concept

Decision Rights Over Data

Who is entitled to decide what a data element means, who may see it and how long it is kept — the substance of governance once the policy documents are set aside.

Data governance programmes usually produce policies and a committee. What determines whether anything changes is narrower: for each decision that recurs, who decides, and can they be found.

The decisions worth enumerating are few. Who defines what a term means. Who approves access to a dataset. Who sets its retention. Who accepts a quality threshold. Who authorises a new use of data already held. Who signs off a cross-border transfer.

Written down as a table with names, most organisations find several rows blank and several with three claimants. Blank rows are why requests stall; contested rows are why decisions get reversed.

The distinction that makes this work is between federated and centralised rights. Meaning within a domain, and access to a domain's data, belong to the domain — they need the context. Identity resolution keys, sensitivity classification and retention floors are cross-cutting and belong centrally, because a domain deciding its own definition of "customer" is exactly the failure governance exists to prevent. A model that centralises everything becomes a bottleneck; one that federates everything reproduces the problem it was meant to solve.