Chapter 06 · Governance & regulationGovernance, Ethics & Risk

Data governance

Meaning statusEstablishedSource recordDirect document linkedWhy these are different

Definition

The allocation of authority, accountability, rules and controls governing how data are created, accessed, changed, shared, retained and deleted across their lifecycle.

References

European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)

This reference provides supporting context for how “Data governance” is defined and used.

Overview

“Data becomes governable when someone can answer who may decide, who must act and who is accountable. ”

Data governance is often introduced when an organisation has too much data and too little confidence. Duplicate farmers, conflicting indicators, unowned spreadsheets and unclear permissions create pressure for a committee or policy. Yet governance is not the meeting where data problems are discussed. It is the system of decision rights and accountability that determines how those problems are prevented and resolved.

The OECD describes data governance as the technical, policy and regulatory frameworks used to manage data across their value cycle, from creation to deletion. The definition is broad because data move through many hands. A farmer provides information, an enumerator records it, a platform stores it, an analyst transforms it, a client uses it and a regulator or researcher may request access.

Each stage creates choices and responsibility. Governance differs from data management.

Management performs the work: collecting, validating, storing, integrating and archiving. Governance establishes who has authority to set definitions, approve access, accept risk, resolve conflict and hold performance to account. A data steward may maintain the quality of farm records, but governance decides which organisation is allowed to change a boundary and which evidence is needed.

Ownership language can mislead. Personal data are not owned in the same way as equipment, and several parties may hold rights or duties over the same dataset. A buyer may fund collection, a cooperative may control operational access, farmers may have data-protection rights and a government may impose reporting obligations. Governance should specify roles and lawful authority rather than rely on the phrase our data.

Definitions are a core governance decision.

If one programme defines active farmer as anyone registered and another requires delivery in the last twelve months, aggregate counts cannot be compared. A data dictionary should identify meaning, unit, source, owner, permitted values and effective date. Changes need approval and versioning because a revised definition can alter performance without any change in reality. Access also needs purpose.

Broad internal availability may feel efficient and expose people to unnecessary risk. Role-based rules should determine who can view names, precise locations, household income, grievance records or commercial terms. Access logs, periodic review and removal when roles change convert policy into control.

Quality incidents test accountability. A duplicate identifier may inflate the number of farmers reached and the volume attributed to a programme. Who investigates, corrects historical reports, informs users and prevents recurrence? If every team can edit the record and no one owns the consequence, the organisation has data activity without governance. Sharing across organisations adds power questions.

Producers may supply detailed data because market access depends on it, while downstream firms capture most of the analytical value. Governance should address benefit, burden, purpose, retention and onward sharing, not only legal permission. Trust can be damaged when information collected for support is later used for exclusion or pricing without clear explanation. Deletion is equally governed.

Systems often keep data because storage is cheap and future use is uncertain.

Retention creates cost, security risk and possible incompatibility with original purpose. Governance should define retention periods, legal holds, archival value and verifiable deletion across backups and partners.

Metrics can strengthen governance if they measure real control: unresolved data issues, unauthorised access, overdue retention actions, duplicate rates, time to correct and percentage of critical fields with accountable stewards. Counting policies or committee meetings measures activity rather than governed performance. The discipline is to locate every material data decision.

Who defines the field, approves collection, controls access, corrects error, authorises sharing, accepts residual risk and decides deletion? If those answers depend on personal relationships rather than explicit authority, the data system remains fragile.

Practical application

Create a governance map covering data owners, stewards, controllers, processors, custodians and users. Define critical datasets, decision rights, dictionaries, quality rules, access, sharing, retention, incident response and change control. Escalate unresolved conflicts to a body with genuine authority. Include producers, workers or communities where governance decisions affect their rights and interests.

Monitor control performance and publish responsibilities internally. Review governance when new purposes, partners, technologies or regulations change the risk.

Why it matters

Sustainability decisions increasingly depend on data collected across unequal relationships and multiple systems. Governance makes responsibility visible, protects rights and allows errors to be corrected before they become claims, exclusions or regulatory failures.

Common misconception

Data governance is often treated as data management, security or a committee. Those are components. Governance determines who has authority and accountability for decisions across the data lifecycle.

Connections

Interoperability moves data across organisational boundaries. Data Minimisation and Consent constrain collection and use. Data Quality measures fitness for purpose, while Privacy by Design embeds governance decisions into systems and defaults.

A question worth asking

When a disputed data point changes a farmer's eligibility, a public claim or a risk rating, who has the authority to decide - and who is accountable if that decision is wrong?

Selected references

OECD. 2022. Going Digital Guide to Data Governance Policy Making. OECD. Data Governance Topic Framework. ISO/IEC 38505-1:2017. Governance of IT - Governance of Data - Part 1: Application of ISO/IEC 38500 to the Governance of Data. Khatri, V. and Brown, C. V. 2010. Designing Data Governance. Communications of the ACM 53(1): 148-152. United Nations Economic Commission for Europe. 2023.

Data Stewardship and the Role of National Statistical Offices in the New Data Ecosystem.

How it is used

Policymakers, regulators, legal teams, boards and organisations use “Data governance” in legislation, policies, governance systems, contracts, oversight and compliance decisions. In each case, the user should state the applicable jurisdiction, legal or policy text, effective date, scope and responsible actor; otherwise, the same term may be applied to materially different situations.

In this context, it refers to created, accessed, changed, shared, retained and deleted across their lifecycle.

Have evidence, context, or a correction to share? Every suggestion is considered by an editor before publication.

Meaning status
Established
Last verification recorded
22 Aug 2026
Last updated
22 Aug 2026
What the classifications mean

Meaning status: Established

EstablishedCurrentMultiple definitionsContestedEmergingIndexed