Glossary
Information governance
Last updated
Part of our topic guide on AI Governance & Data Strategy.
Information governance is how an organisation manages information as an asset throughout its life: the policies, roles and controls that keep data accurate, secure, accessible to the right people, and used lawfully. It covers everything from how records are created and stored to when they're deleted.
Where's the boundary with data protection?
This is the distinction the two terms' overlap hides. Data protection deals specifically with personal data: information about identifiable living people, governed by the UK GDPR and the Data Protection Act 2018. Information governance is the broader discipline that personal data sits inside: it manages all of an organisation's information (contracts, financial records, operational data, personal data alike) across its whole life. Every data protection duty is an information governance concern; plenty of information governance concerns (say, version control on a supplier contract) have nothing to do with personal data.
The connected areas it runs across
- Policy and accountability: who owns which information, and who's responsible for how it's classified, retained and disposed of.
- Security and access control: making sure only the right people can see or change information, and that there's a record of who did what.
- Data quality: keeping information accurate, complete and fit for the decisions it supports.
- Compliance: meeting legal obligations such as the UK GDPR and the Data Protection Act 2018, overseen by the Information Commissioner's Office (ICO).
- Records management: how long information is kept, and how it's securely disposed of once it's no longer needed.
These pieces only work together: a policy is only as good as the access controls that enforce it, and compliance depends on records being managed consistently, not just written down. Get the whole thing wrong and the damage isn't abstract: it's a data breach that lands on the front page, a decision made on records nobody can trust, or a regulator's letter you can't answer well. Get it right and the business can actually use its data with confidence: you can't build reliable reporting, analytics or AI on information nobody's kept straight.
Whose job is it?
Everyone who touches data, which is the unfashionable answer but the true one. In our view this is exactly why digital and data literacy deserves to sit alongside English and maths as a basic workplace skill, not a specialist add-on: good governance depends on everyone handling information doing their bit properly, not just the person with "data" in their job title.
For the specialists, a funded route exists: in England, information governance is covered by the Level 4 Data Protection and Information Governance Practitioner apprenticeship standard. Day to day, an apprentice on this route works on real organisational information (classifying records, supporting data-protection compliance, managing access and retention, responding to information requests) under the guidance of people already doing that work, with the final assessment set by the standard's own assessment plan. As with any standard, fit is judged against its actual knowledge, skills and behaviours, not job titles: plenty of roles that never use the phrase "information governance" still cover the ground it describes. We deliver this standard as our Data & AI Governance apprenticeship, so read our enthusiasm for the route with that disclosed.