Learning Objectives
By the end of this lesson, learners should be able to:
- Define data governance and explain its organizational importance.
- Explain the relationship between data governance, privacy and security.
- Identify key data-governance roles and responsibilities.
- Explain fundamental principles of responsible data use.
- Identify major data-security risks affecting analytics environments.
- Evaluate appropriate controls for protecting organizational data.
1. Meaning of Data Governance
Data governance is the framework through which an organization establishes authority, accountability, policies, standards and processes for managing data.
Data governance addresses questions such as:
- Who owns the data?
- Who may access it?
- What does a particular data element mean?
- What quality standard must it meet?
- How should it be protected?
- How long should it be retained?
- How may it be used?
Governance therefore establishes the rules under which data is managed and used.
2. Why Data Governance Matters
Effective governance supports:
- Data quality.
- Consistency.
- Accountability.
- Regulatory compliance.
- Security.
- Responsible data use.
- Reliable analytics.
Without governance, different departments may create conflicting definitions, duplicate data, inappropriate access arrangements and inconsistent analytical practices.
3. Data Governance Framework
A governance framework may include:
- Policies.
- Standards.
- Procedures.
- Roles and responsibilities.
- Data classifications.
- Access controls.
- Quality requirements.
- Monitoring mechanisms.
- Escalation processes.
The framework should be aligned with organizational objectives and applicable legal and regulatory requirements.
4. Data Governance Roles
Data Owner
Provides accountability for a data domain and determines appropriate use and access requirements.
Data Steward
Supports the operational implementation of data policies and helps maintain quality, definitions and consistency.
Data Custodian
Usually has technical responsibility for storing, maintaining and protecting data within systems.
Data User
Uses data in accordance with approved policies and access permissions.
These roles may be structured differently across organizations.
5. Data Classification
Organizations may classify information according to its sensitivity and business importance.
A classification framework might distinguish:
- Public information.
- Internal information.
- Confidential information.
- Highly sensitive information.
Classification helps determine appropriate:
- Access controls.
- Storage requirements.
- Transmission methods.
- Retention periods.
- Security measures.
6. Data Privacy
Data privacy concerns how information about individuals is collected, used, shared and retained.
Privacy requires organizations to consider:
- Purpose of collection.
- Appropriate use.
- Transparency.
- Access.
- Retention.
- Sharing.
- Individual rights where applicable.
Privacy is therefore broader than simply protecting data from hackers.
An organization can have strong cybersecurity and still use personal data in an inappropriate manner.
7. Personal Data
Personal data generally refers to information that relates to an identified or identifiable individual.
Examples may include:
- Names.
- Identification information.
- Contact details.
- Online identifiers.
- Location information.
- Certain financial or behavioral information.
The exact legal definition varies by jurisdiction and applicable law.
8. Data Minimization
Data minimization is the principle of limiting the collection and use of personal information to what is necessary and appropriate for the defined purpose.
Collecting large amounts of personal data simply because future use might be possible can increase:
- Privacy risk.
- Security exposure.
- Storage costs.
- Governance complexity.
Effective analytics therefore requires purposeful data collection.
9. Data Security
Data security involves protecting data from unauthorized access, alteration, disclosure, destruction or loss.
Important security objectives include:
Confidentiality
Only authorized parties should access information.
Integrity
Data should remain accurate and protected against unauthorized modification.
Availability
Authorized users should be able to access data when required.
Together these are commonly described as the CIA triad.
10. Access Control
Access should generally be based on legitimate business requirements.
Important principles include:
- Least privilege.
- Role-based access.
- Authentication.
- Authorization.
- Access reviews.
- Separation of duties.
The principle of least privilege means that users should receive only the level of access necessary to perform their authorized responsibilities.
11. Encryption
Encryption transforms data into a form that is difficult to interpret without the appropriate key.
It may be applied to:
- Data at rest.
- Data in transit.
Encryption is an important control but does not eliminate the need for access management, monitoring and other security measures.
12. Data Breaches
A data breach can occur when information is:
- Accessed without authorization.
- Disclosed improperly.
- Lost.
- Stolen.
- Exposed through a security weakness.
Potential consequences include:
- Financial losses.
- Legal consequences.
- Operational disruption.
- Reputational damage.
- Loss of stakeholder trust.
13. Privacy and Analytics
Analytics can create additional privacy risks because combining datasets may reveal information that was not obvious when each dataset was considered independently.
For example, several seemingly harmless variables may collectively make an individual identifiable.
Analysts should therefore consider privacy risks throughout the analytical lifecycle.
14. Ethical Data Governance
Responsible governance requires organizations to consider not only what they can do with data, but also what they should do.
Questions may include:
- Is the proposed use legitimate?
- Is the data relevant?
- Is the use proportionate?
- Could the analysis unfairly disadvantage a group?
- Is the processing transparent?
- Are appropriate safeguards in place?
Ethical governance strengthens trust in analytics.
Lesson Summary
Data governance establishes the authority, accountability, standards and controls required to manage organizational data responsibly.
Privacy focuses on the appropriate collection and use of information, particularly information relating to individuals, while security focuses on protecting data against unauthorized access, alteration, disclosure and loss.
Effective governance combines:
- Clear roles.
- Data classification.
- Access controls.
- Data-quality requirements.
- Privacy principles.
- Security controls.
- Monitoring.
- Accountability.
References
- DAMA International — DAMA-DMBOK
DAMA International - ISO/IEC 27001 — Information Security Management Systems
ISO/IEC 27001 - NIST — Cybersecurity Framework
NIST Cybersecurity Framework - OECD — Privacy Guidelines
OECD Privacy Guidelines
Review Questions
- What is data governance?
- Why is governance important for analytics?
- What distinguishes a data owner from a data steward?
- What is the role of a data custodian?
- Why is data classification important?
- How does data privacy differ from data security?
- What is data minimization?
- What are confidentiality, integrity and availability?
- What is the principle of least privilege?
- Why can combining datasets create additional privacy risks?
- Why does encryption not provide complete data security?
- What factors should organizations consider when making ethical decisions about data use?