SY0-701 Question 417
Single answerRoles and responsibilities for systems and data: Owners , Controllers , Processors , Custodians/stewardsA healthcare company uses a third-party SaaS platform to store and analyze patient appointment data. The clinic's compliance manager decides what patient data will be collected, how long it will be retained, and which business purpose justifies its use. The SaaS provider stores the records, performs analytics requested by the clinic, and applies backups and patching. During an audit, the security team must identify which role is responsible for determining the purpose and means of processing the patient data. Which role best matches that responsibility?
- A
Data owner
- B
Data controller
- C
Data custodian/steward
- D
Data processor
Show answer and explanation
Correct answer: B
Explanation
This question tests the distinction between governance and operational roles for data. In privacy and security practice, the data controller is the entity that determines the purposes and means of processing personal data. The data processor acts on behalf of the controller and handles the data according to the controller's instructions. Within internal governance models, a data owner is often accountable for a dataset's classification, access approvals, and business use, while custodians or stewards carry out operational protection and administration tasks such as backups, patching, and enforcing handling procedures. In the scenario, the clinic decides what data is collected and why it is used, so it is acting as the controller; the SaaS vendor is the processor. This aligns with common guidance found in privacy frameworks such as the GDPR definitions of controller and processor, and with security governance practices reflected in Security+ objectives covering owners, controllers, processors, and custodians/stewards.
- A. Incorrect.
Incorrect. A data owner is typically the person or business role within an organization that is accountable for a specific dataset or system and approves classifications, access, and handling requirements. While this can sound similar, the question specifically asks who determines the purpose and means of processing personal data, which is the definition associated with the controller role in privacy frameworks.
- B. Correct.
Correct. A data controller determines why and how personal data is processed. In this scenario, the compliance manager decides what data is collected, the retention period, and the business purpose for using it. Those decisions align directly with controller responsibilities under common privacy concepts such as GDPR and similar governance models.
- C. Incorrect.
Incorrect. A data custodian or steward is generally responsible for implementing and maintaining the protections, quality controls, and operational handling of data according to policies set by the owner or controller. Backups, patching, storage administration, and enforcing handling procedures are more consistent with custodian or steward duties, not deciding the purpose of processing.
- D. Incorrect.
Incorrect. A data processor processes data on behalf of the controller and follows the controller's instructions. The SaaS provider in this scenario stores records and performs analytics requested by the clinic, which fits the processor role. A common misconception is to assume that because the processor handles the data directly, it also decides why the data is used; that decision remains with the controller.