Identifying Data Roles: Who is the Data Subject?
A company's marketing department collects, modifies, and stores sensitive customer data. The infrastructure team is responsible for securing the data while in transit and at rest. Which of the following data roles describes the customer?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the precise definition of GDPR/privacy terminology where the 'Subject' is the person described by the data, while the 'Owner' is the internal organizational role responsible for governance.
This question tests the definition of data roles in privacy frameworks, specifically distinguishing between the entity holding data and the individual it describes. The community consensus confirms that customers are 'Data Subjects' because they are the individuals to whom the personal data pertains.
Candidates often select 'Owner' (D) because, in general legal terms, individuals own their data. However, in cybersecurity compliance contexts (like ISO 27001 or NIST), 'Data Owner' refers to an internal business executive who authorizes access and defines requirements, not the external customer.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In data privacy frameworks such as GDPR and HIPAA, a Data Subject is defined as any living individual who can be identified, directly or indirectly, by the data being processed. Since the marketing department is collecting sensitive information about the customers, those customers are the subjects of that data. This aligns perfectly with Option C.Why the Other Options Are Wrong
Option A (Processor) refers to the entity processing data on behalf of a controller (e.g., a cloud provider or IT vendor). Option B (Custodian) typically refers to the technical team (like Infrastructure) that maintains and secures the data but does not have decision-making authority over it. Option D (Owner) is the most common trap; in corporate security, the Data Owner is an internal employee (e.g., Marketing Director) accountable for the data classification and protection policies, not the external customer.Community Comment Notes
Comment [3] provides an excellent mnemonic: Owner = Senior Management, Custodian = IT Team, Processor = External Service Provider, Subject = Patient/Customer. Comment [7] clarifies that while customers legally own their identity, the term 'Data Owner' in certification exams strictly refers to the internal asset owner. Comment [5] correctly identifies that the Marketing Head would likely be the Data Owner or Data Protection Officer.Official Reference
Exam Strategy
When answering questions about data roles, always look for context clues regarding 'internal vs. external' and 'technical vs. managerial'. If the option describes the person the data is about, it is the Subject. If it describes the person accountable for the data within the company, it is the Owner.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →