Which governance structure is most appropriate for a decentralized organization managing privacy risks?
Trap 1: Ad-hoc committee based on project needs.
Ad-hoc lacks the consistency needed for governance.
Trap 2: Outsourcing all privacy functions.
Governance accountability cannot be fully outsourced.
Trap 3: Centralized command-and-control structure.
This creates bottlenecks in decentralized firms.
- A
Hub-and-spoke model with localized privacy champions.
This allows central policy setting with local implementation.
- B
Ad-hoc committee based on project needs.
Why wrong: Ad-hoc lacks the consistency needed for governance.
- C
Outsourcing all privacy functions.
Why wrong: Governance accountability cannot be fully outsourced.
- D
Centralized command-and-control structure.
Why wrong: This creates bottlenecks in decentralized firms.