Protecting Trust: Why Data Governance is Non-Negotiable
All Posts
Data Governance

Protecting Trust: Why Data Governance is Non-Negotiable

By Günter Richter

Yesterday I received an email from a professional event photography business that my son's previous school and sports club has used for event photographs. As soon as I saw it was from the organisation's Data Protection Officer, I knew what it was going to contain. News of yet another data breach, involving my personal data. Name, address, email, and phone number. And of course a warning, "there is a potential risk of identity theft or other fraudulent activities. We strongly recommend that you remain vigilant and monitor your personal accounts for any suspicious activity". There you have it, due to a failing in their processes and systems, the onus is now on me to mitigate the risks that result from this breach. Of course, this is something that I already do but it poses the question "how seriously can customers take an organisation that cannot get the basics of data protection right?".

Consumers are becoming a lot more informed and prescriptive when it comes to the use of their data. Aside from the potential fines from regulators, organisations really need to get their acts together when it comes to the management of personal data, and data as a whole. It is therefore imperative that these organisations invest the necessary effort to ensure that they have a robust data governance capability in place, and this needs to be foundational to the organisation's data strategy. Get this wrong and organisations will expose themselves to a host of vulnerabilities and reputational damage as well as eroding customer trust.

Data governance has historically been a bit of a bland topic but has fast become a core capability that organisations need to develop. This is even more pressing with the growing adoption of AI and the multitude of use cases of the technology unlocks.

In addition to being one of the least sexy aspects data, data governance can also be a little nebulous. So what do I mean when I say that organisations need to build this capability? In summary, they need to ensure that a few key principles are in place by:

Ensuring clear ownership and accountability for data Ensuring compliance with regulations like GDPR, CCPA, and of course the upcoming EU AI Act Performing regular audits and risk assessments to identify weaknesses and improvement opportunities Empowering their staff improve their data literacy and helping them understand the importance of good data governance Given the importance of strong data governance, why do so many organisations find themselves in such a difficult place? I attribute this to three key factors:

The pace of business and technological innovation has outstripped the pace of data management and data governance efforts and organisations have now built up a serious level of "data governance debt" Because data governance can be rather nebulous, organisations just don't know where to start Organisations ignore the significant organisational change management element needed to successfully achieve a good data governance standard None of these issues are insurmountable and organisations should begin with the basics. Simply put, get started by expanding the key principles set out earlier in this article. This sets out your intention for data governance and the scope that you wish to include, such as data quality, data security, compliance, etc. It is also an excellent prompt to begin the organisational change management component of your data governance initiative.

The principles that you have defined should then drive the policies that you need to create and adopt. Start with a single, overarching data governance policy. This should cover, at minimum, the following content:

  • The policy purpose and scope
  • The data governance principles that have previously been identified
  • The broad roles and responsibilities (in the organisation) for data governance and good data management
  • Data access and usage rules (especially considering AI use cases)
  • Data quality and standards
  • Data security and privacy
  • Compliance and regulatory requirements
  • High-level data management procedures
  • Performance metrics to help track the progress of the data governance initiative
  • Specification on how the data governance policy will be reviewed and updated on a regular basis

Whilst there is rather a lot here, don't overthink things. Not all the sections of the data governance policy need to be fully fleshed out for your first version. Some sections may even be placeholders. The idea is to use the policy to begin building consensus and getting the organisation onboard.

The initial policy can then be evolved and elements can be broken out into supporting policies. For example, you may want to create a data quality policy that sets out more detail on how data quality will be managed and improved. The policy can take a similar form to the overarching data governance policy but of course will be specific to data quality and significantly expand on sections such as data quality standards and metrics.

Once your data governance policy has set up the guardrails, you can begin to focus on the next level of detail such as processes and procedures that will enable your data governance policy, along with the roles and responsibilities that will be needed.

Of course, do not forgot the required investment in communications and learning and development as part of your organisational change management effort.

There is of course a lot of supporting detail that will progress your data governance initiative and I will cover these topics in other articles. In the meantime, please feel free to use this guide to take the first step on your data governance journey

Share:LinkedInX
Günter Richter

Günter Richter

Founder & Principal Consultant, Umlaut Consulting

30+ years of experience in strategic consulting and data transformation. Helping organisations unlock the real value of their data.

Related Posts