Data Governance

What Is Data Governance? A Practical Guide

  • Data Governance
  • Data Management
  • Data Quality
  • AI Governance

Ask three departments for the number of active customers and you may receive three different answers.

Marketing counts anyone who opened an email. Finance counts customers who made a purchase during the year. Operations counts accounts that are still enabled. Each number may be correct for its own purpose, but the organisation has no shared definition - and no clear authority to settle the difference.

Now add harder questions. Who can access the customer data? Can it be shared with a service provider? How long should it be retained? Is its quality good enough for a demand forecast? Can it be used to train an AI model?

These are not merely technical questions. They require decisions about authority, responsibility, risk and acceptable use.

That is where data governance begins.

What is data governance?

Data governance is the way an organisation establishes decision-making authority, accountability, rules and oversight for data throughout its lifecycle.

Its purpose is to help the organisation use data effectively while keeping it trustworthy, protected and appropriately controlled.

In practical terms, data governance should make it possible to answer questions such as:

  • Who can make a decision about this data?
  • What is the data supposed to mean?
  • Which rules and obligations apply?
  • Who may access, change, share or reuse it?
  • How do we know whether it is accurate enough for its intended use?
  • How long should it be kept?
  • What happens when teams disagree or something goes wrong?

DAMA International describes data governance in terms of accountability, policies and decision rights. The ISO/IEC 38505 series places governance of data within the wider governance of an organisation and addresses the effective, efficient and acceptable use of data.

Both point to an important conclusion: data governance is not simply an IT activity. It is part of how an organisation directs and controls the use of an important asset.

Data governance is a decision system

Many organisations begin with a policy, a committee or a new software platform. Those things can support governance, but none of them is governance by itself.

A policy has little value if nobody has authority to apply it. A committee becomes a talking shop if decisions are never translated into action. A catalogue can show that data exists without resolving whether it is reliable, who may use it or what obligations apply.

The heart of data governance is a repeatable decision system:

The right people make the right decisions about data, using agreed rules, with enough information and evidence to remain accountable.

That system may be simple in a small organisation and more formal in a large or regulated one. The principle is the same.

A practical example

Consider a retail company that holds customer, product, supplier and inventory data.

The company wants to build a dashboard showing customer activity and stock demand. Several issues appear immediately:

  • Sales and finance define an “active customer” differently.
  • Product codes are inconsistent between the website and warehouse system.
  • Marketing wants access to purchase histories.
  • A technology provider will host part of the data.
  • The analytics team wants to use historical transactions for an AI forecast.
  • Nobody is certain how long older records should be kept.

Buying a new analytics platform will not resolve these questions. The organisation must first determine:

  • Which definitions should be used for which purposes
  • Who can approve access and sharing
  • What quality is required before the data is relied upon
  • Which legal, contractual and internal rules apply
  • Whether the proposed AI use is permitted and appropriate
  • Who accepts or escalates the remaining risk

Data management teams can then implement those decisions in systems and processes. Governance provides the authority and direction.

What does data governance cover?

Data governance is broader than data protection and broader than data quality. It connects several concerns that are often managed separately.

Purpose and value

Why is the data collected or created? Which organisational objective does it support? Is the cost and risk of keeping it justified by its value?

Meaning and quality

What does each important data element mean? Which definitions and standards apply? Is the data sufficiently accurate, complete, timely and consistent for its intended purpose?

Quality is always connected to use. The UK Government Data Quality Framework describes data quality at a high level as fitness for purpose: data must be good enough for what someone intends to do with it.

Access and protection

Who needs access? Who can approve it? Which technical and organisational safeguards are proportionate to the sensitivity, value and risk of the data?

Sharing and transfer

Can the data be shared internally, with a partner or with a service provider? What conditions, contracts, approvals or restrictions are required?

Retention and disposal

How long should the data remain available? Which legal, contractual, operational or historical reasons justify retention? What should happen when those reasons no longer apply?

Reuse, analytics and AI

Can data collected for one purpose be used for another analysis or an AI system? Is it suitable, lawful, representative and sufficiently documented? What human oversight is required?

Governance does not mean that one central team makes all these decisions. It means the authority, rules and escalation routes are clear.

The four parts of effective data governance

I find it useful to organise data governance into four connected parts: people, rules, tools and assurance. This is not a claim that every organisation needs the same formal structure. It is a practical way to check whether governance can function beyond paper.

1. People and accountability

Governance needs people with defined authority and responsibility.

This may include senior leadership, business functions, technology, legal, privacy, security, records management, risk and operational teams. Titles matter less than clarity about the decisions each role can make.

The essential questions are:

  • Who is accountable for the data and its use?
  • Who can approve access, sharing, retention or reuse?
  • Who manages quality issues?
  • Who advises on legal, technical or ethical requirements?
  • Who resolves disagreement or accepts an exception?

A role without authority is not accountability. A responsibility assigned to “the business” or “IT” is usually too vague to operate.

2. Rules and processes

Policies establish direction, but people also need workable processes.

These may cover:

  • Data collection and creation
  • Classification and handling
  • Access approval and review
  • Data quality issue management
  • Sharing and third-party processing
  • Retention and disposal
  • Incident response
  • Changes of purpose and reuse
  • AI and automated processing

The rules should explain not only what is required but how decisions are requested, recorded, reviewed and escalated.

3. Tools and information

People cannot govern data they cannot see or understand.

Useful tools may include:

  • A data inventory or catalogue
  • Business definitions and metadata
  • Data lineage records
  • Access-management systems
  • Quality rules and dashboards
  • Retention schedules
  • Contract and vendor records
  • Risk, impact and decision records

These do not all require specialist software. A well-maintained spreadsheet, clear workflow and disciplined review can be a valid starting point. Technology becomes valuable when it supports a defined governance process.

4. Monitoring and assurance

An organisation needs evidence that its decisions and controls are working.

Assurance can include:

  • Periodic access reviews
  • Data quality monitoring
  • Control testing
  • Policy compliance reviews
  • Issue and exception tracking
  • Vendor assurance
  • Internal or external audit
  • Reporting to leadership

Governance without assurance depends on hope. The goal is not to produce more reports; it is to detect where practice no longer matches the organisation’s decisions and correct it.

These disciplines overlap, but they answer different primary questions.

Discipline Primary question
Data governance Who may decide what about data, under which rules, and how is accountability demonstrated?
Data management How is data collected, stored, maintained, integrated and made available?
Data protection and privacy How must personal data be processed to protect individuals and meet applicable law?
Cybersecurity How are systems and data protected against threats, unauthorised access and disruption?
Data quality Is the data fit for its intended purpose?
Records management What must be retained as evidence, for how long, and what happens at the end of that period?

Data governance does not replace any of these disciplines. It helps connect their decisions and requirements.

For example, privacy law may determine that an organisation is a controller for a personal data activity. Governance translates that legal position into operational accountability, contracts, access rules, retention decisions and escalation procedures. For more on that distinction, see Controller or Processor? Your Role Depends on What You Do.

How governance works across the data lifecycle

Governance should follow data from the moment an activity is proposed until the data is disposed of or placed under a justified form of long-term preservation.

Plan

Define the purpose, expected value, responsible decision-makers, required data and applicable constraints before collection begins.

Collect or create

Use agreed definitions, collect only what is needed, record its origin and apply appropriate quality and protection controls.

Store and organise

Classify the data, maintain useful metadata, control access, protect it and ensure it can be found and understood.

Use and analyse

Confirm that the proposed use is permitted, that the data is fit for purpose and that important limitations are visible to the people relying on it.

Share or transfer

Identify the receiving party, purpose, authority, conditions, risks and required agreement before data moves.

Where personal data is involved, correctly identifying the parties’ roles is part of this work. Vietnam, for example, distinguishes a personal data controller, processor, and controller and processor. See Controller and Processor Roles Under Vietnam’s PDPL for the detailed position.

Retain, reuse or dispose

Review whether the original purpose and retention basis still apply. Decide whether data should be retained, reused under appropriate authority, de-identified, archived, returned or securely disposed of.

Governance is not one approval at the beginning. Decisions may need to be revisited as the data, purpose, technology or risk changes.

Why data governance programmes fail

The same failure patterns appear repeatedly.

Starting with documentation instead of decisions

An organisation produces a large policy suite without identifying the recurring decisions people struggle to make. The policies then sit outside everyday work.

Making the scope too broad

Trying to govern every dataset, process and system at once creates a programme too large to deliver. Nothing becomes visibly better.

Assigning responsibility without authority

People are named in a role chart but cannot approve access, require corrections or resolve conflicting priorities.

Buying a tool before defining the process

The organisation implements a catalogue or quality platform before agreeing what must be recorded, who will maintain it and which decisions it should support.

Treating governance as a compliance project

Compliance is important, but a programme built only around restrictions will be seen as an obstacle. Good governance should also make data easier to find, understand, trust and use.

Failing to connect policy with operations

If access requests, projects, procurement, analytics, retention and incident processes do not use the governance rules, the real organisation continues operating separately from the documented one.

Measuring activity instead of outcomes

Counting meetings, policies and catalogue entries does not show whether data is more reliable, decisions are faster or risks are better controlled.

How to start data governance practically

An organisation does not need to design an enterprise-wide programme before taking useful action.

1. Start with a real business need

Choose a small number of valuable or risky data activities. Examples might include customer reporting, supplier information, financial dashboards, access to sensitive information or data proposed for AI use.

2. Map the important decisions

For each activity, ask what decisions repeatedly cause delay, disagreement, poor quality or unacceptable risk.

3. Assign decision-making authority

Identify who can make each decision, who provides advice, who implements it and where unresolved matters are escalated.

4. Establish minimum rules

Define the smallest set of policies, standards and procedures required to make those decisions consistently.

5. Record what must be known

Build a proportionate inventory of the data, purpose, location, responsible parties, access, sharing, quality requirements, retention and applicable obligations.

6. Put governance into existing workflows

Connect it with project approval, system changes, procurement, access management, vendor onboarding, analytics and AI review. Avoid creating a separate governance universe that people can bypass.

7. Test, measure and improve

Pilot the approach, monitor the results and change what does not work. Expand only after the organisation can show that the first area is better governed.

This approach produces evidence and credibility early. It also allows the governance model to grow from real organisational needs rather than assumptions.

What should data governance measure?

Useful measures depend on the organisation’s objectives, but they should show whether governance is improving decisions and outcomes.

Examples include:

  • Time taken to resolve access, quality or sharing decisions
  • Percentage of important data with an agreed definition and responsible decision-maker
  • Number and age of unresolved quality issues
  • Completion and findings of access reviews
  • Compliance with retention and disposal decisions
  • Third-party processing arrangements with complete governance records
  • Repeated exceptions or policy breaches
  • Critical reports using data with known quality limitations
  • AI use cases with documented data sources, permissions and oversight

Not every measure should aim for zero. A sudden rise in reported quality issues may show that the organisation has become better at finding problems. Measures need interpretation, not just targets.

How data governance supports responsible AI

AI increases the importance of data governance because models and automated decisions depend on data that may have unclear origins, limitations, permissions or quality.

Before data is used with AI, an organisation should be able to answer:

  • Where did the data come from?
  • What was it collected or created for?
  • Can it be used for this new purpose?
  • Does it contain personal, confidential or restricted information?
  • Is it sufficiently complete, accurate and representative?
  • Which provider or system will receive it?
  • Will the provider retain or reuse it?
  • Who validates the output and remains accountable for its use?

AI governance cannot compensate for missing data governance. If the organisation cannot explain its data, authority or controls, it cannot responsibly explain the AI system built on top of them.

What good data governance looks like

Successful data governance is not necessarily highly visible. It appears in the quality and consistency of everyday decisions.

People know where to go for a decision. Important terms have agreed meanings. Access is proportionate and reviewable. Sharing is documented. Quality limitations are visible. Retention is intentional. Exceptions are escalated. Evidence is available when leadership, a customer, an auditor or a regulator asks what happened and why.

Most importantly, governance helps the organisation use data - not merely restrict it.

The outcome should be data that can be used with greater confidence because authority, responsibility and risk are understood.

Frequently asked questions

Is data governance only for large organisations?

No. Smaller organisations also make decisions about access, quality, sharing, retention and acceptable use. Their governance can be simpler and rely on existing roles and tools.

Does data governance cover only personal data?

No. It can cover customer, financial, operational, product, supplier, employee, technical and other data. Personal data introduces specific privacy and legal obligations, but it is only part of the governance scope.

Is data governance an IT responsibility?

IT plays an essential role in architecture, systems, access, security and implementation. However, business functions determine why data is needed, what it means and how it creates value. Effective governance requires both organisational and technical participation.

Do we need data governance software?

Not necessarily. Software can help with scale, automation, metadata and evidence. It cannot decide the organisation’s authority, priorities or rules. Start by defining the operating process and then select tools that support it.

What is the difference between data governance and data management?

Data governance establishes direction, decision rights and accountability. Data management performs the work needed to collect, store, maintain, protect and provide data. Governance decides what should happen and under whose authority; management makes it happen.

Final takeaway

Data governance is not a policy library, a committee or a software platform.

It is the organisational system through which decisions about data are made, applied and checked.

Effective governance brings together:

  • People with clear authority and accountability
  • Rules and processes that work in practice
  • Tools and information that support decisions
  • Assurance that shows whether the arrangements are working

Begin with the data activities that matter most. Make the important decisions explicit. Assign authority. Put the rules into everyday workflows. Then measure whether the organisation is making better use of data with greater confidence and control.

Data governance becomes valuable when it helps people make clear, responsible and repeatable decisions about data.

This article provides general information about data governance. The appropriate structure, controls and legal requirements depend on an organisation’s activities, risks and applicable obligations.