Data Governance
Data governance defines the policies, roles, and processes that ensure organizational data is accurate, consistent, secure, and used appropriately. It establishes ownership, quality standards, access rules, and lifecycle management across the data estate.
itData engineering and analytics | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Dont Panic: Data Governance
Data governance is the part of data work that decides who gets to settle an argument before the argument becomes three dashboards and a meeting with suspiciously firm opinions. It turns a wish for trustworthy data into decision rights, policy, controls, evidence, and accountability. That sounds like committee furniture. It is the wiring that lets several teams use the same data without each quietly inventing a different reality.
Start with the outcome, the business or mission result that makes an asset worth governing. A customer identifier, revenue figure, or product metric crosses producers, platforms, and consumers. Each local choice can be sensible and still collide with another one. Governance gives people a way to decide what a term means, which source is authoritative, and what evidence counts when an answer changes.
The cast is smaller than the vocabulary suggests. A data owner is accountable for a business decision in a defined scope. A data steward keeps definitions, metadata, quality expectations, and issue processes in working order. A technical custodian runs systems and applies approved controls. The crucial detail is authority. A role title without the ability to approve, reject, or escalate a decision is a label wearing a hat.
A catalog helps people discover an asset. Lineage, the record of where data came from and what depends on it, reveals the blast radius of a change. Quality controls test whether an asset meets an expectation for a stated use. Useful tools, all of them. None can decide whether a disputed metric definition is acceptable, which is the awkward bit that tools wisely decline to do.
The working loop is repetitive: choose an outcome, scope data and stakeholders, assign decision rights, define policy and a measurable expectation, apply controls in delivery work, then review the evidence. An exception needs an owner, expiry, and corrective action. Otherwise it is not an exception. It is a policy that escaped through a side door.
Do not govern every asset at once. Start where value, risk, or cross-team dependency makes indecision expensive. Intro explains the operating model and limits. Slides compress the roles and cycle into a map. Cheatsheet is the desk reference for decisions, asset records, and signals. Practice turns the loop into a small working exercise. That is enough equipment for a calm start.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://resources.data.gov/assets/documents/fds-data-governance-playbook.pdf
Supports
- Data governance sets and enforces priorities for managing and using data as a strategic asset
- A governance body establishes policies, procedures, roles, oversight, and resource priorities
- Governance activities include inventory, metadata, policy, issue management, assessment, oversight, and communication
- Governance roles need explicit responsibilities, authority, accountability, and review processes
- Governance begins with a vision tied to organizational goals and stakeholder needs
- Maturity assessments identify capability gaps and investment priorities
- Architecture guidance includes common data elements, metadata, and authoritative systems
- https://strategy.data.gov/principles/
Supports
- Responsible governance includes ethics, security, privacy, confidentiality, appropriate access, and transparency
- Data quality includes relevance, accuracy, objectivity, accessibility, usefulness, understandability, and timeliness
- Accountability includes assigned responsibility, audits, documentation, learning, and corrective change
- Data practices should consider reuse, interoperability, stakeholder feedback, and continuous learning
- https://strategy.data.gov/practices/
Supports
- Governance needs authority, roles, structures, policies, and resources
- Organizations should inventory assets with sufficient metadata for discovery and collaboration
- Documentation should cover quality, utility, and provenance and remain current
- Maturity, value, stakeholder needs, privacy, confidentiality, integrity, access, and preservation guide priorities
- https://www.nist.gov/privacy-framework/privacy-framework
Supports
- The NIST Privacy Framework is a voluntary tool for managing privacy risk through enterprise risk management
- Privacy risk belongs in organizational decisions about data processing and beneficial data use
- The framework is maintained as a living resource through stakeholder engagement
- https://learn.microsoft.com/en-us/purview/unified-catalog
Supports
- Federated governance combines centralized safety, quality, and standards with distributed ownership and maintenance
- Distributing ownership across business domains reduces central bottlenecks and supports participation
- Governance domains align data organization with business context and responsible self-service use
- https://www.w3.org/TR/vocab-dcat-3/
Supports
- A data catalog is a curated collection of metadata about resources
- DCAT provides a standard vocabulary for datasets and data services in catalogs
- Standard catalog metadata supports discovery, aggregation, and interoperability across catalogs
- https://www.w3.org/TR/prov-o/
Supports
- PROV-O represents and exchanges provenance information across systems and contexts
- Provenance can describe entities, activities, agents, generation, derivation, and attribution
- A common provenance model supports traceability across application domains
- https://dama.org/learning-resources/dama-data-management-body-of-knowledge-dmbok/
Supports
- DAMA-DMBOK is a broad framework for data management principles, practices, and functions
- The framework includes governance, ethics, integration, interoperability, and emerging technologies
- The body of knowledge provides a wider professional map beyond a single governance course
- https://www.w3.org/TR/2013/REC-prov-o-20130430/
Supports
- PROV-O became a W3C Recommendation on 30 April 2013
- https://www.w3.org/TR/vocab-dcat-3/
Supports
- DCAT was standardized in 2014, DCAT 2 in 2020, and DCAT 3 in 2024
- https://eur-lex.europa.eu/eli/reg/2016/679?exec=1ba4110&irpid=irpid
Supports
- Regulation EU 2016/679 was adopted in 2016 and applies from 25 May 2018
- https://strategy.data.gov/action-plan/
Supports
- The Federal Data Strategy required a Data Governance Body by September 2019 and published its 2020 Action Plan
- https://www.nist.gov/privacy-framework/privacy-framework
Supports
- NIST Privacy Framework version 1.0 was released in January 2020
- https://www.microsoft.com/insidetrack/blog/powering-data-governance-at-microsoft-with-purview-unified-catalog/
Supports
- Microsoft reported that adoption was easier when teams focused on data value rather than compliance framing
- https://www.collibra.com/
Supports
- Collibra provides governance capabilities
- https://www.alation.com/
Supports
- Alation provides a data intelligence platform for catalog and governance work
- https://atlan.com/
Supports
- Atlan provides an active metadata platform for data discovery and governance workflows
- https://www.informatica.com/products/data-governance.html
Supports
- Informatica provides data governance capabilities
- https://www.microsoft.com/en-us/security/business/governance-risk-compliance/microsoft-purview
Supports
- Microsoft Purview provides data governance and compliance capabilities
- https://www.ibm.com/products/watsonx-governance/knowledge-catalog
Supports
- IBM Knowledge Catalog provides catalog and governance capabilities
- https://data.world/
Supports
- data.world provides a data catalog and governance platform
