Data governance

Data governance is the framework of roles, rules and controls that defines who decides about which data and how it is used, protected and deleted. Legally, the outcome is required through the accountability principle in Article 5(2) GDPR. The Data Act, Regulation (EU) 2023/2854, has also applied since September 12, 2025.

GRCLast reviewed:

Data governance answers three questions for every relevant data set: who decides about it, which rules govern its use, and how is compliance checked? No duty by that name exists, but the outcome is required anyway.

Key takeaways

  • Data governance sets responsibilities, rules and controls for data; data management carries them out in operations.
  • Typical roles are data owner, data steward and data custodian. They come from practice, not from any statute.
  • Under Article 5(2) GDPR, the controller must be able to demonstrate compliance with the processing principles.
  • The Data Act (Regulation (EU) 2023/2854) has applied since September 12, 2025 and governs, among other things, access to data from connected products and switching between cloud services.
  • Despite its name, the Data Governance Act (Regulation (EU) 2022/868) does not regulate a company's internal data governance.

What is data governance?

Data governance is the framework of roles, policies, decision paths and controls through which a company steers how data is collected, stored, used, shared and deleted. The DAMA-DMBOK, the reference work of the Data Management Association, describes it as the exercise of authority and control (planning, monitoring and enforcement) over the management of data assets. ISO/IEC 38505-1 is a separate standard for the governance of data at board level.

The core is accountability: for every relevant data set, someone is named who decides on access, quality, sharing and deletion. Data classification, retention periods and evidence all depend on that assignment.

Data governance, data management and data protection compared

Data governance decides and controls, data management executes, and data protection sets the legal frame for personal data.

TermGuiding questionOutput
Data governanceWho decides about which data, under which rules?roles, policies, decision paths, controls
Data managementHow is data handled technically and organizationally?data models, integration, storage, backup, day-to-day data quality
Data protectionIs the processing of personal data lawful?legal basis, transparency, data subject rights, technical and organizational measures
IT governanceDoes IT support business goals and is it under control?IT strategy, oversight, frameworks such as COBIT
Information securityAre confidentiality, integrity and availability preserved?ISMS, risk treatment, security controls

Data governance is therefore a precondition for data protection: a record of processing activities or a retention policy stays on paper if nobody owns the underlying data sets.

Which roles belong to data governance?

The usual data governance roles are data owner, data steward and data custodian, plus a decision-making body. The titles are not set by law; smaller companies combine several roles in one person.

RoleResponsibilityTypical holder
Data ownerbusiness accountability for a data set; decides on access, use, sharing and protection needshead of the business unit the data serves
Data stewardapplies the owner's rules day to day, maintains definitions, checks data qualityexperienced specialist in the business unit
Data custodianruns the systems; implements permissions, backup and deletionIT operations or a service provider
Data governance boardadopts policies, resolves conflicts between unitsbusiness units, IT, data protection, information security
Chief data officerowns the company-wide data strategyseparate executive role, not present everywhere
Data protection officeradvises and monitors, but does not decide on purposes and meansappointed internally or externally

An owner has to be a person with decision rights, not a department.

The 6 building blocks of a data governance framework

A data governance framework has six building blocks that build on each other:

  1. Data policy: principles, scope and responsibilities, adopted by management.
  2. Roles and decision paths: named owners and stewards per data set, with escalation to the board.
  3. Data inventory: which data sets exist, where they sit and who is responsible.
  4. Classification: protection needs and categories of personal data per data set, with handling rules.
  5. Lifecycle rules: data quality, retention, sharing and deletion, aligned with the retention policy and the record of processing activities.
  6. Control: metrics, regular review and evidence.

How does data governance relate to the GDPR?

The GDPR does not require data governance by name, but it presupposes its results. Under Article 5(2) GDPR, the controller must be able to demonstrate compliance with the principles (“accountability”), and Article 24(1) requires appropriate technical and organizational measures, including the ability to demonstrate them. Data minimization, accuracy and storage limitation (Article 5(1)(c) to (e)), the record of processing activities under Article 30, security under Article 32 and the impact assessment under Article 35 all need an answer to which data sits where and who is responsible. The GDPR guide shows how these duties fit together.

Data Act and Data Governance Act: status as of October 2026

The Data Act, Regulation (EU) 2023/2854 of December 13, 2023, has applied since September 12, 2025 under Article 50, with some obligations phased in. Under Article 1(1) it covers, among other things, making data from connected products available to their users, data sharing by data holders, switching between data processing services, and safeguards against unlawful third-party access to non-personal data.

DateWhat appliesProvision
Sep 12, 2025general date of application; rules on unfair contractual terms (Chapter IV) for contracts concluded after this dateArt. 50
Sep 12, 2026access by design: connected products and related services placed on the market after this date must make their data accessible to the user by defaultArt. 3(1), Art. 50
Jan 12, 2027providers of data processing services may no longer charge switching feesArt. 29(1)
Sep 12, 2027Chapter IV also applies to older contracts that are open-ended or expire at least ten years after Jan 11, 2024Art. 50

Under Article 1(5), the Data Act applies without prejudice to data protection law, complements the rights under Articles 15 and 20 GDPR, and in case of conflict, data protection law prevails.

Data Governance Act: no rulebook for internal data governance

The Data Governance Act, Regulation (EU) 2022/868, has applied since September 24, 2023 and, under Article 1(1), covers re-use of certain protected public-sector data, data intermediation services, data altruism and the European Data Innovation Board, but not internal data governance. In the digital omnibus (COM(2025) 837) of November 19, 2025, the Commission proposed repealing it and moving parts of it into the Data Act; as of October 7, 2026 this is still a proposal, not law in force.

What does ISO 27001 require for data governance?

ISO/IEC 27001 has no data governance chapter but requires several of its building blocks. Annex A 5.9 requires an inventory of information and associated assets with owners, A 5.12 classification by protection needs, A 5.33 protection of records against loss and falsification, and A 5.34 handling personal data in line with applicable requirements. An ISMS thus lays part of the foundation, with its emphasis on protection rather than data quality and data use; the asset inventory is the shared basis.

Introducing data governance in 5 steps

Data governance can be introduced in five steps, starting with a few data sets:

  1. Pick the data sets with the highest risk or value, such as customer, HR or product data.
  2. Name a responsible person with decision rights per data set and, where needed, a steward.
  3. Record which systems and service providers hold the data, and classify it by protection needs and categories of personal data.
  4. Define rules for access, quality, sharing and deletion, and link them to the record of processing activities and the retention and erasure policy.
  5. Check regularly whether the rules are followed, and record the result and the date.

Data sets as assets in Rizzqo

Rizzqo models the accountability and protection side. A data set such as customer data is a primary asset of the type information, rated on confidentiality; processes and services carry confidentiality, integrity and availability ratings. Supporting assets (applications, systems, service providers) take over the primary asset's confidentiality rating and personal data flag; integrity and availability are rated on each of them. Every asset can be assigned an owner.

Which requirements appear on a supporting asset follows from its category and subcategory; they are finalized with name and timestamp. An open requirement can be linked to a risk assessment that combines likelihood in percent and impact in euros through a configurable matrix.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework