Data Dictionary

Data governance

What is data governance?

Data governance is the set of roles, rules, processes, and controls that determines how an organisation manages and uses its data. It answers practical questions: who owns this dataset, what does this field mean, who may see it, how long may we keep it, which quality rules apply, and who fixes it when it breaks?

Without governance, every department builds its own truth. Sales has one revenue definition. Finance has another. A dashboard exports customer data to a spreadsheet with no owner. An audit starts, and nobody can explain where a number came from.

TechTarget's common definition describes data governance as managing the availability, usability, integrity, and security of enterprise data. In daily language: governance is the operating model for data, the way accounting rules are the operating model for financial numbers.

The pillars of data governance

Ownership and stewardship
Every important dataset needs an owner who can make decisions and a steward who keeps definitions, quality, and metadata in shape.

Data quality
Governance defines which quality rules matter: completeness, uniqueness, validity, consistency, timeliness, and who responds when those rules fail.

Data lineage
Lineage shows where data came from, which transformations touched it, and which reports, models, or applications depend on it. It is essential for impact analysis and incident response.

Classification
Data needs labels: public, internal, confidential, personal data, financial data, trade secret, health data. Different labels need different controls.

Access control
Governance decides who may see rows, columns, tables, reports, and exports. In analytics platforms this often appears as role-based access, row-level security, object-level security, sensitivity labels, and audit logs.

Policies and standards
Naming conventions, retention rules, glossary terms, export rules, data product requirements, AI-use rules, and incident procedures all belong here.

Governance roles

Chief Data Officer
The strategic owner of the data programme. In a large organisation, the CDO sets direction, secures sponsorship, and reports on progress.

Data owner
The business decision-maker for a dataset or domain. The owner approves definitions, access rules, quality targets, and improvement priorities.

Data steward
The operational maintainer. A steward documents definitions, watches quality, answers questions, manages glossary terms, and follows up issues.

Data custodian
The technical caretaker. Custodians handle infrastructure, backups, permissions implementation, monitoring, and technical controls.

The useful distinction is simple: the owner decides what should be true; the custodian implements the technical control; the steward keeps the day-to-day data understandable and usable.

Governance in the Microsoft stack

In Microsoft environments, Microsoft Purview is the main governance platform. Purview Unified Catalog and Data Map help inventory data assets, metadata, lineage, classifications, glossary terms, and governance domains. It can sit alongside Microsoft Fabric, Power BI, Microsoft 365, and Azure sources.

Power BI and Fabric also carry governance controls inside the analytics layer: workspaces, domains, sensitivity labels, endorsements, row-level security, object-level security, audit logs, and capacity boundaries.

Purview is a tool, not the governance programme itself. A catalog can store owners and classifications, but the organisation still has to decide who those owners are and what the classifications mean.

Legal context in Europe

GDPR
GDPR governs personal data. It forces practical governance work: lawful basis, purpose limitation, minimisation, accuracy, retention, security, data subject rights, and accountability.

AI Act
The EU AI Act adds data-governance obligations for high-risk AI systems, especially around training, validation, and testing data: relevance, representativeness, quality, bias checks, documentation, and traceability.

NIS2
NIS2 focuses on cybersecurity and resilience for important and essential entities. Data integrity, access control, incident response, and accountability often meet governance work here, especially in critical sectors.

For SMEs, the point is not to memorise every regulation. The point is to make ownership, classification, access, retention, and incident handling explicit before a regulator, customer, or insurer asks.

What to watch out for

Governance theatre
Policies that exist only in slides do not govern anything. A practical test: can someone publish a new dataset without owner, definition, classification, and access review? If yes, the process is paper-thin.

Too central and too slow
If one committee must approve every field change, people work around it. Keep central standards, but push ownership to business domains.

Tool-first projects
Buying Purview, Collibra, Atlan, or another catalog does not define customer, margin, active user, or confidential data. Process and ownership come first.

Everything at once
Start with the datasets that matter most: customer data, product data, financial reporting, regulatory data, and operational KPIs. Give those owners, definitions, classifications, and basic quality rules. Expand from there.

Last Updated: July 7, 2026 Back to Dictionary
Keywords
data governance data steward data owner microsoft purview gdpr ai act data lineage data classification row-level security data quality