{"id":2260,"date":"2022-02-04T10:16:16","date_gmt":"2022-02-04T10:16:16","guid":{"rendered":"https:\/\/www.calligo.io\/insights\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/"},"modified":"2024-01-18T14:48:11","modified_gmt":"2024-01-18T14:48:11","slug":"why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo","status":"publish","type":"post","link":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/","title":{"rendered":"Why data-ambitious organizations need more than a Chief Data Officer (CDO)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The rise of the CDO<\/h2>\n\n\n\n<p>The potential value of data \u2013 if used optimally \u2013 is unquestioned.<\/p>\n\n\n\n<p>In recent years, there has been a clear acceleration in the number of organizations keen to not only better understand their data\u2019s potential, but also govern it more rigorously, structure it more usefully and use it more creatively.<\/p>\n\n\n\n<p>And so, they appoint a Chief Data Officer (CDO) to drive this change.<\/p>\n\n\n\n<p>This person \u2013 the business hopes \u2013 will \u201ctake hold of the data problem\u201d, pulling sources and siloes together to create clarity, drive automation, place data and insights into the hands of the front line, and improve business performance and customer satisfaction.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Discussing Client Ambition<\/h2>\n\n\n\n<p>When discussing these ambitions with our clients, the excitement and optimism is clear. But what is often missed, or at best over-simplified, is the need to execute safely.<\/p>\n\n\n\n<p>Managing the security risk to the organization is a fundamental part of a CDO\u2019s remit. Depending on the organizational structure, it is usually shared with or delegated to a dedicated CISO or equivalent.<\/p>\n\n\n\n<p>Similarly, compliance with industry regulations and certifications such as ISO and SOC comes under the governance aspect of the CDO role (again, often shared with \/ delegated to the CISO)<\/p>\n\n\n\n<p><strong>But what about\u00a0Data Privacy?<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CDOs and data privacy<\/h2>\n\n\n\n<p>In the pursuit of these ambitious data goals, while the CDO and\/or CISO handle security and compliance, who will manage the privacy-related risks to the organization? And the risk to the data subjects?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What data is personally-identifiable, and therefore subject to data privacy laws?<\/li>\n\n\n\n<li>Where is this data received from and held?<\/li>\n\n\n\n<li>How retrievable is it?<\/li>\n\n\n\n<li>How is it used?<\/li>\n\n\n\n<li>Will personal data be exposed to machine learning or automated decision-making?<\/li>\n\n\n\n<li>When and how is personal data shared?<\/li>\n\n\n\n<li>Or disposed of?<\/li>\n<\/ul>\n\n\n\n<p>In tackling these questions, some organisations believe the CDO can also perform the\u00a0<a href=\"https:\/\/www.calligo.io\/services\/data-protection-officer-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">Data Protection Officer (DPO)<\/a>\u00a0role, or have one report into them or the CISO. Others appoint a Chief Privacy Officer, thinking they are the same as a DPO, or a \u201cDPO+\u201d. Others ignore the need for privacy oversight altogether.<\/p>\n\n\n\n<p>None of these answers are wise. Some are even illegal and can result in penalties.<\/p>\n\n\n\n<p>The truth is, most data-ambitious organizations require all three roles. Without them, data safety is jeopardised and the company is at risk of non-compliance, breaches, inefficiency and missed opportunity.<\/p>\n\n\n\n<p>But how the remits are best defined and structured is often a mystery.<\/p>\n\n\n\n<p>Below is a guide to the three pertinent roles \u2013 Chief Data Officer (CDO), Chief Privacy Officer (CPO) and Data Protection Officer (DPO) \u2013 outlining why each role is essential for every data-ambitious organization, plus their differences, inter-relationships, boundaries and overlaps.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CDOs and data privacy<\/h2>\n\n\n\n<p>In the pursuit of these ambitious data goals, while the CDO and\/or CISO handle security and compliance, who will manage the privacy-related risks to the organization? And the risk to the data subjects?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What data is personally-identifiable, and therefore subject to data privacy laws?<\/li>\n\n\n\n<li>Where is this data received from and held?<\/li>\n\n\n\n<li>How retrievable is it?<\/li>\n\n\n\n<li>How is it used?<\/li>\n\n\n\n<li>Will personal data be exposed to machine learning or automated decision-making?<\/li>\n\n\n\n<li>When and how is personal data shared?<\/li>\n\n\n\n<li>Or disposed of?<\/li>\n<\/ul>\n\n\n\n<p>In tackling these questions, some organisations believe the CDO can also perform the Data Protection Officer (DPO) role, or have one report into them or the CISO. Others appoint a Chief Privacy Officer, thinking they are the same as a DPO, or a \u201cDPO+\u201d. Others ignore the need for privacy oversight altogether.<\/p>\n\n\n\n<p>None of these answers are wise. Some are even illegal and can result in penalties.<\/p>\n\n\n\n<p>The truth is, most data-ambitious organizations require all three roles. Without them, data safety is jeopardised and the company is at risk of non-compliance, breaches, inefficiency and missed opportunity.<\/p>\n\n\n\n<p>But how the remits are best defined and structured is often a mystery.<\/p>\n\n\n\n<p>Below is a guide to the three pertinent roles \u2013 Chief Data Officer (CDO), Chief Privacy Officer (CPO) and Data Protection Officer (DPO) \u2013 outlining why each role is essential for every data-ambitious organization, plus their differences, inter-relationships, boundaries and overlaps.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who you need<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">The Chief Data Officer (CDO)<\/h3>\n\n\n\n<p>Responsible for using data to best effect. The basis of this is data governance \u2013 its stewardship, consolidation, structure, management and distribution, but also the security and compliance risk it presents. On top of this lies innovation and how it can be most profitably exploited, whether through automation, analysis or data science.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Chief Privacy Officer (CPO)<\/h3>\n\n\n\n<p>This role sits within the overall CDO responsibility. This role adds the perspective of privacy compliance to the CDO function, specifically in terms of any action\u2019s risk to the company. As such, they will lead on the construction of the privacy programme, its roll-out and training and any necessary assessments.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Data Protection Officer (DPO)<\/h3>\n\n\n\n<p>Represents the data subject within the organization. They oversee activities from data processing, assessments and employee training to ensure that none of them conflict with data subjects\u2019 privacy rights, and as such must maintain independence from activities and reporting lines. While perhaps not technically required within your organization (for instance if you are not a public body, do not systematically process personal data as a core activity, or are not processing \u2018large volumes\u2019 of sensitive data), it is nonetheless a firmly recommended role for any data-ambitious organization with any degree of use of personal data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Can these roles be combined into single individuals?<\/h2>\n\n\n\n<p>The CDO and CPO can be the same person, and arguably should be to ensure that the entirety of data safety \u2013 security and privacy \u2013 are the foundations of all data use and governance, and reducing the risk of accidental non-compliance, or painful retrofitting of compliance requirements.<\/p>\n\n\n\n<p>The DPO and CDO (and\/or CPO)&nbsp;<strong>must never<\/strong>&nbsp;be the same person, as it would create a punishable conflict of interest. They should not even be in the same reporting structure. The DPO\u2019s role is to independently monitor and question all activities, strategic policies and objectives, which means they need the platform to challenge every level of the organization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The risk of getting this wrong<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Risk of unethical \/ non-compliant data processing<\/h3>\n\n\n\n<p>Our data privacy experts have often seen overenthusiasm and ambition innocently leading to personal data being misused. Without anyone overseeing the privacy risk to the data subject (DPO) or even the business (CPO), and a focus only on security, then organizations can easily overstep.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Missed opportunity<\/h3>\n\n\n\n<p>DPOs and CPOs are often mistaken for naysayers, as they too often focus on limiting what can be done with data and curtailing the ambition of the CDO. In fact, the best DPOs and CPOs will support the CDO\u2019s objectives, by suggesting innovative approaches to data use that balance ambition with risk.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Delays<\/h3>\n\n\n\n<p>If privacy is not a foundation on which data ambitions are built, then it will either be forgotten or retrofitted. The former creates risk of breaches, while the latter creates delays. Projects that lay privacy on top, rather than being designed with it in mind from the outset, risk needing costly redesign and rebuilding.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Conflict of interest<\/h3>\n\n\n\n<p>A DPO has to be independent of the day-to-day processes of data management, including its receipt, use, treatment and security. This rules out those job titles that are classically given this second role, such as CIOs and Heads of Compliance, and that regulators are now punishing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Chief Data Officer (CDO)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Remit unique to this position:<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Data governance<\/h4>\n\n\n\n<p>Ranging from data\u2019s structure and architecture to its management and ongoing quality assurance. Accurate and efficient data governance is the foundation stone of all data initiatives. Data siloes, untidy or incomplete data and inconsistent data structures are the principle barriers to data ambitions.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Security-related risk to company<\/h4>\n\n\n\n<p>Clearly overlapping with the above, the CDO is required to identify where the ambitions for data\u2019s structure, storage and use will create security and regulatory compliance risk. Working with the CISO \u2013 who may be alongside or within the CDO\u2019s team \u2013 these risks then need to be mitigated comprehensively, and without obstructing operations.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Innovation \/ Data Science &amp; Insights<\/h4>\n\n\n\n<p>This is the principal reason for the appointment of a CDO: using data creatively to further the aims of the organization as a whole. Building on the groundwork of data governance and security, this may be through automation, analytics, visualizations, machine learning or other forms of AI. Projects may be intended for internal efficiency, or the development of new products and services, but one truth remains at every initiative\u2019s core: using data more intelligently.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Chief Privacy Officer (CPO)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Remit unique to this position:<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Privacy-related risk to company<\/h4>\n\n\n\n<p>While the CDO handles the security-related risk, the CPO looks specifically at personally-identifiable data, how well protected it is and how ethically \/ compliantly it is used. This will include determining how all the organization\u2019s activities affect the regulations whose scope they fall under, and ensuring the various obligations are all addressed.<\/p>\n\n\n\n<p>Clearly, this responsibility overlaps with the CDO\u2019s security-related remit, and requires the cooperation of the CISO, as a lot (though not all) of a privacy-focused risk assessment is based in typical security technical and organizational measures (TOMs). As such, the CPO role may well be part of the CDO\u2019s, if the individual has the relevant privacy skills.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Devise &amp; deploy the privacy programme<\/h4>\n\n\n\n<p>This is the tactical implementation of the above. It involves the creation of policies and processes that will protect personal data in every department, by every user and with every data interaction, and specifically on an ongoing basis.<\/p>\n\n\n\n<p>Unlike many other areas of compliance, data privacy requires continuous management and oversight. A breach of ISO compliance requirements on a given day is unlikely to jeopardise completing the next audit\u2019s requirements and maintaining certification. In contrast, a single breach of data privacy requirements could result in customer dissatisfaction, being reported to regulators and potentially fines and irreparable brand damage. As such, the deployment of the privacy programme must ensure continuous protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Data Protection Officer<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Remit unique to this position:<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Privacy-related risk to data subjects<\/h4>\n\n\n\n<p>This is the crux of the DPO role. A Data Protection Officer is one of few senior roles who categorically do not serve the interests of the organization, but of third parties \u2013 arguably the only one. It is this unusual perspective that requires them to be independent of the mechanics of the organization, and that underpins all other responsibilities.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Oversight<\/h4>\n\n\n\n<p>The DPO is responsible for continuously monitoring all data processing activities and independently assessing their adherence to the GDPR and any other relevant legislation. Any faults or risks found are then the responsibility of the CPO and\/or CDO to remedy, working alongside any relevant departmental head.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Internal audit<\/h4>\n\n\n\n<p>Part of the Oversight role above will include regular internal audits of data processing activities. An initial GAP Analysis will show a baseline of compliance, while subsequent periodic audits will showcase the evolving privacy maturity of the organization, plus any persistent weaknesses.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Liaison with authorities and data subjects<\/h4>\n\n\n\n<p>DPOs also act as a conduit for all communications with supervisory authorities and data subjects. They may do this proactively, for example securing approval from authorities on the legitimacy of any new and unusual data processing initiatives. DPOs will also handle the communications with any data subjects in the case of Data Subject Requests.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Shared Remits<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Shared remit: CDO &amp; DPO<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Automated decision-making<\/h4>\n\n\n\n<p>This is a crucial overlap. For many data-ambitious organizations, especially those in consumer services such as banking, telecoms or utilities, there will be a drive to use automation or machine learning to systematize interactions with customers based on the data on them as individuals. These may include the pricing and terms offered to them, which would mean that automated decisions are being made that have a legal or similarly significant effect \u2013 which is specifically limited by the GDPR and many other privacy regulations that followed in its footsteps.<\/p>\n\n\n\n<p>This is therefore a classic example of a situation where the CDO and the DPO would have to work together to ensure that the project is legitimately designed and executed, and is highly indicative of why the DPO cannot be the same person or even be in the same reporting structure as the CDO. The CDO\u2019s project needs to be able to be objectively critiqued and perhaps stopped by an independent DPO.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Shared remit: CDO &amp; CPO<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Ethical Data Impact Assessments (EDIAs)<\/h4>\n\n\n\n<p>EDIAs are modern supplements to the pre-existing Data Protection Impact Assessment (DPIA), and are effectively&nbsp;documented evidence of the scrutiny required above in instances of Automated Decision-making.<\/p>\n\n\n\n<p>While not specifically required by privacy legislation or guidance \u2013 as a DPIA is \u2013 the sort of rigour they encompass is. As mentioned above, references are found in the GDPR and many other pursuant regulations.&nbsp;The extra scrutiny is recommended because of the deliberate removal of human oversight from processes, and therefore the risk of the inadvertent removal of understanding, proportionality, fairness and even values.<\/p>\n\n\n\n<p>For a DPIA, a DPO and a CPO (see below) will collaborate on mitigating the risks to data subjects \u2013 hence the DPO\u2019s involvement.<\/p>\n\n\n\n<p>An EDIA\u2019s extra considerations beyond a DPIA focus on accountability, transparency, necessity and sustainability. These are more technical, strategic and concerned with personal rights including but also beyond privacy, such as the right to not be discriminated against.<\/p>\n\n\n\n<p>The CDO\u2019s input will therefore cover the technical and strategic sides, while the CPO is best placed to review the technology\u2019s ethical use. In truth, this is not a perfect fit. But there are few alternatives. A&nbsp;DPO\u2019s role is to monitor activity through a strict lens of protecting data subjects\u2019 privacy rights \u2013 and arguably their independence means their role can never be to&nbsp;<em>perform<\/em>&nbsp;assessments, only to review. Legal counsel is concerned with the application of the codified law, not the wider topic of ethics. Compliance roles are similarly used to implement specific rules and standards.<\/p>\n\n\n\n<p>Upholding ethics is different by its nature, and not typically a nominated role within organizations, but a CPO is arguably the closest fit, not least because they lead the completion of DPIAs, on which EDIAs are based.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Shared remit: CPO &amp; DPO<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Training employees<\/h4>\n\n\n\n<p>This is part of the CPO\u2019s deployment of the overall privacy programme, but requires the involvement of the DPO because of their responsibility for monitoring internal compliance. Acting on behalf of data subjects, the DPO will check the suitability and comprehensiveness of the training programme, in essence confirming that should the training be satisfactorily completed (the CPO\u2019s responsibility to ensure), then data subjects\u2019 rights are protected<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Data Protection Impact Assessments (DPIAs)<\/h4>\n\n\n\n<p>These tools identify any potential risks that may arise from processing personal data, allowing the organization to minimise and negate them in advance. They are a key requirement for demonstrating adherence to GDPR and most other privacy regulations, and should be completed for every way in which an organization processes data.<\/p>\n\n\n\n<p>They are the CPO\u2019s responsibility to perform, though as with the Training above, the DPO is required to provide an oversight role to ensure data subjects\u2019 rights are protected. They will advise the CPO on whether a DPIA is necessary in any given situation, how it should be performed, what measures can be legitimately put in place to negate any risks identified, and whether the ultimate decision that process is permitted or not is correct.<\/p>\n\n\n\n<p>This process and shared responsibility applies equally to other privacy adherence tools such as Legitimate Interest Assessments (LIAs), where the CPO is responsible for performing the duty, while the DPO ensures their completion and verifies their outcomes.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Data Subject Access Requests (DSARs)<\/h4>\n\n\n\n<p>Some of the most common instances of CPOs and DPOs having to collaborate are on DSARs. In some industries, these are rather common, especially those with high volumes of consumer interaction such as retail, utilities, telecoms and retail banking. A CPO will be responsible for the performance of the DSAR \u2013 for example, verifying the identity of the data subject and collecting relevant data \u2013 while the DPO will be responsible for overseeing the process, approving the data to be shared, ensuring deadlines are met and handling communications with the data subject.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Universal Responsibilities<\/h2>\n\n\n\n<h4 class=\"wp-block-heading\">Data Quality<\/h4>\n\n\n\n<p>All three Data Officers have a responsibility \u2013 or at least a vested interest \u2013 in maintaining the continuous quality of all the organisation\u2019s data.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>For a CDO, this is of course a principal strategic objective. Better use of data relies on data sources being cleansed for interrogation, and probably integrated under common data models to allow for deeper insights. But without continuous data governance \u2013 the process by which data quality is preserved \u2013 then interrogation becomes impossible, and integrations fall apart.<\/li>\n\n\n\n<li>Data quality requires common rules \u2013 defined and upheld ultimately by the CDO \u2013 for how data is collected and stored; agreed responsibilities for how it is maintained and kept complete, credible, useful and clean,; and a clear vision for how it may be used.<\/li>\n\n\n\n<li>The CPO and DPO will also have involvement in this, and vested interests in its performance. How and where the CDO decides to store data will need to adhere to data residency and sovereignty requirements. Data privacy regulations routinely give data subjects a Right to Accuracy, where every reasonable step must be taken to rectify data inaccuracies or erase data if no longer correct. And of course, without complete, clean and credible data, then DSARs cannot be accurately performed, and DPIAs and other typical processes cannot be conducted or verified easily.<\/li>\n<\/ul>\n\n\n\n<p>DPIAs in fact even have a specific question of:<\/p>\n\n\n\n<p>\u201cAre you satisfied that the personal data processed is of good enough quality for the purposes proposed? If not, why not?\u201d<\/p>\n\n\n\n<p>Of course, the easiest way for Data Quality to serve all three Data Officers needs is to base the organization\u2019s Data Quality framework on the principles of Privacy by Design &amp; Default.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Contracts<\/h4>\n\n\n\n<p>While the above is a strategic imperative that requires all three Data Officers\u2019 involvement, this is a tactical overlap.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contracts with new suppliers, partners, and potentially customers that inherently involve the processing of personal data create responsibilities for CDOs, DPOs and CPOs alike.<\/li>\n\n\n\n<li>A CDO needs to ensure that the contract and the mechanics of the engagement will not undermine or contradict any element of data governance. For example, if the new contract is with a new cloud services provider, can the provider support any ISO, SOC or PCI obligations? If the contract is with a new CRM, is the data structure consistent with any pre-existing common data model and how will data quality and accuracy be maintained? And in all cases, what security measures are in place to protect data from internal and external threats?<\/li>\n\n\n\n<li>Meanwhile, a CPO will be concerned with whether the contract is in line with the organization\u2019s privacy obligations. To use the example of the new cloud provider again, will data residency obligations be met? Or for new SaaS platforms, where will data be stored and are the correct cross-border data transfer mechanisms such as Standard Contractual Clauses (SCCs) in place?<\/li>\n\n\n\n<li>Finally, a DPO\u2019s role in a contract scenario is to review the legitimacy of the decisions made above, and verify that the privacy of data subjects\u2019 personal data will not be jeopardised \u2013 regardless of whether the organization is a controller or a processor in the given scenario.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The Core Lessons<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>All three roles \u2013 CDO, CPO, DPO \u2013 are probably required in your organization, even if a DPO is not strictly required it is nonetheless advisable.<\/li>\n\n\n\n<li>The CDO can also be the CPO, but the DPO must be independent.<\/li>\n\n\n\n<li>The CDO defines the strategy and is responsible for the vision of what is to be accomplished with your organization\u2019s data. This will include its structure, security, governance, maintenance and creation of value.<\/li>\n\n\n\n<li>The CPO is responsible for ensuring that the implementation of this strategy will not put the organization at any privacy-related risk, and is tasked with mitigating any risk with a defined and well-executed privacy programme.<\/li>\n\n\n\n<li>The DPO is the representative of the data subject within the organization, and is primarily responsible for overseeing the activities and ensuring no rights are or could be infringed.<\/li>\n\n\n\n<li>The more fundamental or complex the operation (such as data quality or intelligent data use), the more likely it is to require all three roles.<\/li>\n\n\n\n<li>Putting privacy \u2013 and better yet, total data safety \u2013 at the heart of every data initiative and interaction will make it more likely that every role\u2019s agendas are equally met.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The rise of the CDO The potential value of data \u2013 if used optimally \u2013 is unquestioned. In recent years, there has been a clear acceleration in the number of organizations keen to not only better understand their data\u2019s potential, but also govern it more rigorously, structure it more usefully and use it more creatively. [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":1972,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[142,140,141,121],"tags":[],"post_format_type":[40],"class_list":["post-2260","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-governance","category-data-privacy-glossary","category-data-protection","category-glossary"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Why data-ambitious organizations need more than a Chief Data Officer (CDO) | Calligo<\/title>\n<meta name=\"description\" content=\"Why data-ambitious organizations need more than a Chief Data Officer (CDO) to better understand their data\u2019s potential.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why data-ambitious organizations need more than a Chief Data Officer (CDO) | Calligo\" \/>\n<meta property=\"og:description\" content=\"Why data-ambitious organizations need more than a Chief Data Officer (CDO) to better understand their data\u2019s potential.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\" \/>\n<meta property=\"og:site_name\" content=\"Calligo\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-04T10:16:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-18T14:48:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"2560\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Brendan Walsh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@calligocloud\" \/>\n<meta name=\"twitter:site\" content=\"@calligocloud\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Brendan Walsh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\"},\"author\":{\"name\":\"Brendan Walsh\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f\"},\"headline\":\"Why data-ambitious organizations need more than a Chief Data Officer (CDO)\",\"datePublished\":\"2022-02-04T10:16:16+00:00\",\"dateModified\":\"2024-01-18T14:48:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\"},\"wordCount\":3429,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.calligo.io\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg\",\"articleSection\":[\"Data Governance\",\"Data Privacy\",\"Data Protection\",\"Glossary\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\",\"url\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\",\"name\":\"Why data-ambitious organizations need more than a Chief Data Officer (CDO) | Calligo\",\"isPartOf\":{\"@id\":\"https:\/\/www.calligo.io\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg\",\"datePublished\":\"2022-02-04T10:16:16+00:00\",\"dateModified\":\"2024-01-18T14:48:11+00:00\",\"description\":\"Why data-ambitious organizations need more than a Chief Data Officer (CDO) to better understand their data\u2019s potential.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage\",\"url\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg\",\"contentUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg\",\"width\":2560,\"height\":2560},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.calligo.io\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why data-ambitious organizations need more than a Chief Data Officer (CDO)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.calligo.io\/#website\",\"url\":\"https:\/\/www.calligo.io\/\",\"name\":\"Calligo\",\"description\":\"Building value through data\",\"publisher\":{\"@id\":\"https:\/\/www.calligo.io\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.calligo.io\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.calligo.io\/#organization\",\"name\":\"Calligo\",\"url\":\"https:\/\/www.calligo.io\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg\",\"contentUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Calligo\"},\"image\":{\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/calligocloud\",\"https:\/\/www.linkedin.com\/company\/calligo-limited\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f\",\"name\":\"Brendan Walsh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g\",\"caption\":\"Brendan Walsh\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why data-ambitious organizations need more than a Chief Data Officer (CDO) | Calligo","description":"Why data-ambitious organizations need more than a Chief Data Officer (CDO) to better understand their data\u2019s potential.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/","og_locale":"en_GB","og_type":"article","og_title":"Why data-ambitious organizations need more than a Chief Data Officer (CDO) | Calligo","og_description":"Why data-ambitious organizations need more than a Chief Data Officer (CDO) to better understand their data\u2019s potential.","og_url":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/","og_site_name":"Calligo","article_published_time":"2022-02-04T10:16:16+00:00","article_modified_time":"2024-01-18T14:48:11+00:00","og_image":[{"width":2560,"height":2560,"url":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg","type":"image\/jpeg"}],"author":"Brendan Walsh","twitter_card":"summary_large_image","twitter_creator":"@calligocloud","twitter_site":"@calligocloud","twitter_misc":{"Written by":"Brendan Walsh","Estimated reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#article","isPartOf":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/"},"author":{"name":"Brendan Walsh","@id":"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f"},"headline":"Why data-ambitious organizations need more than a Chief Data Officer (CDO)","datePublished":"2022-02-04T10:16:16+00:00","dateModified":"2024-01-18T14:48:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/"},"wordCount":3429,"commentCount":0,"publisher":{"@id":"https:\/\/www.calligo.io\/#organization"},"image":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage"},"thumbnailUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg","articleSection":["Data Governance","Data Privacy","Data Protection","Glossary"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/","url":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/","name":"Why data-ambitious organizations need more than a Chief Data Officer (CDO) | Calligo","isPartOf":{"@id":"https:\/\/www.calligo.io\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage"},"image":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage"},"thumbnailUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg","datePublished":"2022-02-04T10:16:16+00:00","dateModified":"2024-01-18T14:48:11+00:00","description":"Why data-ambitious organizations need more than a Chief Data Officer (CDO) to better understand their data\u2019s potential.","breadcrumb":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#primaryimage","url":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg","contentUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/iStock-863620994-scaled-1.jpg","width":2560,"height":2560},{"@type":"BreadcrumbList","@id":"https:\/\/www.calligo.io\/insights\/glossary\/why-data-ambitious-organizations-need-more-than-a-chief-data-officer-cdo\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.calligo.io\/"},{"@type":"ListItem","position":2,"name":"Why data-ambitious organizations need more than a Chief Data Officer (CDO)"}]},{"@type":"WebSite","@id":"https:\/\/www.calligo.io\/#website","url":"https:\/\/www.calligo.io\/","name":"Calligo","description":"Building value through data","publisher":{"@id":"https:\/\/www.calligo.io\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.calligo.io\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.calligo.io\/#organization","name":"Calligo","url":"https:\/\/www.calligo.io\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/","url":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg","contentUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg","width":1200,"height":630,"caption":"Calligo"},"image":{"@id":"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/calligocloud","https:\/\/www.linkedin.com\/company\/calligo-limited\/"]},{"@type":"Person","@id":"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f","name":"Brendan Walsh","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.calligo.io\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g","caption":"Brendan Walsh"}}]}},"_links":{"self":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/posts\/2260","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/comments?post=2260"}],"version-history":[{"count":0,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/posts\/2260\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/media\/1972"}],"wp:attachment":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/media?parent=2260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/categories?post=2260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/tags?post=2260"},{"taxonomy":"post_format_type","embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/post_format_type?post=2260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}