Chief Administrative Officer Designation
Maturity Level

Level 0: Non-Existent
The practice is not implemented or acknowledged.
No CAO designated for privacy oversight, or the role is unassigned.Example Strategies
- Identify potential roles that could oversee data goverance. Examples include: City manager, Executive Leadership, Chief Data Officer, Chief Privacy Officer, IT Manager, HR Director
Level 1: Ad Hoc
Practice may occur but is undocumented (no policies or procedures), application is reactive and not standardized.
A CAO might be informally recognized as having some privacy responsibility, but it's not formalized or documented.Example Strategies
- Draft a memo identifying which position will serve as the CAO for privacy.
- Share memo with relevant personnel.
- Begin organizing assets, templates that will assist in program creation
- Engage senior leadership (capture buy-in, define roles, establish resource allocation)
Level 2: Defined
Practice is implemented and documented, but documentation may not cover all relevant aspects, and application may be informal and inconsistent.
The CAO is formally designated in an internal document, but their specific privacy responsibilities or authority might be vaguely defined.Example Strategies
- Identify your CAO
- Troubleshoot if necessary with your RIM
- Formally document the designation through ordinance, resolution, rule or policy
- Determine communication plan and ensure entity understands program procedure
Level 3: Consistently Implemented
Practice is documented to cover all relevant aspects, application is formal and consistent.
The CAO's role, responsibilities (including championing privacy and resource allocation), and reporting lines for privacy are clearly documented in policies and procedures, and regularly followed.Example Strategies
- Manage annual Privacy training campaign through LMS (KnowBe4, Saba)
- Appoint and approve Records Officers
- Look up ARO's, ensure they are up to date on training
- Insert privacy checkpoint at planning/concept stage (before data exists)
- Insert privacy checkpoint at Design & Development stage
- Insert privacy checkpoint at pre-deployment/go-live stage
- Approve destruction of records
- Delegate others to do some of these tasks (Document delegation)
- Submit records schedules for approval
- Schedule retention of non-record items
- Document all record series either directly in the DARS system (with a RIM specialist) or via an in-house spreadsheet.
- Ensure all sensitive data (private, controlled, or personal) is specifically identified and documented.
- Submit your inventory by sharing the completed spreadsheet with [email protected].
- Participate on Incident Resposne team
- Ensure annual internal assessment of data governance systems. Strategize areas of improvement.
Level 4: Managed
Practice is actively managed with metrics that are regularly reviewed to assess efficacy and facilitate improvement.
The CAO regularly receives and reviews metrics on privacy program effectiveness (e.g., training completion rates, incident reports, audit findings) and uses this data to make improvements.Example Strategies
- Demonstrate year over year assessment and improvement of program
Level 5: Optimized
Practice is fully embedded in the entity with recognition and understanding across the workforce through active training and awareness campaigns, and inclusion in operations and strategy.
Privacy is a standing agenda item for the CAO and senior leadership, integrated into strategic planning and entity-wide initiatives, reflecting a top-down commitment.