Data governance framework design sounds like an enterprise problem, and for a long time it was. Large organisations hired stewards, bought catalogues and wrote hundred-page policies while everybody else simply got on with the work. That distinction has quietly collapsed. A thirty-person business today runs a CRM, a finance system, a shared drive, a payroll platform, a marketing tool, three integrations nobody documented and a steadily growing pile of exports sitting in personal folders — and it carries the same legal duties over that data as an organisation a hundred times its size.
The gap is not ambition. It is that almost every published data governance framework assumes a team that does not exist. A small business does not have a chief data officer, a stewardship council or a budget line for metadata tooling. It has an operations manager who already does three jobs, an outsourced IT provider and a director who wants to know why the customer list in the CRM disagrees with the one in the accounts package. A data governance framework has to fit around those people or it does not happen at all.
This guide is written for that reality. It covers what belongs in a data governance framework for a business of ten to two hundred and fifty people, who owns each part, how to build the inventory without stalling, what to classify and what to ignore, how to set retention that survives audit, what it costs, and a ninety-day plan that produces something real rather than a policy nobody reads. Our cybersecurity and data protection practices sit underneath the controls described here, and our IT governance work is where the accountability side usually starts.
Table of contents
- Why a data governance framework matters more for SMEs than for enterprises
- What a data governance framework actually is, and what it is not
- The six components of an SME data governance framework
- Data governance framework roles: who owns what in a small organisation
- Building the inventory your data governance framework depends on
- Classification that people will actually follow
- Data quality: the four measures your data governance framework should track
- Retention and disposal: the fastest risk reduction in any data governance framework
- Access control and third-party data sharing
- Your data governance framework and AI: the new pressure
- Tooling: what your data governance framework should buy, and what it should defer
- A 90-day data governance framework implementation plan
- What a data governance framework costs and what it saves
- Measuring whether the data governance framework is working
- Data governance framework failure modes and how to avoid them
- Data governance framework: frequently asked questions
- References
Why a data governance framework matters more for SMEs than for enterprises
The intuition runs the other way — big organisation, big problem — and on the question of a data governance framework it is wrong in every way that matters commercially.
Small teams carry identical legal duties
UK GDPR and the Data Protection Act 2018 make almost no allowance for headcount. The obligations to hold accurate records, keep data no longer than necessary, respond to a subject access request within a month and report a qualifying breach within seventy-two hours apply to a five-person consultancy exactly as they apply to a supermarket chain. A data governance framework is simply the cheapest way to be able to answer those obligations without a fire drill each time.
One person usually holds the whole map
In most small businesses, the knowledge of which system holds what, which export feeds which report and which spreadsheet is authoritative lives in one head. That is a single point of failure with no redundancy, no backup and a notice period. Writing it down is the single highest-return governance activity available, and it is what a data governance framework forces.
Growth turns tolerable mess into genuine risk
Twelve customers in a spreadsheet is a filing habit. Twelve thousand is a regulated asset. The transition happens without an announcement, and the practices that were sensible at the start — everyone can see everything, exports live on the desktop, nothing is ever deleted — become the exact findings an auditor, an insurer or an acquirer will write down, and the exact gaps a data governance framework is built to close.
Due diligence now asks the question directly
Cyber insurance renewals, enterprise customer onboarding, supplier questionnaires and acquisition due diligence all now include data handling questions. A business with a documented data governance framework answers them in an afternoon. A business without one spends three weeks reconstructing the answers and still discloses gaps it did not know it had.
AI has raised the cost of ungoverned data
Every assistant, copilot and automation you connect inherits whatever mess it is pointed at, because none of them can infer a data governance framework you never wrote. Ungoverned data used to produce bad reports slowly; it now produces confident, fast, wrong answers at scale, and it exposes anything over-shared to a much wider audience. Our guide to an AI governance framework for SMEs covers the model side; this article covers the data underneath it.
What a data governance framework actually is, and what it is not
Most of the confusion about a data governance framework is definitional, and that confusion is what makes people buy the wrong thing.
It is a set of decisions, not a document
A data governance framework is the answer to five questions: who owns each data set, what each classification of data is allowed to be used for, how long it is kept, who may access it, and how anyone knows whether the answers are still true. The policy document records those answers. The answers are the framework; the document is the receipt.
It is not a tool purchase
Cataloguing, lineage and quality tools are useful once the decisions exist. Bought before the data governance framework exists, they produce an expensive inventory of an ungoverned estate. The order matters: decide, document, then automate the parts that are painful to maintain by hand.
It is not the same as data protection compliance
Compliance is a subset. A data governance framework also covers commercially sensitive data with no personal element — pricing models, source code, supplier terms, board papers — and it covers quality and usefulness, which the regulation says almost nothing about. Treating the two as identical produces a framework that protects personal data and ignores the intellectual property that funds the business.
It is not a one-off project
The estate changes every month. A data governance framework that is not reviewed becomes a description of a business that no longer exists, which is worse than no framework at all because it creates false assurance.
| Common belief | What is actually true | Consequence of the belief |
|---|---|---|
| Governance means buying a catalogue | Governance means assigning owners and rules | Licence spend with no behaviour change |
| It is the IT department’s job | Owners sit in the business, IT operates controls | Rules nobody in operations accepts |
| We are too small to need it | Duties are identical; only resources differ | Breach, fine or lost deal discovers it for you |
| Compliance covers it | Compliance ignores quality and commercial data | Protected personal data, unmanaged everything else |
| We will do it after the migration | Migration is the cheapest moment to do it | The mess is copied into the new platform |
| A policy document is the deliverable | The inventory and retention schedule are | A signed policy with no operational effect |
The six components of an SME data governance framework
Enterprise models list eleven or twelve disciplines. In a data governance framework built for a business under two hundred and fifty people, six components carry almost all the value, and each has a version small enough to finish.
Ownership and accountability
Every significant data set in the data governance framework has one named owner who is accountable for who may use it, how long it is kept and whether it is correct. Owners are business people, not IT people: the sales director owns the customer record, the finance manager owns the ledger, the operations lead owns supplier data.
An inventory you can actually maintain
A list of the systems that hold data, what they hold, who owns them, where they sit and what feeds in and out. Systems, not fields. A twenty-row table beats a two-thousand-row one nobody updates.
Classification and handling rules
Two or three tiers with concrete handling rules attached. The tier is meaningless; the rule attached to it is the control.
Quality standards and measurement
A small number of measures — completeness, accuracy, duplication, timeliness — with a baseline and a target for the data sets that drive decisions.
Retention and disposal
How long each record type is kept, on what basis, and how it is actually destroyed when the clock runs out. This is the component of a data governance framework that reduces risk fastest, and the one most often skipped.
Access, sharing and third parties
Who may see what, how that is granted and removed, and what happens when data leaves the building for a processor, a partner or an analytics tool.
| Component | Minimum viable version | Usual owner | Evidence it exists |
|---|---|---|---|
| Ownership | One named owner per system | Sponsor assigns | Owner column in the inventory |
| Inventory | 20-40 rows, one per system | Operations or IT lead | Dated register with a review date |
| Classification | Three tiers with handling rules | Data owners jointly | One-page handling table |
| Quality | Four measures on two data sets | Owner of each data set | Baseline figures with a date |
| Retention | One-page schedule by record type | Finance or company secretary | Schedule plus deletion log |
| Access and sharing | Role matrix plus processor list | IT with owner sign-off | Quarterly access review record |
Data governance framework roles: who owns what in a small organisation
Data governance framework role models fail in small businesses because they assume the roles are jobs. In a thirty-person firm they are hats, and one person often wears three. Naming them still matters, because unnamed accountability defaults to nobody.
The sponsor
A director who owns the data governance framework’s existence, approves the classification tiers and the retention schedule, and settles disputes between owners. Without a sponsor the work stalls the first time it collides with a sales deadline. Expect two hours a month.
Data owners
Two to five people who own the main data sets. They decide access, approve new uses, and sign off retention. They do not do the work; they make the decisions the work implements. Expect an hour a month each.
Data stewards
The people who actually maintain quality in a system — the person who cleans the CRM, the one who reconciles the ledger. Usually already doing it informally. The data governance framework simply names them and gives them authority to reject bad input.
The IT or provider role
Implements the controls: permissions, labelling, logging, backup, deletion tooling. This may be an internal person or your managed provider. If it is a provider, the responsibilities belong in the contract, not in an email.
The data protection role
Someone accountable for the regulatory side: the record of processing, subject access requests, breach reporting and impact assessments. Most SMEs do not need a statutory data protection officer, but everyone needs a named person, and pretending the role is distributed means it is absent.
| Role | Who it usually is in a 30-person firm | Time per month | Decides |
|---|---|---|---|
| Sponsor | Managing director or finance director | 2 hours | Scope, tiers, retention, disputes |
| Data owner | Head of sales, finance manager, ops lead | 1 hour each | Access, permitted uses, sign-off |
| Data steward | CRM administrator, credit controller | 2-4 hours each | What counts as a valid record |
| IT or provider | Internal IT lead or managed provider | 4-6 hours | How controls are implemented |
| Data protection lead | Operations manager or company secretary | 2-3 hours | Lawful basis, requests, breaches |
Building the inventory your data governance framework depends on
The inventory is where most data governance framework attempts die, because they are scoped as a data discovery exercise rather than a system list. Scope it as systems and it takes a fortnight.
Start with systems, not fields
List every place data lives: SaaS applications, servers, shared drives, mailboxes, databases, backups, and the two or three departmental spreadsheets everybody relies on. A business of thirty people typically lands between twenty-five and forty rows. Field-level cataloguing can wait years, and for most SMEs forever.
The eight questions per system
For each row, answer: what does it hold, who owns it, who administers it, roughly how many records, what classification, how long is it kept, what feeds it, and what does it feed. Eight columns, one afternoon per department. Anything more detailed will not be maintained.
Where the surprises always are
Three places produce findings in almost every engagement: mailboxes holding years of attachments with personal data, ex-employee accounts and their OneDrive or Google Drive contents, and analytics or marketing tools that quietly hold a copy of the customer base. Departed staff accounts are the most common single finding, and closing them is often the fastest risk reduction available. Our IT asset management approach catches the hardware side of the same problem.
Keeping it alive after week three
The inventory under a data governance framework decays at roughly the rate the estate changes. Two habits keep it current: a five-minute inventory question in the procurement or onboarding process for any new system, and a quarterly review owned by one named person. Anything that relies on everyone remembering will not survive a busy quarter.
Classification that people will actually follow
Classification schemes fail on complexity, and they are the part of a data governance framework staff meet every day. The test is whether a new starter can classify a document correctly on their second day without asking.
Three tiers beat five
Public, Internal and Confidential covers almost every SME. Some regulated businesses add a fourth for special category data. Five tiers produce hesitation, and hesitation produces everything landing in the middle tier, which is the same as having no scheme.
Write handling rules, not adjectives
“Confidential means highly sensitive information” is not a rule. “Confidential may not be emailed outside the company, may not be stored on a personal device, and must live in the finance library with access by request” is a rule. Every tier needs storage, sharing, device and disposal rules written in plain language.
Labelling in the tools you already own
Microsoft 365 and Google Workspace both support labels that carry enforcement — blocking external sharing, applying encryption, driving retention. Turning on three labels with real rules attached delivers more of a working data governance framework than any amount of policy text, and costs nothing beyond the licences most businesses already hold.
The rule about spreadsheets
Exports are where classification collapses. The practical rule that works: an export inherits the classification of its source, and any export containing Confidential data must live in a controlled location and be deleted when the piece of work ends. Enforce it with a location, not with hope.
| Tier | Typical content | Storage and sharing rule | Disposal |
|---|---|---|---|
| Public | Marketing material, published prices, job adverts | Anywhere; external sharing permitted | No requirement |
| Internal | Process notes, project plans, internal reporting | Company systems only; sharing by named link | Delete at project close plus one year |
| Confidential | Customer records, payroll, contracts, pricing models | Controlled library; no personal devices; access by request | Per retention schedule, logged |
| Special category (optional) | Health, biometric, criminal offence data | Named individuals only; encryption enforced | Shortest defensible period, logged |
Data quality: the four measures your data governance framework should track
Quality is the component of a data governance framework that pays for the rest, because it is the one the business feels every week. Four measures are enough to start.
Completeness
The share of records that carry the fields a process actually needs. A customer record without a valid billing contact is not a partial record; it is a failed invoice. Measure completeness on the two or three fields that block work, not on every field in the schema.
Accuracy
The share of records that match reality. Bounce rates on email campaigns, returned post, failed direct debits and rejected deliveries are all free accuracy signals you already generate. Use them rather than commissioning a survey.
Duplication
Duplicate customer, supplier or contact records are the most visible quality failure and the one that most damages trust in reporting. A duplicate rate above five per cent in a CRM is common, always fixable, and one of the first numbers a data governance framework should move; above fifteen per cent, reporting has already stopped being believed.
Timeliness
How long after an event the data reflects it. A pipeline updated weekly cannot support a daily decision, and a stock figure that lags by a day will be worked around with a spreadsheet — which then becomes an ungoverned system in its own right.
Measuring it without buying a tool
Every measure above can be produced from an export and a handful of formulas in the first year. Take a baseline, write the date on it, repeat quarterly. The trend matters far more than the absolute figure, and the trend is what turns a data governance framework from an assertion into evidence. When manual measurement becomes the bottleneck, our data analytics and data management and analytics services automate it.
Retention and disposal: the fastest risk reduction in any data governance framework
Deleting data you have no reason to keep removes risk permanently, costs nothing in licence terms and is the only control in a data governance framework that makes a future breach smaller. It is also the component most often deferred, because deletion feels irreversible and nobody wants to sign it off.
The legal floor and the commercial ceiling
Retention has two bounds. The floor is statutory: six years plus the current year for most financial records, six years for most contract records under the Limitation Act, and the periods set by employment and pensions rules for staff data. The ceiling is the point where holding data creates more risk than value. The schedule is a decision about where to sit between them, made once, per record type.
A retention schedule that fits on one page
Ten to fifteen record types is enough for most SMEs: customer records, prospect and marketing data, employee files, recruitment candidates, financial records, contracts, supplier records, support tickets, security logs, backups, CCTV, and general correspondence. For each, record the period, the basis and the trigger event. The trigger is what makes the data governance framework operable — “six years from the end of the contract” can be automated; “six years” cannot.
Deletion is a process, not a button
A defensible deletion process needs three things: a scheduled trigger, a named approver for exceptions such as legal hold, and a log that records what was deleted and when. The log is what proves the schedule was followed; without it you have a policy, not a control.
Backups, archives and the awkward gap
Deleting a record from a live system does not delete it from six months of backups, and regulators accept that backups are restored as a set rather than edited. What matters is that the retention period is applied to backups too, that restores do not silently reintroduce deleted records, and that the position is documented rather than discovered during an incident. Our disaster recovery testing checklist covers the restore side of the same question.
| Record type | Typical UK retention | Trigger event | Disposal method |
|---|---|---|---|
| Financial and tax records | 6 years plus current year | End of accounting period | System purge, logged |
| Customer contracts | 6 years | End of contract term | Archive then purge, logged |
| Employee files | 6 years | End of employment | HR system deletion, logged |
| Unsuccessful candidates | 6-12 months | Role closed | Automatic deletion in ATS |
| Marketing and prospect data | Review at 24 months | Last meaningful engagement | Suppress or delete, logged |
| Support tickets | 2-3 years | Ticket closure | Bulk purge, logged |
| Security and access logs | 6-12 months | Log write date | Rolling retention policy |
| CCTV footage | 30 days | Recording date | Automatic overwrite |
Access control and third-party data sharing
A data governance framework decides who should have access; access control makes it true. The two are routinely managed by different people who never compare notes.
Role-based access as a governance control
Permissions granted person by person drift within months. Roles — sales, finance, operations, admin — with membership rather than individual grants are the only model a small team can keep accurate. The data governance framework’s contribution is the rule that access follows a role, and that exceptions expire.
Joiners, movers and leavers
Leavers are handled reasonably well because somebody wants the licence back. Movers are handled badly everywhere: people accumulate the permissions of every role they have held. A quarterly review of who holds access to Confidential systems, signed by the owner, catches it in twenty minutes. Our change management practice covers the process side of making that stick.
Processors, partners and contracts
Every third party that holds your data on your behalf needs a written contract with the required data protection terms, a defined purpose, security commitments and a deletion obligation at the end. Keep the list of processors in the same inventory as the systems — in practice they are usually the same rows. Our AI procurement checklist covers the diligence questions worth asking before signing.
International transfers
If a supplier stores or supports data outside the UK, the transfer needs a lawful mechanism and a record of the assessment. For most SMEs this is a paperwork exercise rather than an architectural one, but it must exist, and the tooling questions in our cloud exit strategy guide are worth asking at the same time.
Your data governance framework and AI: the new pressure
AI has changed the cost curve of poor governance more than any regulation. It is worth adding a small AI section to the data governance framework rather than starting a separate one.
AI inherits every problem in the data
A retrieval assistant pointed at a document library will surface exactly what the permissions allow, including the payroll spreadsheet somebody shared with everyone in 2023. Over-permissioned storage was previously a latent risk; a search-and-summarise layer converts it into an active one, immediately and at scale.
What to add to the framework
Three additions cover most of it: a rule on which classifications may be sent to which AI services, a register of AI tools that touch company data, and a requirement that any assistant with broad read access is scoped to a reviewed set of locations. Our AI system inventory template provides the register format.
Shadow AI and copy-paste leakage
The dominant real-world leak is not an integration; it is a person pasting a customer list into a consumer chatbot to reformat it. That is a classification and training problem, and it responds to a clear rule about what may leave the estate far better than to a technical block that people route around.
Tooling: what your data governance framework should buy, and what it should defer
Almost every SME already owns more data governance framework capability than it uses, and the licence is already paid for.
Start with what you already own
Microsoft 365 Business Premium includes sensitivity labels, retention policies and data loss prevention. Google Workspace has equivalents. Turning those on with three labels and a retention schedule is usually a two-day exercise that delivers most of the enforceable controls in the data governance framework.
Cloud platform services
If you run analytics on AWS, Azure or Google Cloud, each platform has a catalogue and access-governance layer worth using before buying anything independent. These matter once data is being copied into a warehouse; before that point they solve a problem you do not yet have. Our data warehousing work is where that boundary usually falls.
When a dedicated catalogue is worth it
A standalone catalogue starts to earn its cost when there are more than roughly ten analytical data sources, more than one team consuming them, or a regulatory requirement for demonstrable lineage. Below that, a maintained spreadsheet inventory is not a compromise — it is the correct tool.
Spreadsheets as a legitimate starting point
A data governance framework inventory, retention schedule and role matrix can all live in one workbook for the first year. The failure mode is not the format; it is the absence of a named owner and a review date. Add those two things and the workbook outperforms most tool deployments.
| Tier | What it covers | Indicative annual cost | Worth it when |
|---|---|---|---|
| Workbook plus existing licences | Inventory, retention, labels, access matrix | £0 beyond current spend | Under 50 staff, single office suite |
| Suite governance add-ons | Automated labelling, retention, loss prevention | £3-8 per user per month | Confidential data at volume |
| Cloud platform catalogue | Technical catalogue, lineage, fine-grained access | Consumption-based | A warehouse and multiple consumers exist |
| Dedicated governance platform | Business glossary, workflow, quality rules | £12k-40k | 10+ sources, regulated reporting |
A 90-day data governance framework implementation plan
Ninety days is enough to produce every data governance framework artefact that matters, provided the scope is fixed on day one and the sponsor holds it.
Days 1-30: sponsor, scope and inventory
Name the sponsor and the owners in week one. Agree that the first pass covers systems rather than fields, and set the boundary explicitly — for most businesses, everything holding customer, employee or financial data. Then build the inventory: one workshop per department, eight columns, twenty to forty rows. Close the month by circulating the register and letting people argue with it, which is how the missing rows appear.
Days 31-60: classification, retention and access
Agree three tiers and write the handling rules. Turn on labels in the office suite for those tiers. Draft the retention schedule and get the sponsor to approve it — this is the data governance framework decision people avoid, so it needs a date in a diary. Run the first access review across Confidential systems and close the ex-employee accounts the inventory found.
Days 61-90: quality baseline, policy and training
Take the quality baseline on the two data sets that drive decisions. Write the policy last, in three pages, describing what the previous sixty days established. Then run one thirty-minute session for everybody covering the tiers, the export rule and what to do with a data request. Book the quarterly reviews before the ninety days are up, because a data governance framework with no next date in the calendar is already decaying.
What a data governance framework costs and what it saves
The honest answer is that a data governance framework costs time rather than money in year one, and the money it saves arrives in places the budget does not label as governance.
The realistic first-year cost
For a fifty-person business doing the work internally, expect roughly fifteen to twenty-five days of effort spread across the year, concentrated in the first quarter. If a consultant runs the inventory and retention work, the market rate for that scope is typically five to twelve thousand pounds. Tooling is often zero, because the capability is inside licences already bought.
Where the savings come from
Four places, in rough order of size: storage and licence reduction after disposal; hours no longer lost to reconciling conflicting reports; faster response to subject access requests, questionnaires and audits; and reduced breach impact because there is simply less data to lose. None of these appears on a governance line, which is why the business case has to name them explicitly.
The cost of not doing it
The asymmetry is what makes the data governance framework business case. A regulatory penalty is the visible risk, but the more common costs are a lost enterprise deal because the security questionnaire could not be answered, a cyber insurance renewal priced on unknowns, three weeks of an operations manager’s life during due diligence, and decisions taken on numbers that were wrong. Our compliance and incident response services deal with the aftermath of each.
| Cost line | 20-50 staff | 50-250 staff | Notes |
|---|---|---|---|
| Internal effort, year one | 12-18 days | 25-40 days | Two thirds in the first quarter |
| External facilitation (optional) | £4k-8k | £8k-18k | Inventory and retention workshops |
| Tooling | £0-2k | £2k-15k | Often inside existing licences |
| Ongoing effort per year | 6-10 days | 12-20 days | Quarterly reviews and onboarding |
| Typical storage saving | 10-25% | 15-35% | After first disposal cycle |
Measuring whether the data governance framework is working
A data governance framework decays silently. Six numbers, reported quarterly, make the decay visible while it is still cheap to reverse.
Six metrics worth reporting
Inventory currency, expressed as the share of systems reviewed in the last quarter. Ownership coverage, the share of systems with a named, current owner. Retention execution, the number of disposal runs completed against those scheduled. Access review completion across Confidential systems. Two quality measures on the data sets that drive decisions. Request response time for subject access and similar requests. Six numbers fit on one slide.
The board-level view
Directors do not want the metrics; they want the exposure. Translate it: how many systems hold personal data, how many have no current owner, how much data is held beyond its retention period, and how long it would take to answer a regulator. Four sentences, once a quarter, is a proportionate data governance framework report for an SME board and satisfies the accountability expectation.
Reviewing the framework itself
Once a year, review the data governance framework rather than the estate: are the tiers still right, is the retention schedule still aligned to how the business operates, have the roles moved with the people. This is also where the business-IT alignment question belongs — a framework that no longer matches how decisions are actually made will be routed around within months.
Data governance framework failure modes and how to avoid them
The same five failures account for most abandoned data governance framework attempts, and each has a cheap countermeasure.
The policy nobody reads
Symptom: a signed twenty-page document and no change in behaviour. Cause: writing the policy first. Countermeasure: write it last, in three pages, describing decisions already made and controls already turned on.
The inventory that ages out
Symptom: a register accurate for six weeks. Cause: no owner and no trigger. Countermeasure: one named owner, a quarterly review date in a calendar, and an inventory question in the procurement of any new system.
Governance run as an IT project
Symptom: technically correct rules the business ignores. Cause: owners assigned in IT rather than in the departments that create the data. Countermeasure: business owners decide, IT implements, and the sponsor is a director rather than a technician.
Boiling the ocean
Symptom: nine months of cataloguing with nothing to show. Cause: field-level scope on the first pass. Countermeasure: systems not fields, three tiers not five, ten record types not fifty. A narrow data governance framework that is finished beats a comprehensive one that is not.
The one-person dependency
Symptom: the whole thing pauses when one person is on leave. Cause: stewardship concentrated in a single enthusiast. Countermeasure: two named people per data governance framework artefact, and everything stored where the business can reach it rather than in a personal drive.
Data governance framework: frequently asked questions
How small is too small to need one?
If you hold customer or employee records in more than one system, you already need the inventory and the retention schedule. Below roughly ten people a full data governance framework is disproportionate, but those two artefacts still are not — they take a day and answer most of what anyone will ever ask you.
Do we need a data protection officer?
Most SMEs do not meet the statutory test, which turns on public authority status, large-scale systematic monitoring or large-scale special category processing. Everyone needs a named accountable person regardless. The ICO’s guidance for small organisations is the right place to check your specific position.
How does this relate to ISO 27001 or Cyber Essentials?
They overlap but answer different questions. Cyber Essentials and ISO 27001 ask whether data is protected; a data governance framework also asks whether it is correct, whether it should still exist and who is allowed to decide. Businesses pursuing certification find the data governance framework inventory and asset ownership work transfers directly.
Who should own the retention schedule?
Usually finance or the company secretary, because most statutory retention periods are financial or corporate, and because that role is comfortable with a decision that has a legal basis. The owner of each system executes it; one person owns the schedule itself.
What is the first thing to do on Monday?
List the systems that hold personal data and put a name next to each one. It takes about two hours, needs no budget or approval, and it is the artefact everything else in the data governance framework is built on.
How long before it is worth anything?
A data governance framework inventory pays back immediately, because it answers questionnaires and due diligence. Retention pays back within one disposal cycle. Quality improvement is the slowest, typically two to three quarters before the trend is convincing enough to change how people treat reporting.
Should we hire someone for this?
Almost never at SME scale. Data governance framework work is a fraction of a role, and the decisions have to be made by people who already own the business processes. External help is most useful for facilitating the inventory and drafting the retention schedule — the two tasks that stall internally because they need someone to hold the room.
What if we are about to migrate systems?
Do the inventory first. A migration is the cheapest possible moment to apply retention, because you decide what to carry across rather than what to delete, and nobody has to sign off destroying anything. Migrating an ungoverned estate simply reproduces it somewhere more expensive.
References
ICO: UK GDPR Guidance and Resources
ICO: Advice for Small Organisations
ICO: Accountability and Governance
ICO: Data Protection Impact Assessments
ICO: Controllers and Processors
ICO: Reporting a Personal Data Breach
ICO: Artificial Intelligence Guidance
GOV.UK: Technology Code of Practice
GOV.UK: Cyber Security Breaches Survey 2025
NCSC: 10 Steps to Cyber Security
NCSC: Cyber Security Board Toolkit
NCSC: Risk Management Collection
NCSC: Cyber Essentials Overview
NIST SP 800-53 Rev. 5: Security and Privacy Controls
NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
NIST SP 800-92: Guide to Computer Security Log Management
NIST AI Risk Management Framework
DAMA International: Data Management Body of Knowledge
EDM Council: Data Management Capability Assessment Model
European Commission: Regulatory Framework for AI
Microsoft Purview Documentation
Microsoft Purview: Sensitivity Labels
Microsoft Purview: Retention Policies
Microsoft Purview: Data Loss Prevention