3.5 Governance Bodies, Program Charter & Escalation Paths

Key Takeaways

  • Indicator II.A.1 requires an organizational model, responsibilities and reporting structure appropriate to the size of the organization — the exam tests fit, not maximum formality.
  • A privacy program charter is the founding governance document: mandate, scope, authority, decision rights, membership, cadence and reporting line, approved by the executive body.
  • A privacy steering committee owns cross-functional decisions and resource trade-offs; a working group executes; the board or audit committee receives assurance and approves risk acceptance.
  • Decision rights must be written down in advance: who can approve a new processing purpose, who can accept residual risk, and who can veto a launch.
  • Escalation needs a trigger, a route, a clock and a decision-recording step — an escalation path with no time limit is a queue, not a control.
Last updated: August 2026

The Structure That Makes Decisions Repeatable

Domain II opens with II.A.1 — establish the organizational model, responsibilities and reporting structure appropriate to size of the organization. Two words carry weight: appropriate and size. The exam does not reward maximum formality. A 40-person company that stands up a board sub-committee, a steering committee and three working groups has built governance theatre; a 12,000-person multinational that runs privacy through a monthly email from one manager has built a liability.

The program charter

The charter is the founding document that converts "we have a privacy person" into "we have a privacy program." It should state:

Charter elementWhat it fixes
MandateWhy the program exists, in business terms
ScopeEntities, jurisdictions, data categories and processes covered — and what is out of scope
AuthorityWhat the privacy function can require, and what it can stop
Decision rightsWho approves new purposes, accepts residual risk, and vetoes launches
StructureBodies, membership, quorum, cadence
Reporting lineWho the privacy leader reports to, and how the board receives assurance
ResourcingHeadcount, budget, tooling commitments
ReviewWhen the charter itself is reconsidered

The authority clause is the one candidates undervalue. A program that can advise but cannot delay a launch has no leverage at the moment leverage matters. That does not mean privacy holds an absolute veto — it means the charter states explicitly whether privacy can block, and if not, who must sign to proceed over a privacy objection. Either answer is defensible; silence is not.

The three-tier stack

TierMembershipOwnsTypical cadence
Board or audit committeeNon-executive directorsAssurance, appetite approval, acceptance of material residual riskQuarterly or semi-annual
Privacy steering committeeExecutives from legal, security, IT, HR, marketing, product, procurementCross-functional decisions, prioritisation, budget trade-offs, escalationsMonthly or quarterly
Privacy working groupPractitioners and privacy championsExecution, assessments, remediation tracking, day-to-day issuesWeekly or fortnightly

Small organizations legitimately collapse these. A 150-person company might run a single quarterly steering committee, with the CEO absorbing the board tier. What must not collapse is the separation between deciding and doing: the person running the remediation should not be the only person judging whether the remediation is sufficient.

Decision rights, written in advance

The exam repeatedly punishes ad-hoc decisions. Decision rights should be fixed before they are needed:

  • New processing purpose — who approves? Typically privacy leadership, on the strength of an assessment.
  • Residual risk acceptance — who signs? Escalating by severity: privacy manager for low, privacy leader for medium, executive sponsor for high, board for anything outside stated appetite.
  • Launch veto — does privacy hold one, or does an executive override require a named signature and a logged risk acceptance?
  • Breach notification — a governance decision owned by the privacy leader or the executive they escalate to, never by the technical responder.
  • Vendor approval — who can accept a vendor that failed an assessment, and on what compensating control?

A risk-acceptance record is the artifact that ties this together: the risk, the assessment, the decision, the named accepter, the date, the compensating controls and the review date. Regulators asking "who decided this was acceptable?" are asking for that record.

Escalation paths that work

An escalation path needs four components, and the exam tests the missing one:

  1. Trigger — the objective condition that starts it (a rights request past 20 days, a vendor refusing audit rights, a launch with unmitigated high risk).
  2. Route — the named next decision-maker, not a department.
  3. Clock — how long each tier has before automatic escalation upward.
  4. Record — where the decision and rationale are logged.

The clock is the component most often absent, and its absence is the credited answer in scenario items: without a time limit, escalation becomes a queue where issues age quietly until a statutory deadline passes.

Worked scenario

A product team wants to launch a feature that repurposes existing customer data. The privacy manager assesses it as high residual risk. Under a written charter the path is mechanical: the assessment goes to the steering committee within the stated window; the committee either requires mitigation or refers the residual risk upward; because the processing sits outside stated appetite, an executive sponsor signs a documented risk acceptance with compensating controls and a 90-day review; the acceptance is recorded on the risk register and reported to the board at the next quarterly pack. Nobody negotiates the process during the launch, which is the entire point of writing it down first.

Test Your Knowledge

A 150-person company's privacy program has a steering committee that meets quarterly, but escalated issues routinely sit unresolved for months. The charter names the committee as the escalation destination. What is the missing component?

A
B
C
D
Test Your Knowledge

A privacy manager assesses a proposed launch as carrying high residual privacy risk that falls outside the organization's stated risk appetite. The product executive wants to proceed. Under a well-drafted program charter, what should happen?

A
B
C
D