Glossary

Data governance

Data governance is the set of rules, roles and processes an organisation uses to control how its data is collected, stored, used, shared and protected. It sets who is accountable for data quality and security, and how decisions about data get made.

Last updated

Part of our topic guide on AI Governance & Data Strategy.

Data governance is the set of rules, roles and processes an organisation uses to control how its data is collected, stored, used, shared and protected. It sets who is accountable for data quality and security, and how decisions about data get made.

What failing governance looks like

You rarely notice data governance until it's absent, so start there: reports from two teams that don't match, duplicate customer records nobody trusts, and nobody quite sure who's allowed to touch what. Every one of those symptoms is a governance gap wearing a technical costume. Get governance right and the payoff is equally concrete: every dashboard, model and decision built on top of that data is something people can actually trust.

The five decisions governance actually makes

Strip away the frameworks and data governance answers five questions, each needing a named answer rather than a vague one:

  • Who owns this dataset? A named data owner or steward for each key dataset, accountable for its quality and access.
  • What do our words mean? Agreed definitions, formats and quality rules, so "customer" or "revenue" means the same thing across every team.
  • Who can touch it? Who can see, edit or export data, and how that's enforced and audited.
  • How long does it live? How long data is kept, when it's archived, and how it's deleted when it should be.
  • What does the law require? Meeting legal obligations such as the UK GDPR and the Data Protection Act 2018, overseen by the Information Commissioner's Office (ICO).

Most organisations run these through a governance framework: a written set of policies plus a group (often a data governance board or a lead data steward) that keeps them enforced and up to date as the business and its data change.

Why the policy document alone never holds

Our view is that governance fails less often on policy and more often on people: a document sits in a wiki nobody reads, while the actual data work happens the way it always has. The fix isn't a longer policy; it's building data literacy into the people who touch the data every day, so the rules become habits rather than a compliance exercise bolted on afterwards. That's also why most data and AI initiatives stall: not for lack of tools, but for lack of the capability to use them well and consistently.