Snapshot
Decision rights, stewardship, ownership, quality accountability, maturity assessment and the EU data-law stack.
Module status
- •Track: Annex II.2 — Governance and compliance
- •Last verified: 2026-08-12
- •Scope: Independent EPSOHQ training mapped to Annex II; the official notice and candidate messages prevail.
Governance and compliance principles
Data governance assigns authority and accountability for data decisions. It is an operating model, not a catalogue purchase. A board resolves cross-domain priorities; owners remain accountable for defined data assets; stewards coordinate definitions, quality rules and issue resolution; technical custodians operate controls.
Exam-ready principles:
- •A data owner is accountable for decisions about a data asset, while a data steward coordinates its definitions, quality and use in daily practice.
- •Governance decision rights must identify who proposes, approves, implements, monitors and escalates each class of data decision.
- •A data policy states mandatory intent and rules, while a standard makes those rules testable through specific requirements.
- •Data quality accountability belongs with the business process and data owner, even when a technical team operates validation tools.
- •A maturity assessment needs defined capabilities and evidence; tool inventory alone does not demonstrate governance maturity.
- •The GDPR applies to personal data processing, while anonymised data fall outside it only when individuals are not reasonably identifiable.
- •The Data Governance Act creates conditions for data intermediation, public-sector protected-data reuse and data altruism; it does not create a general right to all data.
- •The Data Act regulates fair access to and use of data, including connected-product data and certain business-to-government access situations.
- •The Open Data Directive governs reuse of public-sector information and high-value datasets, subject to its scope and lawful restrictions.
- •Compliance by design translates legal and ethical requirements into architecture, process, controls, evidence and accountable review.
Use a control loop: identify obligations, map them to processing and assets, design preventive and detective controls, name owners, collect evidence, test effectiveness and remediate gaps. Regulatory lists are not controls. A mature programme explains how a requirement changes actual access, retention, sharing, quality or transparency.
Primary references: