A committee exists so governance has somewhere to get authority from. Data owners can settle what a customer is and who approves access to it, but they cannot approve a budget, absorb a regulatory risk on behalf of the company, or tell another executive that a project ships late because its data is not ready. That is why the room is wider than the data team: the C-level sponsor who owns the P&L, the data protection officer, the cybersecurity director, and usually legal, internal audit and the domain owners whose data is on the agenda.
In practice. It meets quarterly, not monthly, because it decides fewer and bigger things than a council: the policy set, the funding, the risk appetite, the priority domains, and the escalations the council could not close. Every item arrives with a recommendation attached and leaves with a name against it. The DPO and the security lead are members rather than reviewers, which is what stops a privacy or security objection from landing three weeks after a decision was already made.
Where it goes wrong. Only data people show up. A committee of the CDO, two analysts and a consultant can recommend anything and fund nothing, and after two meetings it becomes a project status review with an executive title. The other failure is the opposite: thirty invitees, a fifty-slide deck, and a decision log that has been empty since the kickoff.