No one person owns data governance. The CISO protects data from unauthorized access. Legal and the privacy office decide what you’re allowed to collect, retain, transfer and share. The chief data officer owns whether that data is accurate and usable. The data team builds what the other three decide. Write that split into one RACI chart before your next audit.
Takeaways
- The CISO owns protecting data that already exists, while legal owns the decision of whether that data should have been collected at all.
- GDPR’s Article 33 gives organizations 72 hours to notify a supervisory authority after discovering a breach involving personal data.
- A 2023 SEC rule requires U.S. public companies to disclose material cybersecurity incidents within four business days on Form 8-K.
- Data classification should carry four signatures: the CDO proposes categories, legal maps them to regulations, the CISO assigns controls, and the data team implements the tags.
- A working data governance RACI chart needs only four rows: classification, retention, access and the data dictionary, each with exactly one accountable owner.
| Global breach cost | $4.88M in 2024 (IBM) |
|---|---|
| GDPR notice window | 72 hours after discovery |
| SEC disclosure window | 4 business days (Form 8-K) |
| AI training data rule | EU AI Act Article 10 |
What does the CISO own?
The CISO owns protecting data once it exists, not deciding whether it should exist. I’ve written separately about who owns cybersecurity across the CISO, CIO, CTO, CFO and CHRO, and data governance splits along a similar but not identical line. That means access controls, encryption, monitoring, and the incident response plan that fires when something goes wrong. Under GDPR’s Article 33, a breach involving personal data must reach the relevant supervisory authority within 72 hours of discovery. A 2023 SEC rule requires U.S. public companies to disclose material cybersecurity incidents within four business days on Form 8-K. ISO/IEC 27001 puts ultimate accountability with top management, which in practice usually means the CISO writes the plan. What the CISO doesn’t own is whether a dataset should have existed at all, or how long it should be kept. Those are legal questions, and confusing the two is the mistake I train teams to fix first.
What does legal own?
Legal and the privacy office decide whether you’re allowed to collect, retain, transfer or share data at all. That covers consent language, retention schedules, cross-border transfer rules, and responding to a person’s request to see or delete their own data. Under GDPR’s accountability principle, an organization must be able to demonstrate compliance, not just claim it, and that burden usually falls to legal or a designated data protection officer. The California Privacy Protection Agency enforces the CPRA’s rules the same way. Sector laws add more layers: the FTC’s Safeguards Rule covers financial data, and HIPAA covers health data. Legal doesn’t build access controls or write the data dictionary; legal decides the boundary that security and the data team build inside. When legal wants records kept seven years for litigation and security wants old data deleted to shrink exposure, legal’s regulatory obligation should win, but the decision needs to be documented, not assumed.
What does the CDO own?
The chief data officer owns whether the organization’s data is accurate and usable, not whether it’s legally allowed to exist. That means a shared data dictionary, so “active customer” means the same thing in sales and finance, plus quality metrics and a catalog that shows where a dataset lives and who owns it. DAMA International’s Data Management Body of Knowledge treats governance as a CDO-level function above the technical work of moving and storing data. McKinsey’s research on data governance makes a related point: programs stall when no one is accountable for data as a business asset, separate from data as a security risk. The CDO role is newer than the CISO’s or general counsel’s, and many companies don’t have one yet, which is when data quality problems get blamed on “IT” instead of assigned to anyone by name.
Where does the data team fit?
The data engineering and analytics team owns implementation, not policy. Once legal sets the retention rule, the CISO sets the access standard, and the CDO sets the data definition, the data team builds the pipeline, tags the dataset, documents where it flows, and provisions access to match. Treating the data team as the default owner of governance is a common shortcut, because they have the database credentials, but it puts implementers in charge of decisions carrying legal and security consequences they weren’t trained to weigh. A simple test sorts most disputes: if a decision requires interpreting a regulation, it belongs to legal. If it requires deciding who gets access, it belongs to the CISO. If it requires deciding what a field means or whether it’s trustworthy, it belongs to the CDO. Anything left over belongs to the data team.
The five ownership gaps, ranked by what they cost
Ownership gaps in data governance don’t all cost the same, and knowing which bite hardest shows where to fix the RACI chart first. IBM’s 2024 Cost of a Data Breach Report put the global average breach cost at $4.88 million, and breaches take longer to contain when no one owns the response end to end. Ranked from most to least expensive, based on how each gap typically shows up in a breach or an audit:
- No one classifies data before an incident, so security can’t prioritize protecting records it doesn’t know exist, and the most sensitive data is often found only after it’s already exposed.
- Legal and security disagree on retention and no one resolves it, so data gets kept past its legal shelf life “just in case,” which is exactly the data a later breach exposes.
- The CDO owns quality but not security, so a sensitive field gets labeled low-risk by default because no one told the data team otherwise, and the wrong control gets applied.
- The data team provisions access without a policy owner’s sign-off, so people accumulate access they no longer need, widening the pool of accounts an attacker could compromise.
- There’s no single escalation path when a decision crosses functions, so an incident sits in email threads while the regulatory notification clock keeps running.
Who signs off on classification?
Data classification should carry four signatures, not one, because it’s the decision every other governance rule depends on. The CDO proposes the categories, for example public, internal, confidential and restricted, based on what the data is. Legal maps each category to the regulations that apply, such as whether a field counts as personal data under GDPR. The CISO assigns the security control required for each category, like encryption at rest for restricted data. NIST’s Privacy Framework calls this the Identify-P function: an organization inventories what data it holds before deciding how to protect it. The data team implements the tags in the catalog and the access system. Write the sign-off into the policy itself: “The CDO recommends the category, legal approves the regulatory mapping, the CISO approves the control, and the data governance council ratifies the scheme once a year.” That sentence, word for word, is what I have teams put at the top of their classification policy.
Does AI change who owns this?
AI adds a new governance question, but it doesn’t change who answers it. The EU AI Act, in force since 2024, requires that training, validation and testing datasets for high-risk AI systems meet specific data governance and quality criteria under Article 10. That obligation still splits the same way: legal interprets which AI systems count as high-risk, the CDO vets whether the training data is accurate and representative, and the CISO controls who can access the model and the data feeding it. NIST’s AI Risk Management Framework, published in January 2023, makes a similar point in plainer language: govern, map, measure and manage are separate functions, and no single team owns all four. The new risk is an AI agent that can read across systems faster than any human reviewer, which makes the classification work above more urgent. I’ve written separately about how long context, tool use and computer use work, which covers what that kind of agent access requires.
How do you draw the RACI in one meeting?
You can draw a working data governance RACI chart in one meeting if you limit it to four decisions. Put four rows on a whiteboard: who classifies data, who approves retention, who approves access, and who owns the data dictionary. For each row, name exactly one person as Accountable, even when others are Consulted. In most organizations that plays out as: the CDO accountable for classification and the dictionary, legal accountable for retention, and the CISO accountable for access. NIST’s Cybersecurity Framework 2.0, updated in 2024, added a dedicated Govern function for this reason: naming who’s accountable is now treated as a security control in its own right. Get the chart ratified by whoever the CISO and CDO both report to, so it survives the next reorg. Skip the forty-row chart some governance consultants sell; it looks thorough and nobody uses it, because four functions can’t track forty decisions. The same discipline applies to board reporting: fewer, sharper metrics beat a long dashboard, a trap I wrote about in why a phishing click rate tells the board nothing useful.
Prompts you can use
Paste these straight in. Change the parts in square brackets and nothing else.
You are an experienced data governance consultant helping me design a RACI chart for my organization. Here is my context: [describe your company size, industry, whether you have a CISO, a CDO or equivalent, a legal/privacy lead, and a data engineering team, and note any regulations that apply to you such as GDPR, CCPA/CPRA, HIPAA or the EU AI Act]. Build a RACI chart covering exactly four decisions: data classification, data retention, data access approval, and ownership of the data dictionary. For each decision, name who should be Responsible, Accountable, Consulted and Informed, and explain in one sentence why that role fits, given my context. Flag any decision where my organization currently has no clear owner. Before you produce the chart, ask me any clarifying questions you need about my org structure or regulatory obligations.
Replace the bracketed context with your real org details, and treat the output as a starting draft to check with legal and security before adopting.
Act as a data governance and privacy reviewer. I will paste our current data classification policy below. Review it against these four checks: (1) does every classification category have a named owner from legal, security, or the data team responsible for defining it, (2) does every category map to a specific regulation such as GDPR, CCPA/CPRA or HIPAA rather than a vague description, (3) does every category specify a concrete security control such as encryption or access restriction, and (4) is there a documented sign-off process with named roles, not just named people who could leave. List every gap you find, ranked by how much regulatory or security risk it creates. Ask me clarifying questions about our industry and applicable regulations before you start if you need them. Here is the policy: [paste policy text]
This works best on an existing draft policy; for a blank page, use the RACI prompt above first.
You are helping me figure out who inside my company should own data governance decisions for the AI systems we use or build. I will describe each AI system we use: [list each system, what it does, what data it touches, and whether it makes decisions about people, such as hiring, credit or healthcare]. For each system, tell me whether it likely counts as high-risk under a framework like the EU AI Act, what data governance obligation that status would create if it applies to us, and which of these four roles should own the resulting decision: legal, the CISO, the CDO, or the data engineering team. Be explicit about where you are uncertain and where I should get a lawyer's confirmation instead of relying on your answer.
This is a starting map, not legal advice; confirm any high-risk classification with counsel before acting on it.
Questions people actually ask
Should the CISO or the CDO own data governance?
Neither owns it alone. The CISO owns protecting data from unauthorized access, and the CDO owns whether that data is accurate and usable as a business asset. Split the two roles in writing, or quality and security decisions will keep getting made by whichever team reacts first.
Does legal or the CISO decide how long to keep data?
Legal decides, because retention periods usually follow a regulatory or litigation requirement, not a security preference. The CISO can push to delete old data sooner to reduce breach exposure, but the final retention schedule should reflect what the law requires legal to defend.
Who is accountable if a data breach happens because of bad governance?
It depends on where the failure occurred. If sensitive data was never classified, that traces back to the CDO and data team. If access controls failed, that’s the CISO. If the wrong data was collected or kept too long, that’s legal.
Do small companies need a chief data officer?
Not necessarily by title. What they need is one named person accountable for data quality and definitions, separate from whoever handles security and whoever handles legal compliance. A 20-person startup can assign this as a responsibility without hiring a formal CDO.
How often should a data governance RACI chart be reviewed?
Review it at least once a year, and immediately after any reorg that changes who the CISO or CDO reports to, since a RACI chart with an outdated reporting line stops working the moment the org chart changes underneath it.
Sources
- GDPR’s Article 33gdpr-info.eu
- 2023 SEC rulesec.gov
- ISO/IEC 27001iso.org
- accountability principlegdpr-info.eu
- California Privacy Protection Agencycppa.ca.gov
- FTC’s Safeguards Ruleftc.gov
- HIPAAhhs.gov
- DAMA International’s Data Management Body of Knowledgedama.org
- McKinsey’s research on data governancemckinsey.com
- IBM’s 2024 Cost of a Data Breach Reportibm.com
- NIST’s Privacy Frameworknist.gov
- EU AI Acteur-lex.europa.eu
- NIST’s AI Risk Management Frameworknist.gov
- NIST’s Cybersecurity Framework 2.0nist.gov
What happens next
Expect data governance responsibilities to keep colliding with AI rules, since the EU AI Act’s Article 10 already ties training data quality to legal compliance rather than leaving it purely as a CDO or engineering concern. Watch whether more organizations formalize a data governance council the way many already have an incident response team, since ad hoc ownership is what regulators cite most often after a breach. If your company doesn’t have a CDO yet, watch who inherits data quality decisions by default, because that person is doing the job without the title or the authority that should come with it.
Take this further
Act as a blunt hiring manager who has read ten thousand resumes, not a career coach. I will paste my full resume and the job description I want. Rewrite the whole resume for that role, section by section, in this order: summary, experience, skills, education. Rules: every experience line leads with impact, not duty. Use bracketed placeholders like [8 percent] for any number I did not give you, and list at the end every placeholder I need to replace with a real figure. Keep it to one page of text. Plain formatting only, no tables or columns, so screening software can parse it. After the rewrite, tell me the three weakest claims that need evidence before I send this anywhere. My resume: [paste resume]. The role: [paste job description].

