Skip to content
Getting Digital

Data Governance

Also: data ownership, data stewardship, data policy, data catalogue, data lineage, data management

Data governance is the set of decisions and responsibilities an organisation puts in place over its data: who owns each dataset, what each field means, who may read or change it, how long it is kept and how its quality is measured, recorded so that the answers do not depend on who is asked.

Assessment. Governance is effective when it exists as a maintained register rather than as a committee alone. An organisation that can state, for each dataset it relies on, the owner, the definition of each field, the access rule and the retention period has governance, whatever the arrangement is called; one that holds meetings without that register does not. The register comes first and the policies that reference it follow.

The DAMA Data Management Body of Knowledge, the reference most courses and job descriptions draw on, treats governance as the knowledge area that oversees the others: it sets the rules under which data is modelled, stored, integrated, secured and measured for quality. In practice the rules reduce to a small number of questions asked of every dataset the organisation depends on. Who is accountable for it. What each field means, in one agreed definition. Who may read it, who may change it, and under what approval. How long it is kept and when it is deleted. How its quality is measured and who is told when the measure falls. An organisation that can answer those questions for its principal datasets is governed; the method by which it arrived at the answers is secondary.

  • Owner: the role, not the person, accountable for a dataset's definition, quality and access decisions.
  • Steward: the person who maintains the definitions and the catalogue entry day to day and resolves disputes about meaning.
  • Catalogue: the register of datasets with their owners, definitions, sources, freshness and access rules; the artefact that makes the rest usable.
  • Lineage: the record of where each figure came from and what was done to it on the way, so that a number in a report can be traced to its source system.
  • Policy: the written rules on classification, access, retention and quality that the catalogue entries apply.

The reasons an organisation adopts governance are usually external before they are internal. Data-protection law requires it to know what personal data it holds, why, for how long and who can see it, and the UK framework for public-sector data quality frames the same requirements around fitness for purpose and clear ownership. Financial reporting requires figures to be traceable to their source. A data warehouse project discovers that three departments define a customer differently and needs an arbiter. Each of these produces the same register, and the organisations that build it once, for all three reasons, spend less than those that build it three times.

QuestionWithout governanceWith governance
What does active customer mean?Three definitions in three reportsOne definition in the catalogue, referenced by every report
Who may see salary data?Whoever has the database passwordA named role, enforced by row-level access and reviewed
Where did this revenue figure come from?An analyst's memoryLineage from the report to the source table and the transformation
When is this data deleted?Never, by defaultAt the end of the retention period stated in the policy

The discipline connects to data quality, which it defines the measures for and assigns the ownership of, and to security, where the access rules it sets are enforced. The platforms now carry much of the machinery, a catalogue, lineage captured from the pipelines, access rules attached to tables, which is why the AWS Data Engineer Associate, Databricks Data Engineer Associate and Microsoft Fabric Data Engineer exams each include a governance and security domain. The governance, quality and privacy courses cover the organisational side that the platforms cannot supply: the decision about who owns what.

In practice

A retailer receives a data-subject access request and cannot answer it within the statutory period, because nobody knows which of eleven systems hold data about the customer. The remediation is a catalogue: every system that holds personal data, the fields it holds, the owner, the retention period and the deletion method. The next request is answered in two days. The same catalogue is then used by the warehouse team to settle the definition of a customer and by the security team to review who has access to the systems on the list.

Often confused with

Data Quality
Data quality is the measured condition of the data; data governance is the arrangement that decides what to measure, who owns the result and what happens when it falls. Quality is an outcome of governance, not a synonym for it.
Security Risk Assessment
A risk assessment is a security exercise that identifies threats and their likelihood; data governance covers ownership, meaning, access and retention across the whole lifecycle of the data. The access rules governance sets are one input to the assessment.

Key takeaways

  • →Owner, definition, access, retention and quality measure for every dataset that matters: the register is the substance of governance.
  • →Law, financial reporting and warehouse projects all require the same register; build it once.
  • →The platforms supply catalogue, lineage and access controls; the organisation still has to decide who owns what.

Related concepts

  • Governance decides what is measured and who owns the result; quality is the measured result.

Where this concept sits in the field

Certifications that test this

Vendor exams whose syllabus covers this concept: facts, cost and a preparation path on each page.

More courses from these categories

Courses from the categories where this concept is taught. Details, price and the provider link are on each course page.

FAQ

Does a small organisation need data governance?
It needs the register as soon as it holds personal data or reports figures to anyone outside, which is almost immediately. At small scale the register is a document maintained by one person; the formal roles and committees are added when the number of datasets and owners makes a document insufficient.
Who should own the data governance function?
A role with authority across departments, since the disputes it settles are between departments. In practice it sits with a chief data officer where one exists, with finance or operations where one does not, and rarely succeeds when placed inside IT alone, because the definitions are business decisions.
How does governance relate to the GDPR and UK data-protection law?
The law requires an organisation to know what personal data it holds, on what basis, for how long and with what protection, and to demonstrate it. A governance register is the evidence; without one the obligations are met by memory, which does not satisfy a regulator.

Sources

The primary text this definition rests on. Read it before relying on this one.

Last reviewed 3 October 2026 · Getting Digital