Learning Objectives

By the end of this lesson, learners should be able to:

  • Define data governance and explain its organizational importance.
  • Explain the relationship between data governance, privacy and security.
  • Identify key data-governance roles and responsibilities.
  • Explain fundamental principles of responsible data use.
  • Identify major data-security risks affecting analytics environments.
  • Evaluate appropriate controls for protecting organizational data.

1. Meaning of Data Governance

Data governance is the framework through which an organization establishes authority, accountability, policies, standards and processes for managing data.

Data governance addresses questions such as:

  • Who owns the data?
  • Who may access it?
  • What does a particular data element mean?
  • What quality standard must it meet?
  • How should it be protected?
  • How long should it be retained?
  • How may it be used?

Governance therefore establishes the rules under which data is managed and used.

2. Why Data Governance Matters

Effective governance supports:

  • Data quality.
  • Consistency.
  • Accountability.
  • Regulatory compliance.
  • Security.
  • Responsible data use.
  • Reliable analytics.

Without governance, different departments may create conflicting definitions, duplicate data, inappropriate access arrangements and inconsistent analytical practices.

3. Data Governance Framework

A governance framework may include:

  • Policies.
  • Standards.
  • Procedures.
  • Roles and responsibilities.
  • Data classifications.
  • Access controls.
  • Quality requirements.
  • Monitoring mechanisms.
  • Escalation processes.

The framework should be aligned with organizational objectives and applicable legal and regulatory requirements.

4. Data Governance Roles

Data Owner

Provides accountability for a data domain and determines appropriate use and access requirements.

Data Steward

Supports the operational implementation of data policies and helps maintain quality, definitions and consistency.

Data Custodian

Usually has technical responsibility for storing, maintaining and protecting data within systems.

Data User

Uses data in accordance with approved policies and access permissions.

These roles may be structured differently across organizations.

5. Data Classification

Organizations may classify information according to its sensitivity and business importance.

A classification framework might distinguish:

  • Public information.
  • Internal information.
  • Confidential information.
  • Highly sensitive information.

Classification helps determine appropriate:

  • Access controls.
  • Storage requirements.
  • Transmission methods.
  • Retention periods.
  • Security measures.

6. Data Privacy

Data privacy concerns how information about individuals is collected, used, shared and retained.

Privacy requires organizations to consider:

  • Purpose of collection.
  • Appropriate use.
  • Transparency.
  • Access.
  • Retention.
  • Sharing.
  • Individual rights where applicable.

Privacy is therefore broader than simply protecting data from hackers.

An organization can have strong cybersecurity and still use personal data in an inappropriate manner.

7. Personal Data

Personal data generally refers to information that relates to an identified or identifiable individual.

Examples may include:

  • Names.
  • Identification information.
  • Contact details.
  • Online identifiers.
  • Location information.
  • Certain financial or behavioral information.

The exact legal definition varies by jurisdiction and applicable law.

8. Data Minimization

Data minimization is the principle of limiting the collection and use of personal information to what is necessary and appropriate for the defined purpose.

Collecting large amounts of personal data simply because future use might be possible can increase:

  • Privacy risk.
  • Security exposure.
  • Storage costs.
  • Governance complexity.

Effective analytics therefore requires purposeful data collection.

9. Data Security

Data security involves protecting data from unauthorized access, alteration, disclosure, destruction or loss.

Important security objectives include:

Confidentiality

Only authorized parties should access information.

Integrity

Data should remain accurate and protected against unauthorized modification.

Availability

Authorized users should be able to access data when required.

Together these are commonly described as the CIA triad.

10. Access Control

Access should generally be based on legitimate business requirements.

Important principles include:

  • Least privilege.
  • Role-based access.
  • Authentication.
  • Authorization.
  • Access reviews.
  • Separation of duties.

The principle of least privilege means that users should receive only the level of access necessary to perform their authorized responsibilities.

11. Encryption

Encryption transforms data into a form that is difficult to interpret without the appropriate key.

It may be applied to:

  • Data at rest.
  • Data in transit.

Encryption is an important control but does not eliminate the need for access management, monitoring and other security measures.

12. Data Breaches

A data breach can occur when information is:

  • Accessed without authorization.
  • Disclosed improperly.
  • Lost.
  • Stolen.
  • Exposed through a security weakness.

Potential consequences include:

  • Financial losses.
  • Legal consequences.
  • Operational disruption.
  • Reputational damage.
  • Loss of stakeholder trust.

13. Privacy and Analytics

Analytics can create additional privacy risks because combining datasets may reveal information that was not obvious when each dataset was considered independently.

For example, several seemingly harmless variables may collectively make an individual identifiable.

Analysts should therefore consider privacy risks throughout the analytical lifecycle.

14. Ethical Data Governance

Responsible governance requires organizations to consider not only what they can do with data, but also what they should do.

Questions may include:

  • Is the proposed use legitimate?
  • Is the data relevant?
  • Is the use proportionate?
  • Could the analysis unfairly disadvantage a group?
  • Is the processing transparent?
  • Are appropriate safeguards in place?

Ethical governance strengthens trust in analytics.

Lesson Summary

Data governance establishes the authority, accountability, standards and controls required to manage organizational data responsibly.

Privacy focuses on the appropriate collection and use of information, particularly information relating to individuals, while security focuses on protecting data against unauthorized access, alteration, disclosure and loss.

Effective governance combines:

  • Clear roles.
  • Data classification.
  • Access controls.
  • Data-quality requirements.
  • Privacy principles.
  • Security controls.
  • Monitoring.
  • Accountability.

References

  1. DAMA International — DAMA-DMBOK
    DAMA International
  2. ISO/IEC 27001 — Information Security Management Systems
    ISO/IEC 27001
  3. NIST — Cybersecurity Framework
    NIST Cybersecurity Framework
  4. OECD — Privacy Guidelines
    OECD Privacy Guidelines

Review Questions

  1. What is data governance?
  2. Why is governance important for analytics?
  3. What distinguishes a data owner from a data steward?
  4. What is the role of a data custodian?
  5. Why is data classification important?
  6. How does data privacy differ from data security?
  7. What is data minimization?
  8. What are confidentiality, integrity and availability?
  9. What is the principle of least privilege?
  10. Why can combining datasets create additional privacy risks?
  11. Why does encryption not provide complete data security?
  12. What factors should organizations consider when making ethical decisions about data use?