Report by ISACA

State of Privacy ISACA Report

65 FINDINGSPublished Jan 1, 2025
View Original Report →

Key Findings

15% said a material privacy breach in the next 12 months was likely.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyStaff TrainingInternal MobilitySkill Development

30% of respondents in North America said they experienced difficulties in retaining privacy professionals, compared to 60% of respondents in Latin America.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRetentionRegional DifferencesStaffing Challenges

21% said the chief privacy officer was primarily accountable for privacy.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyChief Privacy OfficerAccountabilityLeadership

31% plan to use AI for privacy in the next 12 months.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyLegal ComplianceJob VacanciesStaffing

66% of organisations provide privacy training annually.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRecruitment SpeedTechnical PrivacyStaffing

54% track the number of privacy incidents to evaluate privacy training effectiveness.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyApplicant QualityTechnical PrivacyQualifications

61% said privacy awareness training was separate from security training.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyQualificationsHands-On ExperienceRecruitment

29% indicated there were open technical privacy positions.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical RolesOpen PositionsRecruitment

24% expect their privacy budget to stay the same in the next 12 months.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyBudget ExpectationsStabilityFuture Planning

54% of privacy professionals interact with internal audit.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyInternal AuditInteractionsCollaboration

24% of respondents said they were increasingly relying on AI or automation to address privacy skill gaps, compared to 18% last year.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyAI AutomationSkill GapsTrends

48% of enterprises are using training to allow nonprivacy staff who are interested to move into privacy roles.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRetentionQualified ProfessionalsStaff Retention

59% said resource shortages made their privacy role more stressful.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyResource ShortagesStressWorkplace Pressure

39% said it was neither easy nor difficult to identify/understand privacy obligations.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyObligationsIdentificationUnderstanding

78% of privacy professionals frequently interact with information security.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyInformation SecurityInteractionsCollaboration

49% perform a privacy risk assessment to monitor their privacy programs.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyAIAutomationSkill Gaps

87% of respondents said their organisation provided privacy awareness training for employees.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRecruitment SpeedLegal ComplianceStaffing

73% of respondents said expert-level privacy professionals were the most difficult to hire.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyExpert-Level RolesRecruitment DifficultyHiring Challenges

67% of respondents said their enterprise practiced privacy by design when building new applications and services.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

61% track the number of employees who have completed privacy training.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyApplicant QualityLegal ComplianceQualifications

46% of respondents felt their technical privacy team was understaffed.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical StaffingUnderstaffedResources

42% of respondents indicated a data breach/leakage was a common privacy failure.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyData BreachCommon FailuresSecurity Risks

57% of respondents believed their board of directors adequately prioritized privacy.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyBoard PriorityGovernanceOrganizational Strategy

74% said their organisation’s privacy strategy was aligned with organisational objectives.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyStrategic AlignmentGovernanceOrganizational Strategy

96% of respondents consider compliance/legal experience important in determining if a privacy candidate was qualified.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyCompliance ExperienceCandidate AssessmentQualifications

68% of respondents said that addressing privacy with documented privacy policies, procedures, and standards was mandatory.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyUnderstaffed TeamsLegal ComplianceStaffing

36% of privacy professionals cited management of risk associated with new technologies as an obstacle.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRisk ManagementNew TechnologiesObstacles

29% expect their privacy budget to increase in the next 12 months.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyBudget ExpectationsIncreaseFuture Planning

61% said compliance challenges made their privacy role more stressful.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyCompliance ChallengesStressWorkplace Pressure

70% of privacy professionals interact with legal and compliance.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyLegal ComplianceInteractionsCollaboration

38% of respondents believed their legal/compliance privacy team was understaffed.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyLegal StaffingUnderstaffedCompliance

51% of respondents believed the demand for legal/compliance privacy roles would increase in the next year.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyCompliance RolesDemandRecruitment

22% of respondents indicated their organisation had open legal/compliance practitioner roles.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyCompliance RolesPractitioner PositionsOpenings

94% of respondents consider prior hands-on experience in a privacy role important in determining if a privacy candidate was qualified.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyExperienceTechnical SkillsCandidate Assessment

93% consider technical experience and credentials in a privacy role important in determining if a privacy candidate was qualified.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical SkillsCandidate QualificationsRecruitment

10% saw a decrease in their privacy budget in the past 12 months.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyBudgetDecreaseTrends

48% perform a privacy impact assessment to monitor their privacy programs.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyLegal ComplianceRole DemandStaffing

22% of respondents currently use AI for privacy-related tasks.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical PrivacyRole DemandStaffing

27% of respondents always practiced privacy by design.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

80% of those in enterprises that always practiced privacy by design said their board adequately prioritized privacy.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

The median staff size among enterprises that always practiced privacy by design was 11, compared to eight among enterprises overall.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

57% of respondents believed the demand for technical privacy roles would increase in the next year.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyLegal RolesDemandRecruitment

82% of respondents use a framework or law/regulation to manage privacy in their organisation.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyFramework UsageComplianceManagement

38% of respondents said their organisation experienced difficulties retaining qualified privacy professionals.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRetentionQualified ProfessionalsStaffing Difficulties

86% of respondents said privacy training and awareness programs had a positive impact on overall employee privacy awareness.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyQualificationsComplianceRecruitment

40% of respondents felt completely or very confident in their organisation’s ability to ensure the privacy of its sensitive data.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyExpert-LevelHiring DifficultyStaffing

12% of respondents' organisations experienced a material privacy breach in the past 12 months.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyQualificationsTechnical ExperienceCredentials

16% of respondents indicated that the speed of filling open legal/compliance privacy roles increased.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyCompliance RolesHiring SpeedRecruitment Efficiency

18% indicated the speed of filling technical privacy roles increased.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical StaffingHiring SpeedRecruitment Efficiency

65% of privacy professionals interact with risk management.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRisk ManagementInteractionsCollaboration

43% of respondents believed their privacy budget was underfunded.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyBudgetUnderfundedResources

36% of respondents felt their privacy budget was appropriately funded.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyBudgetAdequately FundedResources

72% of respondents in enterprises that always practiced privacy by design felt completely or very confident in their ability to ensure data privacy and achieve compliance with new privacy laws.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

10% of those who always practiced privacy by design experienced a material privacy breach in the past year.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

63% of privacy professionals interact with IT operations and development.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyIT OperationsInteractionsCollaboration

9% of respondents in enterprises whose boards viewed privacy programs as purely compliance driven reported currently using AI for privacy.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical PrivacyJob VacanciesStaffing

18% of those who always practiced privacy by design reported currently using AI for privacy-related tasks.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyStaffing RetentionRegional DifferencesNorth America

50% of respondents in enterprises that always practiced privacy by design said their enterprise privacy budget was appropriately funded.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by Design

28% said more than half of technical privacy applicants were well qualified for the role.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTechnical SkillsRecruitmentQualifications

38% of privacy professionals cited a complex international legal and regulatory landscape as an obstacle.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyRegulatory LandscapeComplexityInternational

37% of privacy professionals cited a lack of competent resources as an obstacle.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyResource CompetenceObstaclesStaffing

47% of respondents indicated a lack of training or poor training as a common privacy failure.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyTrainingCommon FailuresSkill Development

29% of respondents indicated that more than half of legal/compliance privacy applicants were well qualified for the role.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyLegal QualificationsRecruitmentQualifications

41% indicated not practicing privacy by design was a common privacy failure.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyPrivacy by DesignImplementation FailuresSecurity Risks

35% said the number of data subject requests they received increased in the past year.

ISACAState of Privacy ISACA Report·Jan 1, 2025
PrivacyUnderstaffedTechnical PrivacyStaffing