CISSP Resources · Domain 2 — Asset Security

Data Owner vs Data Controller vs Data Custodian

One of the most common CISSP exam traps: two answers are technically correct but only one role has the authority the question is asking about. This guide separates the four roles you need to know cold.

The 30-second version

  • Data Owner — decides what the data is worth and who gets access. A business role, not a technical one.
  • Data Controller — a GDPR term. Decides why and how personal data is processed. Legally accountable to regulators.
  • Data Custodian — implements and maintains controls. Runs backups, patches the database, provisions access the way the Owner specified.
  • Data Processor — a GDPR term. Handles personal data on the Controller's instructions.

Side-by-side

RoleResponsibilityAuthorityAccountable?
Data OwnerClassifies the data, defines protection requirements, approves access.Senior business/management role. Ultimately accountable for the data.Yes — the buck stops here for how the data is classified, protected, and used.
Data Controller (GDPR)Determines the purposes and means of processing personal data. Legal responsibility for compliance.Legal/regulatory role under privacy law (GDPR, UK DPA, similar). Often the organisation itself.Yes — legally accountable to regulators and data subjects for lawful processing.
Data CustodianImplements and maintains controls the Data Owner specified: backups, access provisioning, patching, encryption at rest.Technical/operational role (DBA, sysadmin, storage team). Does not decide classification.Operationally responsible for day-to-day protection, not for what the data is or how it may be used.
Data Processor (GDPR)Processes personal data on behalf of the Data Controller, only on documented instructions.Third party or internal team acting under contract with the Controller.Limited — must follow Controller's instructions and secure the data; Controller remains accountable to regulators.

Who is responsible for X?

Classifying the data: Data Owner. Not the custodian, not IT, not security.

Approving who gets access: Data Owner. Custodians provision the access the Owner approves.

Running nightly backups and applying database patches: Data Custodian.

Deciding the lawful basis for processing personal data: Data Controller.

Processing personal data under a signed agreement on the Controller's instructions: Data Processor.

Being ultimately accountable if the data is misclassified or mishandled: Data Owner (organisationally) and Data Controller (legally, for personal data).

CISSP exam tips

  • If the question is about classification, access approval, or acceptable use, the answer is almost always Data Owner.
  • If the question mentions GDPR, personal data, lawful basis, or regulators, switch into privacy-law vocabulary: Controller vs Processor.
  • If the question is about backups, patching, encryption at rest, or storage administration, the answer is Data Custodian.
  • Watch for "BEST" and "PRIMARY" — a Custodian may technically do the work, but the Owner is the one accountable for the decision.

Practise these role questions

Domain 2 (Asset Security) questions on Domain Eight test these distinctions with scenario-based, best-answer style questions.