Data Governance: Corporate Management vs. Global Policy
Data governance operates at two scales: managing data within a company and setting data policy between nations. It applies to corporate data management and international internet governance.
WHY IT EXISTS Organizations generate data faster than they can trust it, and nations move data across borders faster than law can agree on who owns it. Data governance exists to answer the same underlying question, who is allowed to do what with this data, at two very different scales: inside a single company, and between countries. Without an explicit answer at either scale, data quality erodes internally and legal risk accumulates externally.
THE MENTAL MODEL Picture two rings. The inner ring is a company deciding who can read, write, or export its customer records, which is data management with teeth: ownership, quality, access. The outer ring is a set of nations deciding whether a company can move that data across a border in the first place. Corporate data governance operates entirely inside the outer ring's rules, so a policy that is airtight internally can still be illegal externally.
HOW IT WORKS At the corporate level, governance runs through data stewardship: named owners for each dataset, quality rules, access control tied to roles, and lineage tracking so a downstream error can be traced to its source. Frameworks such as DAMA-DMBOK formalize this into pillars covering security, quality, and metadata. At the international level, governance takes the form of law and treaty: rules restricting transfer of personal data outside a region, adequacy decisions between jurisdictions, and data localization laws requiring certain data to physically stay within a country's borders.
WHEN IT MATTERS The two scales collide the moment a company operates across borders. Get the corporate layer wrong and a marketing team joins two datasets it should never have combined. Get the macro layer wrong and a routine database replication to a cheaper region becomes a regulatory violation. The footgun is treating governance as purely an internal policy question and discovering the cross-border rules only after the data has already moved.
ONE CONCRETE EXAMPLE A SaaS company headquartered in the United States stores its European customer data in a Frankfurt data center to satisfy regional data residency requirements, while internally a data steward restricts that same dataset so only the EU support team, not global sales, can query it. Both layers of governance are enforced at once, by entirely different mechanisms.
Read the original → en.wikipedia.org
Get five bites like this every day.
Tezvyn delivers a daily feed of 60-second tech bites with quizzes to lock in what you learn.