# What is Data Governance?

> Data governance is the system by which an organization directs, controls, and holds people accountable for decisions about data and its use.

- Canonical URL: https://yellowcube.eu/glossary/data-governance/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It establishes decision rights, roles, policies, standards, oversight, and escalation across the data lifecycle. Its scope commonly includes purpose, ownership, access, quality, metadata, lineage, sharing, retention, protection, acceptable use, and disposal — not only security or regulatory compliance.

Governance should connect organizational objectives and stakeholder interests to operational data management. Governing bodies and accountable leaders set direction and constraints; owners, stewards, custodians, product teams, and control functions implement and verify them through defined responsibilities.

### Key points

- **Decision authority:** Specify who may approve collection, definitions, access, sharing, changes, retention, exceptions, and risk acceptance, and who resolves conflicts between legitimate interests.
- **Common rules:** Maintain usable policies, data definitions, quality criteria, metadata, classification, provenance, and control requirements that follow data across systems and third parties.
- **Lifecycle oversight:** Inventory important data and flows, monitor adherence and outcomes, record decisions, manage exceptions, and revise rules when purposes, technology, risks, or obligations change.
- **Important limitation:** A governance council, catalog, policy library, or stewardship title does not prove that data is accurate, secure, lawful, or well managed. Governance must produce implemented decisions, evidence, accountability, and corrective action.

### Related terms

[Data security](<https://yellowcube.eu/glossary/data-security/>) · [Data protection](<https://yellowcube.eu/glossary/data-protection/>) · [Data privacy](<https://yellowcube.eu/glossary/data-privacy/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [Data integrity](<https://yellowcube.eu/glossary/data-integrity/>) · [Data retention](<https://yellowcube.eu/glossary/data-retention/>) · [Shadow IT](<https://yellowcube.eu/glossary/shadow-it/>)

### Sources

[ISO/IEC 38505-1:2017 Governance of Data](https://www.iso.org/standard/56639.html) · [US Federal Data Strategy Practices](https://strategy.data.gov/practices/) · [NIST SP 1500-18 Rev. 2: Research Data Framework](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/1500-18/NIST.SP.1500-18r2.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

