Correct answer: B
A data dictionary defines and documents each data element's name, meaning, format, allowable values, source, ownership, and permissible uses, establishing a common organizational language and governance framework for how personal data is understood and handled. By standardizing these definitions, the data dictionary ensures that all business units apply consistent rules to personal data usage, supporting transparency, accuracy, and accountability across the big data initiative. The other options address specific risks but do not provide the organization-wide definitional standardization that a data dictionary delivers.
- ADe-identifying data reduces re-identification risk but does not standardize how personal data is defined, classified, or used across business units before de-identification occurs; it also limits the analytical value of the data.
- CEncrypting sensitive data protects confidentiality but does not establish standard definitions or permitted uses; encryption is a security control, not a data governance mechanism.
- DData discovery identifies where personal data resides, which is a prerequisite for governance, but does not itself define or standardize how that data should be used across the organization.
The CDPSE guide explains every answer.