Overview
Curated: · Written: · Reviewed:
Data governance assigns accountable decisions across the data lifecycle
Data governance is the system of decision rights, policies, standards, controls, evidence and escalation used to create value from data while managing quality, security, privacy, legal, ethical and operational risk. It is not possession of a database, a quarterly committee, a catalogue purchase or an approval queue. A healthy model puts decisions with the right accountable people, delegates day-to-day responsibility, automates repeatable controls and makes exceptions visible.
Ownership means accountability, not personal property. A data owner is answerable for a logical asset or domain: meaning, fitness, lifecycle, strategic use, quality, sharing conditions and major changes. A steward manages definitions, quality issues, catalogue content and operational policy. A custodian or platform team implements storage, access, protection, backup and processing controls. Process, product, privacy, security, records and legal roles retain their own accountabilities. A RACI helps expose gaps but cannot substitute for named authority and sufficient skill, time and budget.
Inventory and classify data by business purpose, users, criticality, sensitivity, legal/contractual constraints and lifecycle stage. Prioritize critical and widely shared assets because their failure has larger downstream impact. Catalogue identity, owner, source, lineage, schema/version, quality, refresh, access, permitted use, retention, licensing and limitations. Unknown copies and shadow pipelines are governance gaps even if the authoritative dataset is well controlled.
Quality is fitness for specified use, not one universal score. Define critical data elements and consumer decisions, then accuracy, completeness, validity, consistency, uniqueness, timeliness and integrity expectations with thresholds, measurement point and owner. A producer may meet its operational purpose while an analytical reuse needs stronger history or precision. Publish limitations and incident status; do not label data trusted without scope and evidence.
Access follows least privilege and purpose. Identify principal, role or attribute, dataset/field/row/action, environment, purpose, duration, approval authority and logging. Separate authorization from data discoverability: people can learn that an asset exists without receiving its sensitive contents. Use time-bound access and periodic review, revoke on role or purpose change, and test effective policy across warehouses, extracts, notebooks, BI, files and downstream shares.
Privacy governance begins before collection. Define purpose and lawful basis where applicable; minimize data, linkability, precision and retention; make transparency and individual rights workable; assess privacy risk and high-risk processing; restrict secondary use; and govern processors and transfers. Pseudonymized data remains personal data where additional information or other reasonably likely means can identify someone; health or other special-category attributes stay special-category after identifiers are replaced. Consent is not the only legal basis and is not valid simply because a checkbox exists. Legal requirements vary, so named privacy/legal authority must interpret obligations.
Ethical review extends beyond legal compliance. Ask whether the intended public or user benefit is legitimate and proportionate, which groups gain or bear harm, whose data or voice is absent, whether proxy variables create unfair treatment, and what contestability or recourse exists. Record alternatives and stop conditions. Ethics cannot be outsourced to a checklist or used to make unsupported claims that a system is fair.
Sharing requires an explicit purpose, minimum data, authority, roles, quality/semantic contract, security method, permitted use, retention, incident coordination, onward-sharing rule and exit. The provider remains accountable for its source; a recipient becomes accountable for the copy and processing it controls. A data-sharing agreement does not technically enforce policy, and encryption does not establish lawful or appropriate use.
Retention and deletion must cover primary stores, replicas, caches, logs, extracts, backups, models and derived datasets. Tie retention to purpose, legal/records schedules and recovery needs; define holds, archival, disposal verification and downstream propagation. Infinite retention increases value only in slogans—it also increases breach, discovery, misuse and re-identification exposure. Deletion may be delayed in protected backups, but access and expiry must be controlled and accurately communicated.
Lineage connects sources, transformations, jobs/runs and outputs so teams can assess change impact, incidents, rights requests and provenance. It complements, rather than replaces, business ownership and definitions. Automate lineage where possible, validate completeness and protect sensitive metadata. A beautiful graph with anonymous owners, stale nodes or missing manual extracts is not governance.
Change governance should classify semantic, schema, quality, access, retention and source changes, identify affected consumers, test compatibility, communicate support windows and preserve decision history. Emergency changes still need retrospective review. Exceptions specify scope, justification, risk, authority, compensating controls, expiry and convergence plan. Permanent undocumented exceptions create a second policy system.
Governance metrics should reflect outcomes: ownership coverage for critical assets, issue resolution, access-review findings, stale metadata, unauthorized copies, quality incidents, deletion completion, change failures, exception aging, sharing lead time and consumer trust. Avoid measuring policy pages, committee attendance or access denials alone. Excessive friction encourages shadow data; weak controls create invisible risk. Review both protection and safe value realization.
Test governance through real journeys: request access, onboard a new source, change a definition, discover a quality issue, share externally, answer an individual request, impose a legal hold, respond to breach, revoke a vendor, restore backup and retire an asset. Verify decision ownership, technical enforcement, evidence, communication and appeal. Good governance makes responsible use easier, risky use harder and every material decision accountable.
