Governance, Ethics & Risk
Data governance
The allocation of authority, accountability, rules and controls governing how data are created, accessed, changed, shared, retained and deleted across their lifecycle.
Expert review openNo editor-accepted expert review yetDefinition
The allocation of authority, accountability, rules and controls governing how data are created, accessed, changed, shared, retained and deleted across their lifecycle.
Overview
“Data becomes governable when someone can answer who may decide, who must act and who is accountable. ”
Data governance is often introduced when an organisation has too much data and too little confidence. Duplicate farmers, conflicting indicators, unowned spreadsheets and unclear permissions create pressure for a committee or policy. Yet governance is not the meeting where data problems are discussed. It is the system of decision rights and accountability that determines how those problems are prevented and resolved.
The OECD describes data governance as the technical, policy and regulatory frameworks used to manage data across their value cycle, from creation to deletion. The definition is broad because data move through many hands. A farmer provides information, an enumerator records it, a platform stores it, an analyst transforms it, a client uses it and a regulator or researcher may request access.
Each stage creates choices and responsibility. Governance differs from data management.
Management performs the work: collecting, validating, storing, integrating and archiving. Governance establishes who has authority to set definitions, approve access, accept risk, resolve conflict and hold performance to account. A data steward may maintain the quality of farm records, but governance decides which organisation is allowed to change a boundary and which evidence is needed.
Ownership language can mislead. Personal data are not owned in the same way as equipment, and several parties may hold rights or duties over the same dataset. A buyer may fund collection, a cooperative may control operational access, farmers may have data-protection rights and a government may impose reporting obligations. Governance should specify roles and lawful authority rather than rely on the phrase our data.
Definitions are a core governance decision.
If one programme defines active farmer as anyone registered and another requires delivery in the last twelve months, aggregate counts cannot be compared. A data dictionary should identify meaning, unit, source, owner, permitted values and effective date. Changes need approval and versioning because a revised definition can alter performance without any change in reality. Access also needs purpose.
Broad internal availability may feel efficient and expose people to unnecessary risk. Role-based rules should determine who can view names, precise locations, household income, grievance records or commercial terms. Access logs, periodic review and removal when roles change convert policy into control.
Quality incidents test accountability. A duplicate identifier may inflate the number of farmers reached and the volume attributed to a programme. Who investigates, corrects historical reports, informs users and prevents recurrence? If every team can edit the record and no one owns the consequence, the organisation has data activity without governance. Sharing across organisations adds power questions.
Producers may supply detailed data because market access depends on it, while downstream firms capture most of the analytical value. Governance should address benefit, burden, purpose, retention and onward sharing, not only legal permission. Trust can be damaged when information collected for support is later used for exclusion or pricing without clear explanation. Deletion is equally governed.
Systems often keep data because storage is cheap and future use is uncertain.
Retention creates cost, security risk and possible incompatibility with original purpose. Governance should define retention periods, legal holds, archival value and verifiable deletion across backups and partners.
Metrics can strengthen governance if they measure real control: unresolved data issues, unauthorised access, overdue retention actions, duplicate rates, time to correct and percentage of critical fields with accountable stewards. Counting policies or committee meetings measures activity rather than governed performance. The discipline is to locate every material data decision.
Who defines the field, approves collection, controls access, corrects error, authorises sharing, accepts residual risk and decides deletion? If those answers depend on personal relationships rather than explicit authority, the data system remains fragile.
Practical application
Create a governance map covering data owners, stewards, controllers, processors, custodians and users. Define critical datasets, decision rights, dictionaries, quality rules, access, sharing, retention, incident response and change control. Escalate unresolved conflicts to a body with genuine authority. Include producers, workers or communities where governance decisions affect their rights and interests.
Monitor control performance and publish responsibilities internally. Review governance when new purposes, partners, technologies or regulations change the risk.
Why it matters
Sustainability decisions increasingly depend on data collected across unequal relationships and multiple systems. Governance makes responsibility visible, protects rights and allows errors to be corrected before they become claims, exclusions or regulatory failures.
Common misconception
Data governance is often treated as data management, security or a committee. Those are components. Governance determines who has authority and accountability for decisions across the data lifecycle.
Connections
Interoperability moves data across organisational boundaries. Data Minimisation and Consent constrain collection and use. Data Quality measures fitness for purpose, while Privacy by Design embeds governance decisions into systems and defaults.
A question worth asking
When a disputed data point changes a farmer's eligibility, a public claim or a risk rating, who has the authority to decide - and who is accountable if that decision is wrong?
Selected references
OECD. 2022. Going Digital Guide to Data Governance Policy Making. OECD. Data Governance Topic Framework. ISO/IEC 38505-1:2017. Governance of IT - Governance of Data - Part 1: Application of ISO/IEC 38500 to the Governance of Data. Khatri, V. and Brown, C. V. 2010. Designing Data Governance. Communications of the ACM 53(1): 148-152. United Nations Economic Commission for Europe. 2023.
Data Stewardship and the Role of National Statistical Offices in the New Data Ecosystem.
Review
Public comments appear only after editor acceptance. Draft comments stay in the review queue.
Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.
Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.
Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.
Submitted reviews stay private until accepted.
Loading verified endorsements… Endorsements are not votes and never determine publication.
Endorse this definition
Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.
Review board
Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.
Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.
AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.
An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.