Data governance & data protection

Data
governance and
data protection.

Establishing clear accountability for your most critical data and demonstrable compliance with your GDPR obligations, so that quality problems have named owners, regulatory risk has a named owner and AI or analytics investments can actually deliver what they promise.

The right conversation to have

Governance is an organisational discipline. Protection is a legal obligation.

When data governance and data protection are designed together, the benefits compound quickly. Named ownership means data disputes get resolved at the point they arise, not escalated to the board. A record of processing activities that is actually current turns a subject access request from a scramble into a formality. Quality problems get fixed at the source, so they stop reappearing in every downstream report.

Reaching that position depends on answering two questions clearly: who is accountable for the day-to-day quality and use of your most critical data, and who is accountable for demonstrating that its use meets your legal obligations. Both answers rely on the same foundation — named owners, a shared domain model, and a governance forum that makes decisions rather than just receiving updates.

The two disciplines are more durable - and more credible internally -when they share that foundation from the outset rather than being designed separately. A framework that only covers governance leaves an organisation unable to answer a subject access request or a breach within 72 hours. A GDPR programme run in isolation tends to produce a record of processing activities that nobody keeps current once the project ends.

The conversation that matters is about accountability and decision rights — who owns the accuracy of your most critical data and who owns demonstrating compliance when it is tested. Technology is an enabler of that accountability: It is not a substitute for it.

A Medasi engagement lands governance and data protection as a single business capability, owned at executive level, with a practical framework that an organisation of your scale can realistically implement and sustain.

How we frame the conversation

Not this …

But this …

We need a data governance programme

You need clear accountability for your most critical data so you can stop burning resource on rework.

Your data maturity is low.

Two senior people can give the board different numbers for the same metric. That is the problem we are solving.

We need to comply with GDPR

If a subject access request or a personal data breach lands tomorrow, you will know exactly what happens in the next 72 hours, and who owns it.

We will implement a framework.

In 90 days, you will have named owners for your ten most critical datasets and a DPO or equivalent in place.

The framework

Six components.
Data protection woven throughout.

Most organisations at this scale do not need a complex governance architecture. They need clear answers to four questions for their ten to twenty most critical datasets — who owns it, how are quality problems resolved, who defines what the data means and could you demonstrate to a regulator that its use is lawful. Each of the six components below answers one part of that, with data protection built in rather than treated as a separate track.

Data domains

Logical groupings of data that form the boundaries of ownership. These same domains define the scope of the record of processing activities, so governance and GDPR documentation stay aligned by design.

Ownership model

Named domain owners and stewards. Each owner is accountable for GDPR compliance within their domain, working alongside the DPO rather than in place of them.

Data policies

Rules governing how data is created, used, changed and retired. Retention and lawful basis rules are set here, not in a separate compliance document.

Data standards and business glossary

Agreed definitions and business rules for critical data elements. Glossary entries flag which elements are personal data, so protection obligations are visible at the point of use.

Data quality framework

The six dimensions used to assess and report quality. Accuracy and timeliness extend to the personal data used to respond to subject access requests, not only to business reporting.

Governance processes

How issues are triaged and disputes resolved. DPIA triggers, breach escalation and subject access request triage sit within the same processes as data quality disputes, not a parallel set.

the 90-day approach

Risk reduction before speed.
Foundations before features.

The 90-day horizon is the primary planning unit. Organisations at this scale lose focus on multi-year plans. We sequence by what reduces risk first, not what is easiest to deliver first.

Days 1-30

Establish foundations

Build the structural conditions for governance to take hold — including the executive conversations that determine whether it will survive.

  • Domain model agreed with senior leadership

  • Domain owners and stewards nominated

  • Governance lead identified

  • DPO or equivalent identified

  • Record of processing activities gap analysis complete

  • Priority datasets scoped for quality analysis

  • Framework documentation in client hands

Days 31-60

Build and activate

The framework goes live. The governance council meets. Data protection processes start operating rather than existing only on paper.

  • First governance council meeting held

  • Quality scorecards live for priority domains

  • Business glossary — first entries agreed

  • Record of processing activities first draft complete

  • Data subject rights triage process in place

  • Two to three quick wins identified and underway

Days 61-90

Stabilise and hand over

The programme transitions from consultant-led to client-led. Handover is planned from day one, not added at the end.

  • Council operating without consultant facilitation

  • Record of processing activities reviewed by the DPO

  • Breach response process documented and briefed

  • Quick wins delivered and reported to sponsor

  • Executive sponsor quarterly review held

  • Maintenance regime in place and owned

The ownership model

Named accountability at every level.
No committees without owners.

Executive level

Executive sponsor

Typically the CFO, COO or Chief Digital Officer. Provides the mandate and authority for the programme. Makes final decisions on unresolved cross-domain disputes. Chairs the quarterly governance review.

Programme level

Data governance lead

The day-to-day owner of the governance programme. Maintains the framework, facilitates the council, tracks remediation and manages the business glossary. A relationship management and organisational role — not a technical data role.

Programme level

Data governance lead

The day-to-day owner of the governance programme. Maintains the framework, facilitates the council, tracks remediation and manages the business glossary. A relationship management and organisational role — not a technical data role.

Statuory role

Data Protection Office

A role required under UK GDPR for some organisations and a strong governance investment for the rest. Reports to the highest level of management, monitors compliance, advises on data protection impact assessments and is the contact point for the ICO and for data subjects.

Domain level

Data domain owner

A senior leader (director or above) accountable for the quality, availability and appropriate use of data within a defined domain. One owner per domain. Makes final calls on intra-domain disputes and represents the domain in the governance council.

Domain level

Data domain owner

A senior leader (director or above) accountable for the quality, availability and appropriate use of data within a defined domain. One owner per domain. Makes final calls on intra-domain disputes and represents the domain in the governance council.

Operational level

Data steward

An operational manager or senior analyst responsible for day-to-day governance within the domain — monitoring quality, triaging issues, maintaining glossary entries and enforcing standards. The first escalation point for quality disputes.

The governance lead and the DPO work in partnership, not competition. The governance lead builds and runs the infrastructure. The DPO uses it to demonstrate statutory compliance — and must remain free to raise concerns independently of the programme.

Governance forum

Data governance council

The cross-functional forum where domain owners convene to make shared decisions, not to receive status updates. Typically meets monthly. Agenda items include cross-domain quality issues, definition disputes, policy updates and data protection matters such as DPIA sign-off. The governance lead chairs; the DPO and executive sponsor attend as required.

Data quality analysis

Six dimensions.
Assessed against your most critical datasets.

Before designing the framework, we establish an evidence-based picture of where quality fails, why it fails and what the business consequence is. Where a domain contains personal data, the same analysis identifies the compliance consequence too, including its bearing on subject access requests and lawful basis.

Completeness

The degree to which required fields are populated across records in the dataset.

Mandatory fields blank; records created with placeholder or default values to satisfy system requirements.

Accuracy

The degree to which data correctly describes the real-world entity it represents.

Contact details out of date; financial figures that do not reconcile across systems or to source.

Consistency

The degree to which data is the same across systems, reports and representations.

Different values for the same metric appearing in different reports — the most common cause of MI disputes.

Timeliness

The degree to which data is available when needed and reflects current reality.

Reports based on data days or weeks old; batch refresh failures; records that are technically populated but practically stale.

Validity

The degree to which data conforms to defined formats, types and business rules.

Free text in structured fields; invalid codes, reference values or formats that bypass system validation.

Uniqueness

The degree to which each entity appears exactly once within the dataset.

Duplicate customer, product or supplier records that create downstream errors in reporting, billing and service.

What you get

Board-ready outputs at every stage of the engagement.

Board-level one-pager

A standalone summary of governance and data protection position, a traffic-light view of maturity, the top three risks of inaction — operational, regulatory and strategic — and a clear recommendation, designed to be read independently of any supporting document.

Board-level one-pager

A standalone summary of governance and data protection position, a traffic-light view of maturity, the top three risks of inaction — operational, regulatory and strategic — and a clear recommendation, designed to be read independently of any supporting document.

Maturity scorecard

A traffic-light assessment scored against evidence, not aspiration, covering the governance framework and the data protection programme — including record of processing currency, breach readiness and DPO effectiveness. Updated at each major milestone.

Maturity scorecard

A traffic-light assessment scored against evidence, not aspiration, covering the governance framework and the data protection programme — including record of processing currency, breach readiness and DPO effectiveness. Updated at each major milestone.

Data protection assessment

A standalone GDPR compliance review — record of processing accuracy, lawful basis mapping, data subject rights capability, data protection impact assessment obligations and breach response readiness — for engagements where data protection is the primary scope.

Data protection assessment

A standalone GDPR compliance review — record of processing accuracy, lawful basis mapping, data subject rights capability, data protection impact assessment obligations and breach response readiness — for engagements where data protection is the primary scope.

Data quality report

A structured assessment of priority datasets across all six quality dimensions, including the compliance dimension where personal data is involved, with root cause analysis, business impact ratings and a prioritised remediation list.

Data quality report

A structured assessment of priority datasets across all six quality dimensions, including the compliance dimension where personal data is involved, with root cause analysis, business impact ratings and a prioritised remediation list.

Governance and data protection framework

The fully designed operating model — domain model, ownership structure, policies, business glossary, quality framework and governance processes — with role profiles for every accountability, including DPO positioning.

Governance and data protection framework

The fully designed operating model — domain model, ownership structure, policies, business glossary, quality framework and governance processes — with role profiles for every accountability, including DPO positioning.

90-day roadmap

A sequenced, phased delivery plan across the three horizons — sequenced by governance and data protection risk reduction together, with named owners, realistic milestones and clear handover criteria for each phase.

90-day roadmap

A sequenced, phased delivery plan across the three horizons — sequenced by governance and data protection risk reduction together, with named owners, realistic milestones and clear handover criteria for each phase.

Maintenance regime

The recurring activities, cadences and ownership needed to keep the framework current after delivery — the quality scorecard, remediation backlog, record of processing maintenance triggers, governance council rhythm and annual maturity and DPO review.ring activities, cadences and ownership needed to keep the framework current after delivery — including the quality scorecard, remediation backlog, governance council rhythm and annual maturity review.

Who this is for

Leaders whose decisions — and compliance position — depend on data they cannot trust.

Data governance and data protection engagements are most valuable when data quality is visibly hurting the business, when a regulatory trigger has made compliance urgent, or when significant capital is about to be committed to data or AI platforms that governance and protection failures would put at risk.

Chief Financial Officer

Motivated by financial accuracy and eliminating MI conflict at board level

Chief Operating Officer

Dealing with operational rework and reconciliation caused by data quality failures

Chief Digital or Technology Officer

Whose AI or analytics initiatives are stalled or underperforming due to data quality

General Counsel or Chief Compliance Officer

Motivated by regulatory exposure and the cost of ICO enforcement; a strong co-sponsor for GDPR-led engagements

Chief Executive Officer

Whose strategic decisions are being undermined by data they cannot rely on

When organisations engage us

MI conflict at board or ExCo level

Two senior people can give the board different numbers for the same metric, and nobody knows which is correct or who is accountable for resolving it.

AI or analytics investment stalled

A digital or AI initiative is underperforming and the team cites data quality as the primary cause. The programme is sound; the foundations are not.

Following a regulatory inquiry, ICO investigation or data breach

Data protection has become the immediate priority. We lead with the compliance response and build the governance structure around it, so the fix outlasts the immediate pressure.

Regulatory or audit pressure

Audit findings or regulatory requirements demand traceable accountability for data accuracy and demonstrable GDPR compliance, and the organisation does not currently have the structures to provide it.

Pre-platform investment

A significant investment in data infrastructure, a data warehouse or an AI platform is being considered and governance and data protection are the prerequisites that need to be established first.

Start with clarity

Determine who is accountable for your data — and what to do when it's wrong.

Determine who is accountable for your data — and whether you could prove compliance today.

A conversation about your data quality challenges and what a governance engagement would realistically involve for an organisation of your scale.

A conversation about your data governance and data protection position, and what an engagement would realistically involve for an organisation of your scale.