Data governance is how an organisation decides who can use which data, for what, and to what standard.
Core Elements
- Ownership and stewardship: named people accountable for each important dataset.
- Definitions: a shared business glossary so "customer" and "revenue" mean the same thing everywhere.
- Access control: permissions based on roles and need, with sensitive data protected.
- Quality: standards, monitoring and processes to fix issues.
- Lifecycle: retention and deletion rules.
- Compliance: meeting privacy and industry regulations.
Data Classification
Label data by sensitivity — public, internal, confidential, restricted — and apply controls accordingly, such as masking personal fields for most users.
Catalogues and Lineage
A data catalogue helps people find datasets, understand them and see who owns them. Lineage shows where data comes from and where it flows, which is essential for impact analysis and audits.
Governance for AI
AI adds requirements: documenting training data sources and licences, controlling which data may train models, and tracking which models use which data.
Making It Work
- Start with the most important data domains, not everything at once.
- Automate controls where possible rather than relying on manual approvals.
- Make the governed path the easiest path — self-service access to well-documented, approved data.
- Measure outcomes: fewer incidents, faster access, consistent metrics.
Governance that only says "no" gets bypassed. Aim for enablement with guardrails.