EPSOHQ
Annex II.2 — Governance and complianceVerified 12 Aug 2026

Data governance and compliance

Decision rights, stewardship, ownership, quality accountability, maturity assessment and the EU data-law stack.

Independent training. Official notice and EPSO communications prevail.Open official notice
All 13 modules

Snapshot

Decision rights, stewardship, ownership, quality accountability, maturity assessment and the EU data-law stack.

Module status

  • Track: Annex II.2 — Governance and compliance
  • Last verified: 2026-08-12
  • Scope: Independent EPSOHQ training mapped to Annex II; the official notice and candidate messages prevail.

Governance and compliance principles

Data governance assigns authority and accountability for data decisions. It is an operating model, not a catalogue purchase. A board resolves cross-domain priorities; owners remain accountable for defined data assets; stewards coordinate definitions, quality rules and issue resolution; technical custodians operate controls.

Exam-ready principles:

  • A data owner is accountable for decisions about a data asset, while a data steward coordinates its definitions, quality and use in daily practice.
  • Governance decision rights must identify who proposes, approves, implements, monitors and escalates each class of data decision.
  • A data policy states mandatory intent and rules, while a standard makes those rules testable through specific requirements.
  • Data quality accountability belongs with the business process and data owner, even when a technical team operates validation tools.
  • A maturity assessment needs defined capabilities and evidence; tool inventory alone does not demonstrate governance maturity.
  • The GDPR applies to personal data processing, while anonymised data fall outside it only when individuals are not reasonably identifiable.
  • The Data Governance Act creates conditions for data intermediation, public-sector protected-data reuse and data altruism; it does not create a general right to all data.
  • The Data Act regulates fair access to and use of data, including connected-product data and certain business-to-government access situations.
  • The Open Data Directive governs reuse of public-sector information and high-value datasets, subject to its scope and lawful restrictions.
  • Compliance by design translates legal and ethical requirements into architecture, process, controls, evidence and accountable review.

Use a control loop: identify obligations, map them to processing and assets, design preventive and detective controls, name owners, collect evidence, test effectiveness and remediate gaps. Regulatory lists are not controls. A mature programme explains how a requirement changes actual access, retention, sharing, quality or transparency.

Primary references: