A data policy states a requirement and names who is accountable for meeting it. "Personal data is retained no longer than the purpose it was collected for requires." "Every critical data element has a named owner." Policies are deliberately few, deliberately short, and deliberately boring — they are the layer that does not change when the tooling does. The detail of how to comply belongs in a standard or a procedure underneath.

In practice. A workable policy set for a mid-sized organization is five to ten pages in total, each policy fitting on one page, each with an owner, an approval date and a review date. If it cannot be read in an afternoon by someone it applies to, it will not be.

Where it goes wrong. Two failure modes, both fatal. The first is the forty-page policy written to satisfy an auditor, which nobody reads and which therefore governs nothing. The second is a policy approved by a data team rather than by the business function it constrains: the moment it costs someone a deadline, it turns out to have had no authority behind it.