Which Privacy Governance Model Fits
Choosing a privacy governance model decides where authority sits. Centralised, decentralised and hybrid answer one question. Who decides, who executes, and who is accountable when the two disagree?
The CIPM Body of Knowledge is the IAPP document that sets out what the exam covers. It puts the choice in Domain I, developing the privacy programme framework, and it arrives in a set order. Identify the sources, types and uses of personal information. Understand the business model, the operational environment and the risk appetite. Then choose the governance model, define the team structure and identify stakeholders.
The privacy governance model is a conclusion drawn from those facts. That is why exam scenarios describe the organisation before they ask.
Three shapes of privacy governance model
Three structures cover almost everything an exam scenario will describe. Each buys something and gives something up.
Centralised
One team holds the decision rights. Policy, interpretation, approvals and reporting run through a single function. Consistency stays high and interpretations do not drift between markets.
The cost is distance. The central team sits furthest from the operational detail. It can also become a bottleneck as request volume rises.
Decentralised, or local
Authority sits with business units or country organisations. Decisions land close to the facts and move quickly.
The risk is divergence. Two units answer the same question differently. Nobody notices until a regulator or an acquirer does.
Hybrid
Standards, interpretation and reporting stay central. Execution moves into the business, often through named privacy champions. I keep seeing organisations that run across several jurisdictions land somewhere in this territory.
Hybrid arrangements fail in a particular way. The split of decision rights stays implicit. The centre and the business then each assume the other decided.
What drives the privacy governance model choice
Four facts do most of the work.
Size and geographic spread set the load. One regulator and one market can be handled centrally. Twenty markets with different supervisory authorities and languages usually cannot.
Regulatory footprint matters more than headcount. A mid-sized business processing health data across several Member States carries more interpretive work than a larger business selling one product in one country.
Risk appetite sets how much local variation the organisation will tolerate. A low appetite pushes decisions towards the centre. It also accepts the slower pace that follows.
The operating model tends to settle the argument. A privacy governance model that contradicts how the business already runs gets ignored in practice, whatever the policy says. Federated businesses resist central control. Centrally run businesses resist local discretion.
The legal constraint the model has to survive
Structure meets law at the data protection officer. Article 37(2) of the GDPR lets a group of undertakings appoint a single data protection officer. One condition applies. That officer stays easily accessible from each establishment. So a centralised privacy governance model is lawful, with a string attached.
The Article 29 Working Party guidelines on data protection officers, endorsed by the EDPB, explain what accessibility means. The officer acts as a contact point for data subjects, for the supervisory authority and internally. Communication has to happen in the languages that the supervisory authorities and the data subjects concerned use. Availability can mean physical presence, a hotline or another secure channel. A team can support the officer where one person cannot cover the ground.
The EDPB then looked at how this works in practice. Its 2023 coordinated enforcement action on the designation and position of data protection officers, adopted on 16 January 2024, drew in 25 supervisory authorities across the EEA. Two of its recommendations concerned reporting lines and direct access to top management as a guarantee of independence.
That gives a practical test for any structure you assess. Reporting lines that route the officer through a business function they also advise create a conflict. The governance model that produced them makes no difference.
What the exam does with the privacy governance model
Scenario questions supply the facts and expect the model as the answer. Read for the number of jurisdictions, the sensitivity of the processing, the existing management structure, and any statement about how much variation leadership accepts.
Two traps recur. One treats centralised as the rigorous answer and local as the lax one, when the correct answer is whichever fits the described organisation. Another answers with a structure where the question asks for a first step. Establishing an inventory or a baseline usually comes before any reorganisation.
The four-step method for IAPP scenario questions applies directly here. The piece on answering for the right role helps where a question names a task and asks who owns it.
