Governance for your data platform: The sooner the better

2 min read

To meet today’s competitive demands, companies are rebuilding their data platforms, hoping to achieve new levels of business insight by eliminating data silos, utilizing the cloud and ensuring high performance, scalability and agility.

During the initial stages of development, a data governance strategy to ensure compliance with internal controls and regulatory requirements, including new privacy regulations, is often not a priority. Since few users and limited amounts of data are involved, the logic goes, data risks are low, so the emphasis should be on faster iteration. Governance can always be added later.

This logic is risky—and wrong. In the same way that better software testing speeds development, imposing data governance early on can speed data platform iteration, while also protecting data and ensuring compliance with the increasing demands of privacy regulations. In short, by investing early in data governance, you can build faster and stay out of trouble.

Privacy regulations are here to stay, and there will be more of them. The General Data Protection Regulation (GDPR) went into effect last year and non-compliance is proving to be fiscally painful. The U.K. Information Commissioner’s Office (ICO) levied a $230 million fine on British Airways and a $123 million fine on Marriott Group. And this doesn’t include the cost of legal fees, repairing damage to the brand, or lost opportunity costs.

A higher number of larger fines is expected in the future, and the California Consumer Privacy Act (CCPA) goes into effect next year, with more regulations to follow. Companies ignore these regulations at their peril.

Yet a typical data platform development process may start out something like this:

The problem here is clear. Adding data before a governance solution creates risk, no matter how “careful” developers insist they will be to avoid using sensitive data. Enterprises are typically pretty good at distinguishing clearly non-problematic data—zero personally identifiable information (PII)—from clearly problematic data—SSNs, credit card numbers, etc.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at information-management.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.