← All postsHow-to

Data governance for a small company: the useful parts

Data governance sounds like something only large organisations do. The three parts that matter — ownership, definitions and access — are worth having at fifteen people.

How-toD

Data governance is the set of decisions about who owns which data, what the numbers mean, who may see them, and how quality is maintained. In large organisations it becomes a function with a committee. In a company of fifteen it is three or four decisions, written down once — and skipping them is why two people present different revenue figures in the same meeting.

The trigger is usually a specific embarrassment rather than a principle: a report contradicted by another report, a customer list that turned out to exist in four versions, an ex-employee who still had access to everything, or a question from a customer about their data that nobody could answer.

The parts worth having early

  • An owner per dataset — customers, orders, financials, marketing lists — by role, accountable for it being correct and for who can see it.
  • Definitions for the handful of numbers people argue about: what counts as a customer, when revenue is recognised, what an active user is. One page.
  • A single source of truth per dataset, named. Where copies exist, say which one wins.
  • Access rules: who can read, who can edit, who can export. Export is the one usually forgotten and the one that leaks.
  • A joiners, movers and leavers routine, so access changes when people do.
  • Quality expectations for the fields that matter — required, format, who fixes errors — rather than for every field.
  • A record of what personal data you hold and why, which most data protection regimes expect and which is useful regardless.
  • A retention position, linked to your retention schedule rather than restated.

Definitions are the cheapest win and the one most often skipped. Two teams counting customers differently produces two truths, an argument in every review, and eventually a decision made on the wrong number. Writing down what a customer is takes twenty minutes and settles that permanently — and unlike most governance, it needs no tooling at all.

Doing it in a week, not a quarter

  1. List your datasets. Most small companies have between five and ten that matter.
  2. Assign an owner to each, by role, and get the person in that role to confirm.
  3. Write definitions for the five numbers that appear in your regular reporting. Circulate them and settle the disagreements now rather than in a review.
  4. For each dataset, name the source of truth and note where duplicates exist. The duplicates are your quality problem in the making.
  5. Write the access rules — read, edit, export — and check them against reality. What people actually have is usually broader than what anyone intended.
  6. Add access removal to your leaver checklist, and audit access once a year against the current staff list.
  7. Record what personal data you hold, why, and where — this doubles as the basis for your retention schedule.
  8. Review annually, or whenever you adopt a new system, which is when governance quietly decays.

What not to build yet

Small companies waste time on the parts of governance designed for scale: a formal council, a full data catalogue, quality scorecards, a lineage diagram of every field. None of these earn their cost below a certain size, and starting there is the reliable way to abandon the whole effort. Owners, definitions, access and retention are the parts that pay at any size. Everything else can wait until someone can name the specific problem it would solve.

Ettex Records is a reasonable home for the registers this produces: custom tables with typed fields for a dataset inventory — name, owner, source of truth, location, personal data yes or no, retention reference — plus relations between tables so owners and systems are references, saved views to see everything one role owns, revision history where every cell change is tracked, and CSV import to start from a spreadsheet. The definitions document and the access rules belong in Ettex Docs with version history, so "what did we mean by active customer last year" is answerable. Access to the workspace itself is managed in Ettex Teams, and the numbers everyone argues about usually live in Ettex Sheets.

The boundary: Ettex is not a data governance platform. There is no data catalogue that discovers your systems, no lineage, no quality scoring, no classification or PII detection, and no access-review workflow. What you get is a place to keep the registers and documents, plus workspace-level permissions. The decisions — who owns what, what the terms mean — are not a software problem anyway.

Signals governance is missing

  • Two reports on the same subject that disagree, and no agreed way to settle which is right.
  • The same customer list existing in several places, each partially updated.
  • Nobody able to say who owns a dataset when a question about it arrives.
  • Ex-employees still holding access months later.
  • A customer asking what data you hold about them and the answer taking days to assemble.
  • Key numbers defined differently by finance and by the team producing them.
  • Exports of the full customer list sitting in personal downloads folders.

Frequently asked

What is data governance?

The decisions about who owns each dataset, what key terms and numbers mean, who may access and export data, how quality is maintained, and how long data is kept.

Do small companies need it?

They need the useful parts — owners, definitions, access rules and retention. The committees, catalogues and scorecards designed for large organisations rarely pay for themselves below a few hundred people.

Where should you start?

With definitions of the five numbers your reports argue about, and an owner per dataset. Both take hours rather than weeks and remove the most common source of confusion.

What is a source of truth?

The one place a dataset is authoritative, named explicitly, so that when copies disagree there is a rule for which wins. Unnamed sources of truth are how four versions of a customer list appear.

How does data governance relate to data protection law?

Knowing what personal data you hold, why, where and who can see it is both good governance and the foundation of most data-protection obligations. The specific legal requirements depend on your jurisdiction — check them locally.

How often should access be reviewed?

Annually against the current staff list, plus removal at the point someone leaves. Access that accumulates and never contracts is the most common finding in any first review.

Data governance in a small company is four things written down: who owns each dataset, what the key numbers mean, who can read and export them, and how long you keep them. Everything else is scale you do not have yet.

IP
Written by Ivan P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.