.

Privacy metrics fail more often through misdirection than through bad measurement. The number is accurate, the audience cannot use it, and the programme gets no benefit from having produced it.

Three tiers, three different questions

The Information Commissioner’s Office describes a reporting structure in the leadership and oversight section of its accountability framework. It expects clear reporting lines and information flows between groups, giving as examples a management board reporting to an audit committee, and an executive team reporting to an information governance steering group.

Three tiers fall out of that. Operational groups meet to coordinate the work. An oversight group provides direction across the organisation. The board, or the highest level of management, carries overall responsibility for data protection.

What the operational tier can act on

Operational groups need measures tied to work they control this month. Open requests by age. Assessments started and not finished. Vendor reviews outstanding. Training completion by team. The ICO expects these groups to meet regularly, to minute their discussions and to report issues and risks upwards to the oversight group.

A useful test: if nobody in the room can change the number by Friday, that number belongs somewhere else.

What the oversight group needs

The oversight group sits between the operational work and the board, and the ICO is specific about its content. That group should cover a full range of data protection topics including key performance indicators, issues and risks. Its outcomes feed a work plan that gets reviewed, and the minutes and reports cascade back down to operational teams.

This tier is where trend replaces snapshot. Whether the assessment backlog grew or shrank over two quarters matters more here than its size today. Privacy metrics at this level exist to direct effort, so each one should point at a decision somebody in that room can take.

What the board actually uses

The board holds accountability under Article 5(2) of the GDPR, which asks the controller to demonstrate compliance rather than merely achieve it. Directors need exposure and direction of travel: material risks, incidents that reached a notification threshold, regulatory developments affecting the business, and whether the programme is closing or widening its gaps.

The ICO expects data protection issues and risks discussed at the oversight group to reach the board or highest management level. Note the wording. Issues and risks travel upward, not raw operational counts.

Choosing privacy metrics that survive contact

Start from the decision, not the data. Ask which choice this number should inform, then ask who makes that choice. The answer usually places the metric in a tier immediately, and it exposes measures that inform nothing.

Two further habits help. Report the same measure the same way over time, because a metric that changes definition stops being a trend. Separate forward-looking indicators from performance measures: the share of systems without a completed assessment warns you about tomorrow, while time to close a rights request describes yesterday.

Where governance design comes first

None of this works without somewhere to send the numbers. Where an organisation has no oversight group, its privacy metrics reach either the board or nobody, and both outcomes waste the effort. Our piece on choosing a privacy governance model covers the structural question that sits underneath this one.

Privacy metrics in the CIPM exam

The Body of Knowledge is the IAPP’s published outline of what each certification exam tests. Metrics appear twice, and candidates lose marks by not noticing. Domain II covers defining metrics and identifying their audience as part of setting up governance. Domain V covers using collected metrics to evaluate and improve a programme already running.

Scenario questions typically name an audience and ask which measure fits, or name a measure and ask what it evidences. Read for the audience first. A distractor that offers a technically excellent metric aimed at the wrong tier is the standard trap in this area, and it catches people who revise the list of measures without revising who receives them. Our piece on privacy threshold analysis covers the assessment sequence that generates much of what you end up reporting.

Before your next revision session, write your programme’s five most-used measures on one page and mark the tier each belongs to. Anything you cannot place is a measure without a reader. The CIPM Flash Cards at €15 cover the assessment and metric vocabulary that surrounds this domain.

Similar Posts