Report by ISACA

State of Privacy ISACA Report

65 FINDINGSPublished Jan 1, 2025
View Original Report →

Key Findings

15% said a material privacy breach in the next 12 months was likely.

PrivacyStaff TrainingInternal MobilitySkill Development

30% of respondents in North America said they experienced difficulties in retaining privacy professionals, compared to 60% of respondents in Latin America.

PrivacyRetentionRegional DifferencesStaffing Challenges

21% said the chief privacy officer was primarily accountable for privacy.

PrivacyChief Privacy OfficerAccountabilityLeadership

31% plan to use AI for privacy in the next 12 months.

PrivacyLegal ComplianceJob VacanciesStaffing

61% said privacy awareness training was separate from security training.

PrivacyQualificationsHands-On ExperienceRecruitment

66% of organisations provide privacy training annually.

PrivacyRecruitment SpeedTechnical PrivacyStaffing

61% track the number of employees who have completed privacy training.

PrivacyApplicant QualityLegal ComplianceQualifications

54% track the number of privacy incidents to evaluate privacy training effectiveness.

PrivacyApplicant QualityTechnical PrivacyQualifications

29% indicated there were open technical privacy positions.

PrivacyTechnical RolesOpen PositionsRecruitment

24% expect their privacy budget to stay the same in the next 12 months.

PrivacyBudget ExpectationsStabilityFuture Planning

54% of privacy professionals interact with internal audit.

PrivacyInternal AuditInteractionsCollaboration

24% of respondents said they were increasingly relying on AI or automation to address privacy skill gaps, compared to 18% last year.

PrivacyAI AutomationSkill GapsTrends

48% of enterprises are using training to allow nonprivacy staff who are interested to move into privacy roles.

PrivacyRetentionQualified ProfessionalsStaff Retention

59% said resource shortages made their privacy role more stressful.

PrivacyResource ShortagesStressWorkplace Pressure

39% said it was neither easy nor difficult to identify/understand privacy obligations.

PrivacyObligationsIdentificationUnderstanding

78% of privacy professionals frequently interact with information security.

PrivacyInformation SecurityInteractionsCollaboration

49% perform a privacy risk assessment to monitor their privacy programs.

PrivacyAIAutomationSkill Gaps

87% of respondents said their organisation provided privacy awareness training for employees.

PrivacyRecruitment SpeedLegal ComplianceStaffing

73% of respondents said expert-level privacy professionals were the most difficult to hire.

PrivacyExpert-Level RolesRecruitment DifficultyHiring Challenges

67% of respondents said their enterprise practiced privacy by design when building new applications and services.

PrivacyPrivacy by Design

46% of respondents felt their technical privacy team was understaffed.

PrivacyTechnical StaffingUnderstaffedResources

42% of respondents indicated a data breach/leakage was a common privacy failure.

PrivacyData BreachCommon FailuresSecurity Risks

57% of respondents believed their board of directors adequately prioritized privacy.

PrivacyBoard PriorityGovernanceOrganizational Strategy

74% said their organisation’s privacy strategy was aligned with organisational objectives.

PrivacyStrategic AlignmentGovernanceOrganizational Strategy

96% of respondents consider compliance/legal experience important in determining if a privacy candidate was qualified.

PrivacyCompliance ExperienceCandidate AssessmentQualifications

68% of respondents said that addressing privacy with documented privacy policies, procedures, and standards was mandatory.

PrivacyUnderstaffed TeamsLegal ComplianceStaffing

36% of privacy professionals cited management of risk associated with new technologies as an obstacle.

PrivacyRisk ManagementNew TechnologiesObstacles

29% expect their privacy budget to increase in the next 12 months.

PrivacyBudget ExpectationsIncreaseFuture Planning

61% said compliance challenges made their privacy role more stressful.

PrivacyCompliance ChallengesStressWorkplace Pressure

70% of privacy professionals interact with legal and compliance.

PrivacyLegal ComplianceInteractionsCollaboration

38% of respondents believed their legal/compliance privacy team was understaffed.

PrivacyLegal StaffingUnderstaffedCompliance

51% of respondents believed the demand for legal/compliance privacy roles would increase in the next year.

PrivacyCompliance RolesDemandRecruitment

22% of respondents indicated their organisation had open legal/compliance practitioner roles.

PrivacyCompliance RolesPractitioner PositionsOpenings

94% of respondents consider prior hands-on experience in a privacy role important in determining if a privacy candidate was qualified.

PrivacyExperienceTechnical SkillsCandidate Assessment

93% consider technical experience and credentials in a privacy role important in determining if a privacy candidate was qualified.

PrivacyTechnical SkillsCandidate QualificationsRecruitment

10% saw a decrease in their privacy budget in the past 12 months.

PrivacyBudgetDecreaseTrends

48% perform a privacy impact assessment to monitor their privacy programs.

PrivacyLegal ComplianceRole DemandStaffing

22% of respondents currently use AI for privacy-related tasks.

PrivacyTechnical PrivacyRole DemandStaffing

27% of respondents always practiced privacy by design.

PrivacyPrivacy by Design

80% of those in enterprises that always practiced privacy by design said their board adequately prioritized privacy.

PrivacyPrivacy by Design

The median staff size among enterprises that always practiced privacy by design was 11, compared to eight among enterprises overall.

PrivacyPrivacy by Design

57% of respondents believed the demand for technical privacy roles would increase in the next year.

PrivacyLegal RolesDemandRecruitment

82% of respondents use a framework or law/regulation to manage privacy in their organisation.

PrivacyFramework UsageComplianceManagement

38% of respondents said their organisation experienced difficulties retaining qualified privacy professionals.

PrivacyRetentionQualified ProfessionalsStaffing Difficulties

86% of respondents said privacy training and awareness programs had a positive impact on overall employee privacy awareness.

PrivacyQualificationsComplianceRecruitment

40% of respondents felt completely or very confident in their organisation’s ability to ensure the privacy of its sensitive data.

PrivacyExpert-LevelHiring DifficultyStaffing

12% of respondents' organisations experienced a material privacy breach in the past 12 months.

PrivacyQualificationsTechnical ExperienceCredentials

16% of respondents indicated that the speed of filling open legal/compliance privacy roles increased.

PrivacyCompliance RolesHiring SpeedRecruitment Efficiency

18% indicated the speed of filling technical privacy roles increased.

PrivacyTechnical StaffingHiring SpeedRecruitment Efficiency

65% of privacy professionals interact with risk management.

PrivacyRisk ManagementInteractionsCollaboration

43% of respondents believed their privacy budget was underfunded.

PrivacyBudgetUnderfundedResources

36% of respondents felt their privacy budget was appropriately funded.

PrivacyBudgetAdequately FundedResources

72% of respondents in enterprises that always practiced privacy by design felt completely or very confident in their ability to ensure data privacy and achieve compliance with new privacy laws.

PrivacyPrivacy by Design

10% of those who always practiced privacy by design experienced a material privacy breach in the past year.

PrivacyPrivacy by Design

63% of privacy professionals interact with IT operations and development.

PrivacyIT OperationsInteractionsCollaboration

9% of respondents in enterprises whose boards viewed privacy programs as purely compliance driven reported currently using AI for privacy.

PrivacyTechnical PrivacyJob VacanciesStaffing

18% of those who always practiced privacy by design reported currently using AI for privacy-related tasks.

PrivacyStaffing RetentionRegional DifferencesNorth America

50% of respondents in enterprises that always practiced privacy by design said their enterprise privacy budget was appropriately funded.

PrivacyPrivacy by Design

28% said more than half of technical privacy applicants were well qualified for the role.

PrivacyTechnical SkillsRecruitmentQualifications

38% of privacy professionals cited a complex international legal and regulatory landscape as an obstacle.

PrivacyRegulatory LandscapeComplexityInternational

37% of privacy professionals cited a lack of competent resources as an obstacle.

PrivacyResource CompetenceObstaclesStaffing

47% of respondents indicated a lack of training or poor training as a common privacy failure.

PrivacyTrainingCommon FailuresSkill Development

29% of respondents indicated that more than half of legal/compliance privacy applicants were well qualified for the role.

PrivacyLegal QualificationsRecruitmentQualifications

41% indicated not practicing privacy by design was a common privacy failure.

PrivacyPrivacy by DesignImplementation FailuresSecurity Risks

35% said the number of data subject requests they received increased in the past year.

PrivacyUnderstaffedTechnical PrivacyStaffing