Data Owner
Data owner:The person/department responsible for the data and deciding who can access it.
• Example: The HR director owns employee records.
Data Custodian
Data Custodian: The IT person/team that actually manages and protects the data (backups, permissions, patches).
• Example: The sysadmin who sets file permissions for HR data.
Data Steward
Data Steward: The person who ensures data is accurate, consistent, and high quality.
• Example: Someone checking that all employee birthdates are entered correctly.
Data Controller
Data Controller: Under privacy laws (like GDPR), this is the person/company that decides why and how personal data is processed.
• Example: A hospital deciding to collect patient data for medical treatment.
Data Processor
Data Processor: The person/company that actually processes the data on behalf of the controller.
• Example: A cloud service provider storing patient records for the hospital.
Easy way to remember
Owner = “It’s my data, I’m responsible.”
• Custodian = “I take care of the data (IT tasks).”
• Steward = “I keep the data clean & correct.”
• Controller = “I decide why and how data is used.”
• Processor = “I do the work with the data for the controller.”