Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable for Law 25 compliance when…
Governance, Ownership & Risk

Who is accountable for Law 25 compliance when no privacy officer is formally appointed?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Governance, Ownership & Risk

Law 25 makes accountability explicit. If an organization does not appoint a privacy officer, the CEO becomes the default privacy officer. That matters because ownership includes DSAR fulfillment, breach reporting, privacy impact assessments, and oversight of internal policies and training. In practice, leadership must ensure those responsibilities are assigned, tracked, and evidenced.

What accountability means under Law 25 when no privacy officer is named

Law 25 does not leave accountability floating at the organisational level. When no privacy officer is formally appointed, the default accountability sits with the CEO, which means the obligation is not just symbolic authority but operational ownership. The key question for practitioners is not who signs the policy, but who can actually direct, evidence, and sustain compliance.

That default role matters because it extends to the practical work behind compliance, including DSAR handling, breach reporting, privacy impact assessments, and oversight of policies and training. If those duties are not clearly delegated, they can become fragmented across legal, security, HR, and operations, which is where accountability often becomes hardest to prove.

How leadership should translate default accountability into working control

A default privacy-officer arrangement only works if the organisation turns the legal default into a managed operating model. The CEO may retain accountability, but day-to-day execution usually needs named owners, deadlines, evidence retention, and a review cadence. Without that structure, compliance exists on paper while the actual tasks drift between teams.

Practitioners should treat this as a governance design problem, not a title problem. The most important control is a clear assignment model that shows who handles intake, assessment, approval, escalation, and recordkeeping for privacy obligations. That makes it possible to demonstrate that accountability is active even when the formal role has not been separately appointed.

  • Document who performs each privacy obligation and who approves exceptions.
  • Retain evidence for DSARs, PIAs, incident decisions, policy reviews, and training completion.
  • Review delegation regularly so responsibilities do not become stale or implicit.

For organisations that want a broader compliance and audit lens on governance obligations, NHI Mgmt Group’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful for thinking about how accountability, audit trails, and governance evidence are operationalised in practice.

Risk and Threat Considerations

When no privacy officer is appointed, the main risk is not only noncompliance, but unclear ownership during time-sensitive events such as access requests or privacy incidents. If multiple teams assume another function is responsible, the organisation can miss statutory deadlines, under-document decisions, or fail to escalate a breach correctly.

Failure mechanism: accountability becomes informal, so control activities are delegated by habit rather than by documented authority. That creates gaps in response timing, evidence retention, and management oversight, especially when legal, security, and operational teams each hold part of the process.

Impact: the organisation may be unable to prove who made privacy decisions, whether required reviews occurred, or whether leadership actually supervised compliance. That increases regulatory exposure and makes remediation harder after an incident or complaint.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyLaw 25 accountability depends on assigned governance ownership and documented oversight.
GV.OV-01 — OversightThe question is about who has formal oversight when no privacy officer is named.
Recommendation — Assign a named executive owner and document oversight for privacy obligations. Record executive oversight and periodic review of privacy compliance tasks.
CIS Controls v85 — Account ManagementNamed responsibility and tracked ownership are central to proving who controls privacy duties.
Recommendation — Maintain documented ownership and review evidence for privacy-related responsibilities.
ISO/IEC 42001:20235.3 — Roles, Responsibilities and AuthoritiesPrivacy compliance needs explicit responsibility assignment and authority to execute controls.
Recommendation — Define and evidence responsible owners for each privacy compliance activity.
NIST SP 800-632.1 — Identity Proofing and EnrollmentAccountability for privacy duties includes controlled handling of requests and decisions tied to data subject identity.
Recommendation — Ensure identity verification steps are defined before DSAR fulfillment.
NIST SP 800-53 Rev 5PM-1 — Information Security Program PlanA default accountable executive must ensure privacy obligations are embedded in a documented program.
Recommendation — Document privacy governance responsibilities inside the security and privacy program.

Practitioner Guidance

What to verify: confirm that the organisation can show a named decision-maker for privacy obligations, even if that person is not formally titled as privacy officer. The evidence should show ownership of recurring tasks, not just a policy statement.

Decision rule: if the role is not formally appointed, treat the CEO as the accountable executive and explicitly delegate operational handling to named owners with recorded reporting lines. If delegation cannot be evidenced, the organisation is not in a defensible state.

What good looks like: each privacy obligation has a primary owner, an approver, a review date, and a retained record of completion. The organisation can answer quickly who handled a DSAR, who reviewed a PIA, and who received breach escalation.

Practitioner takeaway: under Law 25, accountability is only real when the organisation can demonstrate an executable ownership model, not merely a legal default or an informal expectation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org