Strong data governance has become an important part of running an organization because it improves data quality, reduces risk, strengthens security, and increases trust in business decisions. Data governance is definitely no longer just about fulfilling compliance requirements. This article provides our expert view on how to implement and demonstrate a coherent data governance framework, especially for data, security, and compliance decision-makers in the Benelux financial sector.
Data governance is the formal framework through which an organization defines how its data is produced, classified, protected, shared, and ultimately consumed. It is not a single technology, nor a single process, but a discipline that brings together policies, standards, roles, and supporting tooling to ensure that data is treated as a strategic asset rather than an operational byproduct.
Where data management answers the question "how do we move and store the data," data governance answers the prior and more consequential questions: who decides what the data means, who is allowed to use it, who is responsible when it is wrong, and how do we prove all of this to a regulator, an auditor, or a customer.
For organizations operating in the Benelux region, data governance is not optional in any practical sense. The region sits inside one of the strictest regulatory perimeters in the world, with the EU's General Data Protection Regulation (GDPR), the NIS2 Directive, the Digital Operational Resilience Act (DORA) for financial entities, the recently enacted AI Act, and a layer of national implementing legislation all imposing concrete, auditable obligations on how data is governed.
National supervisory authorities – the Autoriteit Persoonsgegevens (AP) in the Netherlands, the Gegevensbeschermingsautoriteit / Autorité de protection des données (GBA/APD) in Belgium, and the Commission nationale pour la protection des données (CNPD) in Luxembourg – actively enforce these obligations. And financial-sector regulators such as De Nederlandsche Bank (DNB), the National Bank of Belgium (NBB), and the Commission de Surveillance du Secteur Financier (CSSF) overlay additional, sector-specific governance expectations.
A mature data governance program typically rests on five mutually reinforcing pillars:
Each pillar can fail in isolation, but a program cannot succeed unless all five are addressed coherently.
Next, we will go into each of these in more detail.
Data security is the foundation on which every other data governance pillar stands. If an organization cannot demonstrate that its data is protected against unauthorized access, modification, or exfiltration, then no policy on quality, privacy, or accountability carries credibility.
Security in a governance context goes well beyond perimeter defense. It encompasses:
In the Benelux region, the regulatory expectations around data security have intensified sharply in recent years. The NIS2 Directive, transposed into national law in all three countries, extends cybersecurity obligations to a much wider population of "essential" and "important" entities, including many financial, energy, transport, healthcare, and digital infrastructure organizations. NIS2 requires documented risk management measures, supply-chain security, incident reporting within 24 hours of awareness, and personal accountability at the management body level.
For financial institutions supervised by DNB, NBB, or the CSSF, DORA imposes further specific requirements on ICT risk management, third-party risk, and resilience testing. GDPR Article 32 separately requires "appropriate technical and organizational measures" to ensure a level of security appropriate to the risk, and a failure to implement them is itself a sanctionable offense – independent of whether a breach actually occurs.
Proper security measures are therefore not merely a defensive necessity; they are a compliance instrument, and the ability to evidence them through controls, attestations, and audit trails is what transforms a security posture into a governance asset.
Privacy is closely related to security but is conceptually distinct. Security asks whether data is protected; privacy asks whether the organization has the right to hold and use the data in the first place, and whether the rights of the individuals to whom that data relates are being respected.
A perfectly secured dataset can still represent a serious privacy violation if it was collected without a lawful basis, used beyond the purposes communicated to the data subject, retained longer than necessary, or transferred outside the European Economic Area without adequate safeguards.
The Benelux jurisdictions are governed primarily by the GDPR, supplemented by national implementing acts: the Uitvoeringswet AVG (UAVG) in the Netherlands, the Belgian Act of 30 July 2018 on the protection of natural persons about the processing of personal data, and the Luxembourg Act of 1 August 2018. These instruments translate GDPR principles – lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability into binding national obligations.
A robust governance program must operationalize these principles concretely: maintaining a record of processing activities under Article 30, performing Data Protection Impact Assessments under Article 35 for high-risk processing, embedding privacy-by-design into project intake, enforcing retention schedules, and providing mechanisms for data subjects to exercise their rights of access, rectification, erasure, restriction, portability, and objection.
The recently applicable EU AI Act adds another layer, classifying certain AI use cases as high-risk and tying their deployment to data governance requirements that cover training, validation, and testing data.
National supervisors have been demonstrably willing to impose significant fines – the AP, GBA/APD, and CNPD have each issued sanctions in the millions of euros – and reputational damage in the Benelux markets often outweighs the financial penalty itself.
Even perfectly secured and lawfully processed data is of little value if it is wrong. Data quality is the discipline of ensuring that data is fit for the purposes for which it is used, and is typically measured across several dimensions: accuracy, completeness, consistency, timeliness, uniqueness, and validity.
A governance program defines:
Underpinning effective data quality is data lineage, the end-to-end record of where each piece of data originated, how it has been transformed at every step of its journey, and where it is ultimately consumed.
Without lineage, quality issues become almost impossible to resolve at the root: when a regulatory report shows an anomalous figure, an analyst without lineage can only debug locally and hope. But an analyst with lineage can trace the value back through every transformation, identify the source system or rule responsible, and assess the downstream impact on every other report or model that draws on the same data.
For financial institutions in the Benelux region, lineage is not merely a quality-of-life feature – it is implicitly required by the Basel Committee's BCBS 239 principles for risk data aggregation and reporting, which supervisors such as DNB, NBB, and the European Central Bank actively examine.
Lineage is also essential for impact analysis when systems are changed, for audit defensibility, and for demonstrating to regulators that data flowing into critical decisions can be reconstructed and explained.
Metadata (data about data) is the connective tissue that makes the rest of the governance programme operable. It captures business definitions, technical schemas, ownership, classification levels, retention rules, source and lineage references, quality scores, and access policies.
Without managed metadata, governance exists only on paper: rules cannot be enforced consistently because the systems that store the data do not know which rules apply.
The cornerstone artefact of metadata management is the enterprise data dictionary (sometimes called a business glossary, especially when its scope is limited to business terminology). The enterprise data dictionary is the authoritative, single-source-of-truth catalog of the terms that matter to the business – what a "customer" is, what counts as an "active account," how "invoice type" is defined – together with the technical attributes that implement each term, the owner accountable for its definition, its sensitivity classification, and its allowable values.
A well-maintained dictionary eliminates the kind of definitional ambiguity that causes finance and operations to report different numbers for the same metric, allows compliance teams to identify every system that stores a given category of personal data, and gives engineers a reliable reference when building new pipelines or models. In modern data platforms, the dictionary is typically implemented through a data catalog tool that integrates with source systems, lineage scanners, and access management, turning metadata into an active control rather than a static document.
The final pillar – and the one without which the others cannot function is accountability. Policies, controls, and tools do not enforce themselves; they require named individuals who are personally responsible for specific decisions and outcomes.
A governance program therefore defines a layered role structure, articulated through a RACI or similar model, that distributes responsibility across the organization.
At the executive level, the Chief Data Officer (or equivalent) owns the governance program overall and reports to the board on its effectiveness. Under GDPR Article 37, many Benelux organizations are also required to appoint a Data Protection Officer, who operates independently and reports to the highest level of management.
Closer to the data itself, three roles do most of the day-to-day work.
The project owner is accountable for ensuring that any initiative consuming or producing data does so in line with governance policies – engaging the right stakeholders, completing the required assessments (DPIA, security review, architecture review), and integrating governance deliverables into the project plan rather than treating them as afterthoughts.
The data owner, typically a senior business stakeholder, is accountable for a defined data domain: they decide what the data means, who may access it, what quality is acceptable, and how long it is retained. They are the person a regulator or auditor will ultimately address questions to.
The data steward operates under the data owner and carries out the operational work of governance: maintaining the domain's data dictionary entries, monitoring quality metrics, triaging incidents, approving access requests, and serving as the subject-matter expert for the data they steward. In larger organizations, a fourth role – the data custodian, typically in IT – handles the technical implementation of the policies the owner sets, and the steward maintains.
Accountability only works when these roles are named, formally documented, communicated, and embedded in performance objectives. A governance programme in which "everyone" is responsible for data quality is one in which no one is; clarity of roles is the mechanism through which all four of the preceding pillars become real.
The five pillars are not a checklist to be completed sequentially but a system to be operated continuously.
Security without privacy can lock down data the organization should not be holding; privacy without quality can produce lawful but useless analytics; quality without metadata cannot be measured at scale; metadata without accountability rapidly becomes stale; accountability without the other four pillars is responsibility without substance.
The role of a data governance program, and of the chapters that follow, is to show how these pillars are designed, implemented, and operated together, in a way that satisfies regulators, while genuinely making the organization's data more trustworthy, more usable, and more valuable.
Want to learn more?
Explore our Integration & data services and get in touch. We’ll help you build change-capable architectures.