Data governance answers three questions for every relevant data set: who decides about it, which rules govern its use, and how is compliance checked? No duty by that name exists, but the outcome is required anyway.
Key takeaways
- Data governance sets responsibilities, rules and controls for data; data management carries them out in operations.
- Typical roles are data owner, data steward and data custodian. They come from practice, not from any statute.
- Under Article 5(2) GDPR, the controller must be able to demonstrate compliance with the processing principles.
- The Data Act (Regulation (EU) 2023/2854) has applied since September 12, 2025 and governs, among other things, access to data from connected products and switching between cloud services.
- Despite its name, the Data Governance Act (Regulation (EU) 2022/868) does not regulate a company's internal data governance.
What is data governance?
Data governance is the framework of roles, policies, decision paths and controls through which a company steers how data is collected, stored, used, shared and deleted. The DAMA-DMBOK, the reference work of the Data Management Association, describes it as the exercise of authority and control (planning, monitoring and enforcement) over the management of data assets. ISO/IEC 38505-1 is a separate standard for the governance of data at board level.
The core is accountability: for every relevant data set, someone is named who decides on access, quality, sharing and deletion. Data classification, retention periods and evidence all depend on that assignment.
Data governance, data management and data protection compared
Data governance decides and controls, data management executes, and data protection sets the legal frame for personal data.
| Term | Guiding question | Output |
|---|---|---|
| Data governance | Who decides about which data, under which rules? | roles, policies, decision paths, controls |
| Data management | How is data handled technically and organizationally? | data models, integration, storage, backup, day-to-day data quality |
| Data protection | Is the processing of personal data lawful? | legal basis, transparency, data subject rights, technical and organizational measures |
| IT governance | Does IT support business goals and is it under control? | IT strategy, oversight, frameworks such as COBIT |
| Information security | Are confidentiality, integrity and availability preserved? | ISMS, risk treatment, security controls |
Data governance is therefore a precondition for data protection: a record of processing activities or a retention policy stays on paper if nobody owns the underlying data sets.
Which roles belong to data governance?
The usual data governance roles are data owner, data steward and data custodian, plus a decision-making body. The titles are not set by law; smaller companies combine several roles in one person.
| Role | Responsibility | Typical holder |
|---|---|---|
| Data owner | business accountability for a data set; decides on access, use, sharing and protection needs | head of the business unit the data serves |
| Data steward | applies the owner's rules day to day, maintains definitions, checks data quality | experienced specialist in the business unit |
| Data custodian | runs the systems; implements permissions, backup and deletion | IT operations or a service provider |
| Data governance board | adopts policies, resolves conflicts between units | business units, IT, data protection, information security |
| Chief data officer | owns the company-wide data strategy | separate executive role, not present everywhere |
| Data protection officer | advises and monitors, but does not decide on purposes and means | appointed internally or externally |
An owner has to be a person with decision rights, not a department.
The 6 building blocks of a data governance framework
A data governance framework has six building blocks that build on each other:
- Data policy: principles, scope and responsibilities, adopted by management.
- Roles and decision paths: named owners and stewards per data set, with escalation to the board.
- Data inventory: which data sets exist, where they sit and who is responsible.
- Classification: protection needs and categories of personal data per data set, with handling rules.
- Lifecycle rules: data quality, retention, sharing and deletion, aligned with the retention policy and the record of processing activities.
- Control: metrics, regular review and evidence.
How does data governance relate to the GDPR?
The GDPR does not require data governance by name, but it presupposes its results. Under Article 5(2) GDPR, the controller must be able to demonstrate compliance with the principles (“accountability”), and Article 24(1) requires appropriate technical and organizational measures, including the ability to demonstrate them. Data minimization, accuracy and storage limitation (Article 5(1)(c) to (e)), the record of processing activities under Article 30, security under Article 32 and the impact assessment under Article 35 all need an answer to which data sits where and who is responsible. The GDPR guide shows how these duties fit together.
Data Act and Data Governance Act: status as of October 2026
The Data Act, Regulation (EU) 2023/2854 of December 13, 2023, has applied since September 12, 2025 under Article 50, with some obligations phased in. Under Article 1(1) it covers, among other things, making data from connected products available to their users, data sharing by data holders, switching between data processing services, and safeguards against unlawful third-party access to non-personal data.
| Date | What applies | Provision |
|---|---|---|
| Sep 12, 2025 | general date of application; rules on unfair contractual terms (Chapter IV) for contracts concluded after this date | Art. 50 |
| Sep 12, 2026 | access by design: connected products and related services placed on the market after this date must make their data accessible to the user by default | Art. 3(1), Art. 50 |
| Jan 12, 2027 | providers of data processing services may no longer charge switching fees | Art. 29(1) |
| Sep 12, 2027 | Chapter IV also applies to older contracts that are open-ended or expire at least ten years after Jan 11, 2024 | Art. 50 |
Under Article 1(5), the Data Act applies without prejudice to data protection law, complements the rights under Articles 15 and 20 GDPR, and in case of conflict, data protection law prevails.
Data Governance Act: no rulebook for internal data governance
The Data Governance Act, Regulation (EU) 2022/868, has applied since September 24, 2023 and, under Article 1(1), covers re-use of certain protected public-sector data, data intermediation services, data altruism and the European Data Innovation Board, but not internal data governance. In the digital omnibus (COM(2025) 837) of November 19, 2025, the Commission proposed repealing it and moving parts of it into the Data Act; as of October 7, 2026 this is still a proposal, not law in force.
What does ISO 27001 require for data governance?
ISO/IEC 27001 has no data governance chapter but requires several of its building blocks. Annex A 5.9 requires an inventory of information and associated assets with owners, A 5.12 classification by protection needs, A 5.33 protection of records against loss and falsification, and A 5.34 handling personal data in line with applicable requirements. An ISMS thus lays part of the foundation, with its emphasis on protection rather than data quality and data use; the asset inventory is the shared basis.
Introducing data governance in 5 steps
Data governance can be introduced in five steps, starting with a few data sets:
- Pick the data sets with the highest risk or value, such as customer, HR or product data.
- Name a responsible person with decision rights per data set and, where needed, a steward.
- Record which systems and service providers hold the data, and classify it by protection needs and categories of personal data.
- Define rules for access, quality, sharing and deletion, and link them to the record of processing activities and the retention and erasure policy.
- Check regularly whether the rules are followed, and record the result and the date.
Data sets as assets in Rizzqo
Rizzqo models the accountability and protection side. A data set such as customer data is a primary asset of the type information, rated on confidentiality; processes and services carry confidentiality, integrity and availability ratings. Supporting assets (applications, systems, service providers) take over the primary asset's confidentiality rating and personal data flag; integrity and availability are rated on each of them. Every asset can be assigned an owner.
Which requirements appear on a supporting asset follows from its category and subcategory; they are finalized with name and timestamp. An open requirement can be linked to a risk assessment that combines likelihood in percent and impact in euros through a configurable matrix.