Data Engineering › Data Governance & Privacy
Data Governance
The policies and roles that decide how data is managed and used.
Also known as: data governance framework, data management policies, governing data, data stewardship policy
Data governance is the set of policies, roles and processes that decide how data is managed and used across an organisation: who can access it, what it means, how good it must be, how long it is kept, and who is accountable when something goes wrong. It is more organisational than technical, though tooling makes it practical.
Without it, things drift. Every team copies the customer table, defines “active customer” differently, and grants its own access. The classic failure: a regulator or an executive asks “where does this personal data live, who can see it, and who approved it?”, and no one can answer.
What governance covers
- Ownership: a named person or team accountable for each important dataset (data ownership).
- Definitions and metadata: a shared data dictionary and catalog so terms and columns mean the same thing (metadata types).
- Classification and access: labelling sensitivity and enforcing least privilege (data classification, column-level security).
- Quality and promises: quality checks and service levels (data quality, data SLA).
- Lineage and audit: knowing where data came from and what changed (data lineage).
- Privacy and retention: collecting only what is needed and deleting it on time (privacy by design, data retention, GDPR).
- Lifecycle and change: contracts, deprecation, and approval for new uses.
Trade-offs
Governance that is only documents and committees slows everyone down and gets bypassed. Governance that is absent produces chaos, breaches and untrustworthy numbers. The workable middle is to match control to sensitivity and value: strict rules and enforcement for restricted and regulated data, lighter guidance for the rest. Embed the rules in the tools people already use, so compliance is the default rather than an extra step.
Start with the data that matters most and the obligations you actually have, and grow from there. An unused policy is not governance.