Should privacy and information security roles be combined?
Should privacy and information security roles be combined? Discover how to successfully navigate the overlap between fair data use and system compromise without overloading a single compliance position.
The short answer
Privacy and information security roles can be combined, but only if the scope, expertise and salary are realistic.
The disciplines overlap, but they are not the same. Privacy focuses on lawful and fair data use. Information security focuses on protecting systems and information from compromise.
Why firms combine them
Both areas involve data risk, incidents, vendors, policies and governance. Combining them may feel efficient, especially in smaller firms.
What are the risks?
The role may become too broad. A strong privacy professional may not be an information security specialist, and vice versa.
If the firm needs deep expertise in both, one hire may not be enough.
How to scope properly
Define what is essential. Is the role leading privacy with security liaison, or leading security with privacy awareness?
Be honest about support from IT, Risk and Legal.
Bottom line
Combined privacy and security roles can work if expectations are realistic.
Do not use one title to hide two full-time specialist jobs.