Glossary

Data governance glossary

Data governance has a vocabulary problem: the same word means three different things in three different meetings. So here is every term you will actually run into, explained the way you would explain it to a colleague — what it means, how it works on a normal Tuesday, and where it usually goes wrong.

47 terms

Foundations

The words everything else leans on: what governance is, how far it reaches, and the policies and standards holding it up.

6 terms
DAMA-DMBOK
DAMA International's reference framework for data management: eleven knowledge areas arranged around data governance at the center.
Data governance
The system of decision rights and accountabilities for data — who may decide what about which data, and on what basis.
Data governance committee
The executive forum where data owners sit alongside C-level sponsors, the DPO and the security lead to give governance its mandate, its budget and its risk decisions.
Data management
The work of building and running the systems, processes, and controls that hold data through its whole life.
Data policy
A short, binding statement of what the organization requires of its data, approved by someone with the authority to require it.
Data standard
The specific, testable rule that says how a policy is satisfied — format, allowed values, naming, tolerance.

Roles and accountability

Who decides, who answers for it, and who does the daily work of keeping data usable.

5 terms
Data governance council
The standing forum of data owners that settles the decisions no single domain can make alone.
Data owner
The single accountable person for a data domain — the one who decides, approves and answers for it, and who has the budget to act.
Data steward
The person who does the day-to-day governance work in a domain: definitions, rules, quality issues, and the questions nobody else can answer.
Data stewardship
The practice and the network of people through which governance decisions actually reach the data.
Decision rights
The explicit record of which role decides, which is consulted, and which is merely informed — per decision, not in general.

Metadata and catalog

How your organization knows what data it has, what it means, and where it came from.

6 terms
Active metadata ingestion
Capturing metadata as events happen — in real time, from the systems themselves — and feeding it back into the tools where people work.
Business glossary
The agreed, owned definitions of the terms the organization reports on — one meaning per term, with a name against it.
Data catalog
The searchable inventory of data assets, with their meaning, owner, lineage and quality attached.
Data lineage
The traceable path a value takes from where it originated to where it is used, including every transformation on the way.
Master data management
The discipline of maintaining one authoritative record for the entities the whole business shares — customer, product, supplier, employee.
Metadata
The descriptive layer around a data asset: what it means, where it came from, who owns it, how it may be used.

Data quality

Whether the data can be trusted, how you measure that, and what to do when the answer is no.

7 terms
Cost of poor data quality
The measurable money and time an organization loses to data that is wrong, missing, late or duplicated.
Critical data element
A data field whose failure has a material consequence — regulatory, financial, operational or reputational — and which therefore gets governed first.
Data profiling
Examining actual data to learn what is really in it — value distributions, null rates, formats, outliers, relationships.
Data quality
The degree to which data is fit for the purpose someone is using it for — which means quality is always relative to a use.
Data quality dimensions
The standard axes along which data can fail: completeness, accuracy, consistency, timeliness, validity, uniqueness.
Data quality rule
An executable test on data with a defined threshold and a named owner who acts when it fails.
DMAIC
The Six Sigma improvement cycle — Define, Measure, Analyze, Improve, Control — used to fix a data quality problem and keep it fixed.

Literacy and culture

The human side: the skills and habits that keep governance alive after the project ends.

3 terms
Data culture
The set of habits that determine whether evidence changes what an organization does — including when it contradicts the person in charge.
Data literacy
The ability to read, question, interpret and argue with data well enough to make a decision with it.
Data-driven decision making
Making choices where the evidence is examined before the conclusion is formed, and can change it.

Maturity and measurement

Where you stand today, where you are heading, and how you show that you moved.

6 terms
Data governance operating model
The written arrangement of who governs what, how decisions are made, and how the work reaches the data day to day.
Data maturity
How reliably and repeatably an organization manages its data — whether the outcome depends on the process or on the individual.
Data maturity model
A structured scale for rating data capabilities, usually from ad hoc to optimized, used to diagnose where to invest.
Levels of maturity
The named stages a maturity model scores against — typically ad hoc, repeatable, defined, managed and optimized — describing behaviour rather than tooling.
Proactive data governance
Governance built into how data is created and changed, so problems are prevented at the source instead of found downstream.
Reactive data governance
Governance that only moves when something breaks — an audit finding, a wrong number in a board pack, a breach — and goes quiet in between.

AI, privacy and risk

What has to be protected, from whom, and what AI changes about both questions.

7 terms
AI governance
The controls over how models are built, approved, monitored and retired — most of which are data controls wearing a new name.
Confidential data
Data whose exposure harms the organization — pricing, margins, salaries, deal pipelines, source code, customer lists.
Data classification
Labeling data by how sensitive it is, so that handling rules can be applied automatically rather than remembered.
Dynamic data masking
Hiding or transforming sensitive values at query time based on who is asking, while the stored data itself stays untouched.
Personally identifiable information
Data that identifies a living person, directly or in combination with other data the holder can reach.
Role-based access control
Granting access to roles that describe a job, then putting people into roles — so permissions are reviewed and revoked as a set, not one by one.
Sensitive data
Data whose exposure harms the person it describes — health, biometrics, beliefs, sexual orientation, criminal records, precise location.

Architecture and data products

How data becomes products, domains and contracts that other teams can build on.

7 terms
Data contract
An explicit, versioned agreement between a data producer and its consumers covering schema, meaning, freshness, quality and how change is announced.
Data domain
A bounded subject area of data — customer, product, employee, contract — that one accountable owner can reasonably answer for.
Data product
A curated, documented, owned dataset built and maintained for known consumers, with a service level attached.
Data subdomain
A slice inside a data domain with its own steward, its own vocabulary and its own critical data elements.
External data marketplace
Where data products are exchanged with parties outside the company — as a buyer of third-party data, or as a publisher of your own.
Internal data marketplace
The place inside the company where teams browse published data products, request access, and get it — with an owner, a contract and a service level attached to each listing.
Single source of truth
The one place designated as authoritative for a given piece of data, which everything else derives from or defers to.