Handed data governance with no job description? Standards bodies and the UK government each mean something precise by it, and each puts its edges somewhere else.

What Is Data Governance? A Plain Definition for a UK Business, and How It Differs from Data Protection and AI Governance

Guides

By James Cotton · Last updated · 9 min read

Part of our topic guides on AI Governance & Data Strategy and Data Literacy.

By James Cotton, Founder, iO-Sphere

How DAMA, ISO and Gartner define it

DAMA International gives its definition in The DAMA Guide to the Data Management Body of Knowledge (DAMA-DMBOK2R), the revised second edition published in 2024 by Technics Publications of Sedona, Arizona: "The exercise of authority, control, and shared decision-making (planning, monitoring, and enforcement) over the management of data assets."

ISO's summary of ISO/IEC 38505-1, the international standard on the governance of data, places it inside two larger kinds of governance: the standard "defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance".

The same summary addresses "governing bodies of organizations" on "the effective, efficient and acceptable use of data", and says the standard "is applicable to organizations of all sizes".

Gartner, a commercial analyst firm, puts the weight on decision rights. On its Peer Community page, as we read it on 8 October 2026, data governance "defines decision rights and creates an accountability framework to ensure appropriate valuation, creation, consumption and control of data and analytics".

None of these wordings names risk. In our view, deciding how much risk to accept with data is part of data governance, and it belongs with whoever answers for the data. The UK data protection regulator's Accountability toolkit warns that without "management focus on information governance" the control environment "may be ineffective", and that this "may breach article 5(2) of the UK GDPR".

For public sector projects, the government's Data and AI Ethics Framework, as updated in December 2025, named senior responsible owners "the primary risk owners for the project".

Who does the work: owners, stewards and custodians

In April 2026 the Government Digital Service published a data ownership model for government organisations; a business can borrow its terms without being bound by them. It made owners accountable, because they "ultimately 'own' the asset, making decisions on major changes and being answerable for them", and stewards responsible, as "experts on what is held within the asset".

RoleThe model's descriptionOne duty it listed
Data owner"a senior individual with dedicated accountabilities for data"Limiting access to data "to those authorised to do so"
Data steward"day-to-day operational activities in their data domain that support data owners' decisions"Handling "data governance queries"
Data custodian"capturing, storing and disposing of data in line with the data owner's requirements"Implementing "user access policies specified by the data owner"

The model asked owners to "be data literate". Beside these roles it placed one with risk in its title, the senior information risk owner: "Someone with particular responsibility for information risk."

The Data and AI Ethics Framework asked public sector projects to name these data roles too, and set an AI asset owner beside them, "responsible for AI outputs, including model predictions and any generated data".

Where one person carries the work, the civil service data governance manager profile, last updated in May 2026, described someone who "plans, monitors and enforces the management of data assets" and who should "assign ownership of data, ensuring there is a clear RACI (responsible, accountable, consulted and informed) matrix".

Accountability in UK data protection law

Article 5(2) of the UK GDPR says "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 ('accountability')", paragraph 1 being the data protection principles. Article 5 covers personal data, so it sets a floor under part of what data governance covers.

Article 24(1) adds that the controller "shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation", and review and update them where necessary.

The Information Commissioner's Office (ICO) set out what accountability asks in its Guide to accountability and governance, listing measures "you can, and in some cases must, take", from "adopting and implementing data protection policies" to "appointing a data protection officer". It called the guidance suitable for large businesses and sent small ones to its small business web hub.

Since 30 September 2026 the regulator has been the Information Commission (the ICO), after the office of Information Commissioner was abolished under the Data (Use and Access) Act 2025. The guide and the regulator's Accountability toolkit are both under review after that Act's changes.

One controller duty came fully into force on 19 June 2026. Under section 164A of the Data Protection Act 2018, a controller must facilitate complaints made under that section, acknowledge each within 30 days, and respond "without undue delay", telling the complainant the outcome.

Where its neighbours begin

Data management

DAMA draws this line with the DAMA Wheel in the same 2024 edition, which puts data governance at the centre of ten knowledge areas, from data architecture to metadata and data quality. Read with DAMA's definition, governance holds the authority and the areas around it do the managing.

ISO's Technical Report ISO/IEC TR 38505-2:2018, last confirmed in 2023, before Part 1's new edition, guides governing bodies and executives on what Part 1 means "for data management", so that data use "aligns with the strategic direction set by the governing body".

Information governance

NHS England's information governance policy (version 5.5) called information governance "an umbrella term which includes data protection, confidentiality and records management". The government's data ownership model called information and data governance "distinct responsibilities": information asset owners focused on "safeguarding and managing the overall information asset", and data ownership "looks more broadly at the quality, clarity and value of the data".

Data protection

The UK GDPR draws this line by scope: its principles apply to personal data. ISO's summary of 38505-1 covers data "created, collected, stored, secured, protected, or controlled by IT systems", so data that identifies nobody still falls within data governance.

The roles differ too. The government's model gave the data protection officer a one-line description: "A specified role defined in data protection law under the UK GDPR." Data owners and stewards are roles an organisation names for itself.

AI governance

A UK government definition, in the Department for Science, Innovation and Technology's Introduction to AI assurance of February 2024, called AI governance "a range of mechanisms including laws, regulations, policies, institutions, and norms that can all be used to outline processes for making decisions about AI". Our guide to what AI governance is takes it from there.

EU law uses the phrase too. Article 10 of the EU AI Act, "Data and data governance", says the training, validation and testing data of a high-risk AI system "shall be subject to data governance and management practices", including on "the origin of data" and "examination in view of possible biases". For UK rules, see our AI regulation register; for hiring, AI in recruitment and HR decisions.

What the 2026 business data survey found

The Department for Science, Innovation and Technology's UK Business Data Survey 2026, published on 18 June 2026 from fieldwork between October 2025 and January 2026, asked about data protection roles and AI policies, and no question about a data governance policy.

Among UK businesses that handle personal data (either of employees or others) and employ staff, the survey found 56% had someone whose job role includes leading on data protection compliance (Table 73, unweighted base 3,150; sole traders were not asked). The share rose with size:

Business sizeSomeone's role includes leading on data protection compliance
Micro (up to 9 employees)53%
Small (10 to 49)64%
Medium (50 to 249)74%
Large (250 or more)92%

By sector, the survey put it at 85% in finance and insurance and 35% in construction. Over the 12 months before the survey, 29% of the same businesses had employed or outsourced specialist staff, and 11% had run data protection training for existing staff, down from 23% in 2023 to 2024, the report noted.

Of businesses using AI, the survey found 17% had a policy or guidelines; of those, 62% said it included guidance on AI access to the business's data and files, with "no measurable variation across business size or sector". Our guide to a staff AI use policy covers what such a policy can say.

How a team learns it

The funded route into this work is ST0967, the Level 4 apprenticeship standard for a Data protection and information governance practitioner, at version 2.0 on the register when we read it on 8 October 2026. The occupation is "found in organisations of all sizes across all sectors where personal and commercial data is processed", and the standard is written in information governance and data protection terms.

Across the standard, "information governance" appears 15 times and "data management" twice; it never names data owners or data stewards, and neither "data governance" nor "AI" appears.

What makes it the route for data governance work is what the practitioner does. They "assist in the maintenance and administration of the organisations' information and governance framework" and "provide advice and training with regard to improving data management"; they "may occasionally be responsible for decision making, but more often will guide or influence the decisions of others". That is close to the steward in the government's model.

We deliver it as our Data & AI Governance apprenticeship (Level 4), teaching AI governance within it, for people who own information governance in their organisation and for analysts and data management, data quality and engineering people picking the work up, if the duties fit. The certificates in this field are in our guide to AI governance certifications in the UK.

The Data & AI Strategy apprenticeship (Level 4) shares the standard by design, because the occupation reaches into strategy: its practitioner supports "the senior team in the development and delivery of operational and strategic information requirements".

For a team newly handed data governance, we recommend putting the person who will run it day to day through the governance apprenticeship, and giving the colleagues around them our data and AI fluency training.

ST0967's funding band maximum, the most government funding puts towards its training and assessment, is £10,000. The employer's part of that depends on the apprentice's age at the start and on its apprenticeship levy position (the levy is a charge on employers with a pay bill over £3 million); our guide to the data protection and information governance apprenticeship takes the route in detail.

Frequently asked questions

Does the law require a data governance policy?

Not by that name. Article 24(2) of the UK GDPR asks a controller for "appropriate data protection policies", and its opening words set the condition: "Where proportionate in relation to processing activities". So it depends on what personal data you process and how. The regulator's toolkit goes further by way of suggestion, proposing that an organisation set out "the overall framework and strategy for information governance in policy documentation".

Who in a business should own data governance?

Someone senior, on both the regulator's suggestion and the government's model for its own bodies. The regulator suggests giving overall responsibility for data protection and information governance to "the board, or highest senior management level", with "data protection champions in key areas of the organisation" at operational level. The model put data ownership with "the business and not the technology domain". Neither is a legal duty on a business.

Can an organisation be certified to ISO/IEC 38505-1?

Not on ISO's own account: its page makes no certification claim and describes the standard as principles for governing bodies. UK buyers purchase the 2026 edition from the BSI store, and ISO lists the 2017 first edition as withdrawn.

Does the EU AI Act's data governance article apply to a UK business?

Not yet, and only to high-risk AI systems under EU law. Under Regulation (EU) 2026/1744, which amended the Act, the high-risk requirements, Article 10 among them, apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. The amendment left the data governance paragraph unchanged and added an Article 4a, "Processing of special categories of personal data for bias detection and correction".

Want to own AI governance in your organisation?

Our Level 4 Data & AI Governance programme builds the frameworks that make data trustworthy and AI accountable, funded through the Growth & Skills Levy.