Data protection, which encompasses data governance, data privacy and cybersecurity, should be considered as part of the board’s oversight of risk and strategy
The board’s responsibilities related to data protection include identifying director(s) or advisor(s) with the appropriate skills and experience, stating explicit accountability within the board, keeping management accountable and ensuring compliance with laws and regulations.
Board best practices in their oversight of data protection include good data governance hygiene, frequent and robust communications, expertise, and continuing education.