Compliance

Data governance

Data governance is the overall framework of policies, roles, processes, and standards an organisation uses to manage its data as an asset throughout its lifecycle, covering how data is classified, who owns and is accountable for it, how it is protected, how long it is kept, who can access it, and how its quality and consistency are maintained.

Why Data governance matters in a Microsoft estate

Data governance matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.

How Data governance shows up in practice

The aim is making data trustworthy, compliant, and genuinely useful rather than simply accumulated. Effective data governance typically assigns clear roles, such as data owners accountable for a specific data domain's classification and access decisions, data stewards responsible for day-to-day quality and policy application, and a governance body or forum that resolves conflicts and approves policy changes. Governance that exists only as a written policy with no assigned accountability tends to decay quickly as the underlying data estate grows and changes. In a Microsoft 365 and Azure estate, data governance is where policy meets platform capability: Microsoft Purview provides the practical enforcement layer through its data map and catalogue for discovering and classifying data across Microsoft 365, Azure, and connected third-party sources, sensitivity labels for classification and protection, retention labels for lifecycle and disposition, and DLP policies for controlling how classified data can move.

But none of that tooling constitutes governance on its own without an organisation first deciding, documenting, and maintaining the classification taxonomy, ownership assignments, and retention schedule those tools are configured to enforce. A frequent and costly gap is treating data governance as purely a compliance exercise driven by regulation, such as UK GDPR, rather than an operational one: poor governance shows up in practice as duplicated and inconsistent SharePoint sites and Teams with no clear owner, sensitive data with looser access than intended because sharing links were never reviewed, orphaned data left behind by leavers whose accounts were deactivated but whose OneDrive and mailbox content was never reassigned or disposed of, and licence or storage costs that grow because nobody is accountable for cleaning up data that no longer needs to be retained.

Data governance also underpins most external compliance obligations relevant to Microsoft-estate operators, since ISO/IEC 27001's asset management and access control clauses, UK GDPR's data minimisation and storage limitation principles, and SOC 2's confidentiality and privacy criteria are all, in practice, testing whether an organisation's data governance framework exists, is followed, and produces verifiable evidence. That is why governance maturity is often one of the first things assessed, directly or indirectly, in a compliance readiness review.

Related terms

Glossary