Services /
Data governance & data protection
Data
governance and
data protection.
Establishing clear accountability for your most critical data and demonstrable compliance with your GDPR obligations, so that quality problems have named owners, regulatory risk has a named owner and AI or analytics investments can actually deliver what they promise.
The right conversation to have
Governance is an organisational discipline. Protection is a legal obligation.
When data governance and data protection are designed together, the benefits compound quickly. Named ownership means data disputes get resolved at the point they arise, not escalated to the board. A record of processing activities that is actually current turns a subject access request from a scramble into a formality. Quality problems get fixed at the source, so they stop reappearing in every downstream report.
Reaching that position depends on answering two questions clearly: who is accountable for the day-to-day quality and use of your most critical data, and who is accountable for demonstrating that its use meets your legal obligations. Both answers rely on the same foundation — named owners, a shared domain model, and a governance forum that makes decisions rather than just receiving updates.
The two disciplines are more durable - and more credible internally -when they share that foundation from the outset rather than being designed separately. A framework that only covers governance leaves an organisation unable to answer a subject access request or a breach within 72 hours. A GDPR programme run in isolation tends to produce a record of processing activities that nobody keeps current once the project ends.
The conversation that matters is about accountability and decision rights — who owns the accuracy of your most critical data and who owns demonstrating compliance when it is tested. Technology is an enabler of that accountability: It is not a substitute for it.
A Medasi engagement lands governance and data protection as a single business capability, owned at executive level, with a practical framework that an organisation of your scale can realistically implement and sustain.
How we frame the conversation
Not this …
But this …
We need a data governance programme
You need clear accountability for your most critical data so you can stop burning resource on rework.
Your data maturity is low.
Two senior people can give the board different numbers for the same metric. That is the problem we are solving.
We need to comply with GDPR
If a subject access request or a personal data breach lands tomorrow, you will know exactly what happens in the next 72 hours, and who owns it.
We will implement a framework.
In 90 days, you will have named owners for your ten most critical datasets and a DPO or equivalent in place.
The framework
Six components.
Data protection woven throughout.
Most organisations at this scale do not need a complex governance architecture. They need clear answers to four questions for their ten to twenty most critical datasets — who owns it, how are quality problems resolved, who defines what the data means and could you demonstrate to a regulator that its use is lawful. Each of the six components below answers one part of that, with data protection built in rather than treated as a separate track.
Data domains
Logical groupings of data that form the boundaries of ownership. These same domains define the scope of the record of processing activities, so governance and GDPR documentation stay aligned by design.
Ownership model
Named domain owners and stewards. Each owner is accountable for GDPR compliance within their domain, working alongside the DPO rather than in place of them.
Data policies
Rules governing how data is created, used, changed and retired. Retention and lawful basis rules are set here, not in a separate compliance document.
Data standards and business glossary
Agreed definitions and business rules for critical data elements. Glossary entries flag which elements are personal data, so protection obligations are visible at the point of use.
Data quality framework
The six dimensions used to assess and report quality. Accuracy and timeliness extend to the personal data used to respond to subject access requests, not only to business reporting.
Governance processes
How issues are triaged and disputes resolved. DPIA triggers, breach escalation and subject access request triage sit within the same processes as data quality disputes, not a parallel set.
the 90-day approach
Risk reduction before speed.
Foundations before features.
The 90-day horizon is the primary planning unit. Organisations at this scale lose focus on multi-year plans. We sequence by what reduces risk first, not what is easiest to deliver first.
Days 1-30
Establish foundations
Build the structural conditions for governance to take hold — including the executive conversations that determine whether it will survive.
Domain model agreed with senior leadership
Domain owners and stewards nominated
Governance lead identified
DPO or equivalent identified
Record of processing activities gap analysis complete
Priority datasets scoped for quality analysis
Framework documentation in client hands
Days 31-60
Build and activate
The framework goes live. The governance council meets. Data protection processes start operating rather than existing only on paper.
First governance council meeting held
Quality scorecards live for priority domains
Business glossary — first entries agreed
Record of processing activities first draft complete
Data subject rights triage process in place
Two to three quick wins identified and underway
Days 61-90
Stabilise and hand over
The programme transitions from consultant-led to client-led. Handover is planned from day one, not added at the end.
Council operating without consultant facilitation
Record of processing activities reviewed by the DPO
Breach response process documented and briefed
Quick wins delivered and reported to sponsor
Executive sponsor quarterly review held
Maintenance regime in place and owned
The ownership model
Named accountability at every level.
No committees without owners.
Executive level
Executive sponsor
Typically the CFO, COO or Chief Digital Officer. Provides the mandate and authority for the programme. Makes final decisions on unresolved cross-domain disputes. Chairs the quarterly governance review.
Statuory role
Data Protection Office
A role required under UK GDPR for some organisations and a strong governance investment for the rest. Reports to the highest level of management, monitors compliance, advises on data protection impact assessments and is the contact point for the ICO and for data subjects.
Operational level
Data steward
An operational manager or senior analyst responsible for day-to-day governance within the domain — monitoring quality, triaging issues, maintaining glossary entries and enforcing standards. The first escalation point for quality disputes.
The governance lead and the DPO work in partnership, not competition. The governance lead builds and runs the infrastructure. The DPO uses it to demonstrate statutory compliance — and must remain free to raise concerns independently of the programme.
Governance forum
Data governance council
The cross-functional forum where domain owners convene to make shared decisions, not to receive status updates. Typically meets monthly. Agenda items include cross-domain quality issues, definition disputes, policy updates and data protection matters such as DPIA sign-off. The governance lead chairs; the DPO and executive sponsor attend as required.
Data quality analysis
Six dimensions.
Assessed against your most critical datasets.
Before designing the framework, we establish an evidence-based picture of where quality fails, why it fails and what the business consequence is. Where a domain contains personal data, the same analysis identifies the compliance consequence too, including its bearing on subject access requests and lawful basis.
Completeness
The degree to which required fields are populated across records in the dataset.
Mandatory fields blank; records created with placeholder or default values to satisfy system requirements.
Accuracy
The degree to which data correctly describes the real-world entity it represents.
Contact details out of date; financial figures that do not reconcile across systems or to source.
Consistency
The degree to which data is the same across systems, reports and representations.
Different values for the same metric appearing in different reports — the most common cause of MI disputes.
Timeliness
The degree to which data is available when needed and reflects current reality.
Reports based on data days or weeks old; batch refresh failures; records that are technically populated but practically stale.
Validity
The degree to which data conforms to defined formats, types and business rules.
Free text in structured fields; invalid codes, reference values or formats that bypass system validation.
Uniqueness
The degree to which each entity appears exactly once within the dataset.
Duplicate customer, product or supplier records that create downstream errors in reporting, billing and service.
What you get
Board-ready outputs at every stage of the engagement.
Maintenance regime
The recurring activities, cadences and ownership needed to keep the framework current after delivery — the quality scorecard, remediation backlog, record of processing maintenance triggers, governance council rhythm and annual maturity and DPO review.ring activities, cadences and ownership needed to keep the framework current after delivery — including the quality scorecard, remediation backlog, governance council rhythm and annual maturity review.
Who this is for
Leaders whose decisions — and compliance position — depend on data they cannot trust.
Data governance and data protection engagements are most valuable when data quality is visibly hurting the business, when a regulatory trigger has made compliance urgent, or when significant capital is about to be committed to data or AI platforms that governance and protection failures would put at risk.
Chief Financial Officer
Motivated by financial accuracy and eliminating MI conflict at board level
Chief Operating Officer
Dealing with operational rework and reconciliation caused by data quality failures
Chief Digital or Technology Officer
Whose AI or analytics initiatives are stalled or underperforming due to data quality
General Counsel or Chief Compliance Officer
Motivated by regulatory exposure and the cost of ICO enforcement; a strong co-sponsor for GDPR-led engagements
Chief Executive Officer
Whose strategic decisions are being undermined by data they cannot rely on
When organisations engage us
MI conflict at board or ExCo level
Two senior people can give the board different numbers for the same metric, and nobody knows which is correct or who is accountable for resolving it.
AI or analytics investment stalled
A digital or AI initiative is underperforming and the team cites data quality as the primary cause. The programme is sound; the foundations are not.
Following a regulatory inquiry, ICO investigation or data breach
Data protection has become the immediate priority. We lead with the compliance response and build the governance structure around it, so the fix outlasts the immediate pressure.
Regulatory or audit pressure
Audit findings or regulatory requirements demand traceable accountability for data accuracy and demonstrable GDPR compliance, and the organisation does not currently have the structures to provide it.
Pre-platform investment
A significant investment in data infrastructure, a data warehouse or an AI platform is being considered and governance and data protection are the prerequisites that need to be established first.
Start with clarity
