Data governance framework design sounds like an enterprise problem, and for a long time it was. Large organisations hired stewards, bought catalogues and wrote hundred-page policies while everybody else simply got on with the work. That distinction has quietly collapsed. A thirty-person business today runs a CRM, a finance system, a shared drive, a payroll platform, a marketing tool, three integrations nobody documented and a steadily growing pile of exports sitting in personal folders — and it carries the same legal duties over that data as an organisation a hundred times its size.

The gap is not ambition. It is that almost every published data governance framework assumes a team that does not exist. A small business does not have a chief data officer, a stewardship council or a budget line for metadata tooling. It has an operations manager who already does three jobs, an outsourced IT provider and a director who wants to know why the customer list in the CRM disagrees with the one in the accounts package. A data governance framework has to fit around those people or it does not happen at all.

This guide is written for that reality. It covers what belongs in a data governance framework for a business of ten to two hundred and fifty people, who owns each part, how to build the inventory without stalling, what to classify and what to ignore, how to set retention that survives audit, what it costs, and a ninety-day plan that produces something real rather than a policy nobody reads. Our cybersecurity and data protection practices sit underneath the controls described here, and our IT governance work is where the accountability side usually starts.

Why a data governance framework matters more for SMEs than for enterprises

data governance framework for smes b four rising blank columns

The intuition runs the other way — big organisation, big problem — and on the question of a data governance framework it is wrong in every way that matters commercially.

Small teams carry identical legal duties

UK GDPR and the Data Protection Act 2018 make almost no allowance for headcount. The obligations to hold accurate records, keep data no longer than necessary, respond to a subject access request within a month and report a qualifying breach within seventy-two hours apply to a five-person consultancy exactly as they apply to a supermarket chain. A data governance framework is simply the cheapest way to be able to answer those obligations without a fire drill each time.

One person usually holds the whole map

In most small businesses, the knowledge of which system holds what, which export feeds which report and which spreadsheet is authoritative lives in one head. That is a single point of failure with no redundancy, no backup and a notice period. Writing it down is the single highest-return governance activity available, and it is what a data governance framework forces.

Growth turns tolerable mess into genuine risk

Twelve customers in a spreadsheet is a filing habit. Twelve thousand is a regulated asset. The transition happens without an announcement, and the practices that were sensible at the start — everyone can see everything, exports live on the desktop, nothing is ever deleted — become the exact findings an auditor, an insurer or an acquirer will write down, and the exact gaps a data governance framework is built to close.

Due diligence now asks the question directly

Cyber insurance renewals, enterprise customer onboarding, supplier questionnaires and acquisition due diligence all now include data handling questions. A business with a documented data governance framework answers them in an afternoon. A business without one spends three weeks reconstructing the answers and still discloses gaps it did not know it had.

AI has raised the cost of ungoverned data

Every assistant, copilot and automation you connect inherits whatever mess it is pointed at, because none of them can infer a data governance framework you never wrote. Ungoverned data used to produce bad reports slowly; it now produces confident, fast, wrong answers at scale, and it exposes anything over-shared to a much wider audience. Our guide to an AI governance framework for SMEs covers the model side; this article covers the data underneath it.

What a data governance framework actually is, and what it is not

data governance framework for smes c closed padlock on plinth

Most of the confusion about a data governance framework is definitional, and that confusion is what makes people buy the wrong thing.

It is a set of decisions, not a document

A data governance framework is the answer to five questions: who owns each data set, what each classification of data is allowed to be used for, how long it is kept, who may access it, and how anyone knows whether the answers are still true. The policy document records those answers. The answers are the framework; the document is the receipt.

It is not a tool purchase

Cataloguing, lineage and quality tools are useful once the decisions exist. Bought before the data governance framework exists, they produce an expensive inventory of an ungoverned estate. The order matters: decide, document, then automate the parts that are painful to maintain by hand.

It is not the same as data protection compliance

Compliance is a subset. A data governance framework also covers commercially sensitive data with no personal element — pricing models, source code, supplier terms, board papers — and it covers quality and usefulness, which the regulation says almost nothing about. Treating the two as identical produces a framework that protects personal data and ignores the intellectual property that funds the business.

It is not a one-off project

The estate changes every month. A data governance framework that is not reviewed becomes a description of a business that no longer exists, which is worse than no framework at all because it creates false assurance.

Common beliefWhat is actually trueConsequence of the belief
Governance means buying a catalogueGovernance means assigning owners and rulesLicence spend with no behaviour change
It is the IT department’s jobOwners sit in the business, IT operates controlsRules nobody in operations accepts
We are too small to need itDuties are identical; only resources differBreach, fine or lost deal discovers it for you
Compliance covers itCompliance ignores quality and commercial dataProtected personal data, unmanaged everything else
We will do it after the migrationMigration is the cheapest moment to do itThe mess is copied into the new platform
A policy document is the deliverableThe inventory and retention schedule areA signed policy with no operational effect

The six components of an SME data governance framework

data governance framework for smes d single hourglass on plinth

Enterprise models list eleven or twelve disciplines. In a data governance framework built for a business under two hundred and fifty people, six components carry almost all the value, and each has a version small enough to finish.

Ownership and accountability

Every significant data set in the data governance framework has one named owner who is accountable for who may use it, how long it is kept and whether it is correct. Owners are business people, not IT people: the sales director owns the customer record, the finance manager owns the ledger, the operations lead owns supplier data.

An inventory you can actually maintain

A list of the systems that hold data, what they hold, who owns them, where they sit and what feeds in and out. Systems, not fields. A twenty-row table beats a two-thousand-row one nobody updates.

Classification and handling rules

Two or three tiers with concrete handling rules attached. The tier is meaningless; the rule attached to it is the control.

Quality standards and measurement

A small number of measures — completeness, accuracy, duplication, timeliness — with a baseline and a target for the data sets that drive decisions.

Retention and disposal

How long each record type is kept, on what basis, and how it is actually destroyed when the clock runs out. This is the component of a data governance framework that reduces risk fastest, and the one most often skipped.

Access, sharing and third parties

Who may see what, how that is granted and removed, and what happens when data leaves the building for a processor, a partner or an analytics tool.

ComponentMinimum viable versionUsual ownerEvidence it exists
OwnershipOne named owner per systemSponsor assignsOwner column in the inventory
Inventory20-40 rows, one per systemOperations or IT leadDated register with a review date
ClassificationThree tiers with handling rulesData owners jointlyOne-page handling table
QualityFour measures on two data setsOwner of each data setBaseline figures with a date
RetentionOne-page schedule by record typeFinance or company secretarySchedule plus deletion log
Access and sharingRole matrix plus processor listIT with owner sign-offQuarterly access review record

Data governance framework roles: who owns what in a small organisation

data governance framework for smes e three upright cylinders row

Data governance framework role models fail in small businesses because they assume the roles are jobs. In a thirty-person firm they are hats, and one person often wears three. Naming them still matters, because unnamed accountability defaults to nobody.

The sponsor

A director who owns the data governance framework’s existence, approves the classification tiers and the retention schedule, and settles disputes between owners. Without a sponsor the work stalls the first time it collides with a sales deadline. Expect two hours a month.

Data owners

Two to five people who own the main data sets. They decide access, approve new uses, and sign off retention. They do not do the work; they make the decisions the work implements. Expect an hour a month each.

Data stewards

The people who actually maintain quality in a system — the person who cleans the CRM, the one who reconciles the ledger. Usually already doing it informally. The data governance framework simply names them and gives them authority to reject bad input.

The IT or provider role

Implements the controls: permissions, labelling, logging, backup, deletion tooling. This may be an internal person or your managed provider. If it is a provider, the responsibilities belong in the contract, not in an email.

The data protection role

Someone accountable for the regulatory side: the record of processing, subject access requests, breach reporting and impact assessments. Most SMEs do not need a statutory data protection officer, but everyone needs a named person, and pretending the role is distributed means it is absent.

RoleWho it usually is in a 30-person firmTime per monthDecides
SponsorManaging director or finance director2 hoursScope, tiers, retention, disputes
Data ownerHead of sales, finance manager, ops lead1 hour eachAccess, permitted uses, sign-off
Data stewardCRM administrator, credit controller2-4 hours eachWhat counts as a valid record
IT or providerInternal IT lead or managed provider4-6 hoursHow controls are implemented
Data protection leadOperations manager or company secretary2-3 hoursLawful basis, requests, breaches

Building the inventory your data governance framework depends on

data governance framework for smes f single funnel on plinth

The inventory is where most data governance framework attempts die, because they are scoped as a data discovery exercise rather than a system list. Scope it as systems and it takes a fortnight.

Start with systems, not fields

List every place data lives: SaaS applications, servers, shared drives, mailboxes, databases, backups, and the two or three departmental spreadsheets everybody relies on. A business of thirty people typically lands between twenty-five and forty rows. Field-level cataloguing can wait years, and for most SMEs forever.

The eight questions per system

For each row, answer: what does it hold, who owns it, who administers it, roughly how many records, what classification, how long is it kept, what feeds it, and what does it feed. Eight columns, one afternoon per department. Anything more detailed will not be maintained.

Where the surprises always are

Three places produce findings in almost every engagement: mailboxes holding years of attachments with personal data, ex-employee accounts and their OneDrive or Google Drive contents, and analytics or marketing tools that quietly hold a copy of the customer base. Departed staff accounts are the most common single finding, and closing them is often the fastest risk reduction available. Our IT asset management approach catches the hardware side of the same problem.

Keeping it alive after week three

The inventory under a data governance framework decays at roughly the rate the estate changes. Two habits keep it current: a five-minute inventory question in the procurement or onboarding process for any new system, and a quarterly review owned by one named person. Anything that relies on everyone remembering will not survive a busy quarter.

Where SME records are typically found during a first inventory
Core business systems (CRM, finance, HR) 41%
Shared drives and document libraries 27%
Mailboxes and attachments 16%
Departmental spreadsheets and exports 11%
Marketing and analytics platforms 5%
Indicative distribution of record-holding locations found in first-pass SME inventories.

Classification that people will actually follow

Classification schemes fail on complexity, and they are the part of a data governance framework staff meet every day. The test is whether a new starter can classify a document correctly on their second day without asking.

Three tiers beat five

Public, Internal and Confidential covers almost every SME. Some regulated businesses add a fourth for special category data. Five tiers produce hesitation, and hesitation produces everything landing in the middle tier, which is the same as having no scheme.

Write handling rules, not adjectives

“Confidential means highly sensitive information” is not a rule. “Confidential may not be emailed outside the company, may not be stored on a personal device, and must live in the finance library with access by request” is a rule. Every tier needs storage, sharing, device and disposal rules written in plain language.

Labelling in the tools you already own

Microsoft 365 and Google Workspace both support labels that carry enforcement — blocking external sharing, applying encryption, driving retention. Turning on three labels with real rules attached delivers more of a working data governance framework than any amount of policy text, and costs nothing beyond the licences most businesses already hold.

The rule about spreadsheets

Exports are where classification collapses. The practical rule that works: an export inherits the classification of its source, and any export containing Confidential data must live in a controlled location and be deleted when the piece of work ends. Enforce it with a location, not with hope.

TierTypical contentStorage and sharing ruleDisposal
PublicMarketing material, published prices, job advertsAnywhere; external sharing permittedNo requirement
InternalProcess notes, project plans, internal reportingCompany systems only; sharing by named linkDelete at project close plus one year
ConfidentialCustomer records, payroll, contracts, pricing modelsControlled library; no personal devices; access by requestPer retention schedule, logged
Special category (optional)Health, biometric, criminal offence dataNamed individuals only; encryption enforcedShortest defensible period, logged

Data quality: the four measures your data governance framework should track

Quality is the component of a data governance framework that pays for the rest, because it is the one the business feels every week. Four measures are enough to start.

Completeness

The share of records that carry the fields a process actually needs. A customer record without a valid billing contact is not a partial record; it is a failed invoice. Measure completeness on the two or three fields that block work, not on every field in the schema.

Accuracy

The share of records that match reality. Bounce rates on email campaigns, returned post, failed direct debits and rejected deliveries are all free accuracy signals you already generate. Use them rather than commissioning a survey.

Duplication

Duplicate customer, supplier or contact records are the most visible quality failure and the one that most damages trust in reporting. A duplicate rate above five per cent in a CRM is common, always fixable, and one of the first numbers a data governance framework should move; above fifteen per cent, reporting has already stopped being believed.

Timeliness

How long after an event the data reflects it. A pipeline updated weekly cannot support a daily decision, and a stock figure that lags by a day will be worked around with a spreadsheet — which then becomes an ungoverned system in its own right.

Measuring it without buying a tool

Every measure above can be produced from an export and a handful of formulas in the first year. Take a baseline, write the date on it, repeat quarterly. The trend matters far more than the absolute figure, and the trend is what turns a data governance framework from an assertion into evidence. When manual measurement becomes the bottleneck, our data analytics and data management and analytics services automate it.

Typical SME data quality: baseline versus six months of stewardship
Contact completeness at baseline 68%
Contact completeness after six months 91%
Duplicate records at baseline 12%
Duplicate records after six months 3%
Indicative movement seen where ownership and stewardship are assigned and measured quarterly.

Retention and disposal: the fastest risk reduction in any data governance framework

Deleting data you have no reason to keep removes risk permanently, costs nothing in licence terms and is the only control in a data governance framework that makes a future breach smaller. It is also the component most often deferred, because deletion feels irreversible and nobody wants to sign it off.

The legal floor and the commercial ceiling

Retention has two bounds. The floor is statutory: six years plus the current year for most financial records, six years for most contract records under the Limitation Act, and the periods set by employment and pensions rules for staff data. The ceiling is the point where holding data creates more risk than value. The schedule is a decision about where to sit between them, made once, per record type.

A retention schedule that fits on one page

Ten to fifteen record types is enough for most SMEs: customer records, prospect and marketing data, employee files, recruitment candidates, financial records, contracts, supplier records, support tickets, security logs, backups, CCTV, and general correspondence. For each, record the period, the basis and the trigger event. The trigger is what makes the data governance framework operable — “six years from the end of the contract” can be automated; “six years” cannot.

Deletion is a process, not a button

A defensible deletion process needs three things: a scheduled trigger, a named approver for exceptions such as legal hold, and a log that records what was deleted and when. The log is what proves the schedule was followed; without it you have a policy, not a control.

Backups, archives and the awkward gap

Deleting a record from a live system does not delete it from six months of backups, and regulators accept that backups are restored as a set rather than edited. What matters is that the retention period is applied to backups too, that restores do not silently reintroduce deleted records, and that the position is documented rather than discovered during an incident. Our disaster recovery testing checklist covers the restore side of the same question.

Record typeTypical UK retentionTrigger eventDisposal method
Financial and tax records6 years plus current yearEnd of accounting periodSystem purge, logged
Customer contracts6 yearsEnd of contract termArchive then purge, logged
Employee files6 yearsEnd of employmentHR system deletion, logged
Unsuccessful candidates6-12 monthsRole closedAutomatic deletion in ATS
Marketing and prospect dataReview at 24 monthsLast meaningful engagementSuppress or delete, logged
Support tickets2-3 yearsTicket closureBulk purge, logged
Security and access logs6-12 monthsLog write dateRolling retention policy
CCTV footage30 daysRecording dateAutomatic overwrite

Access control and third-party data sharing

A data governance framework decides who should have access; access control makes it true. The two are routinely managed by different people who never compare notes.

Role-based access as a governance control

Permissions granted person by person drift within months. Roles — sales, finance, operations, admin — with membership rather than individual grants are the only model a small team can keep accurate. The data governance framework’s contribution is the rule that access follows a role, and that exceptions expire.

Joiners, movers and leavers

Leavers are handled reasonably well because somebody wants the licence back. Movers are handled badly everywhere: people accumulate the permissions of every role they have held. A quarterly review of who holds access to Confidential systems, signed by the owner, catches it in twenty minutes. Our change management practice covers the process side of making that stick.

Processors, partners and contracts

Every third party that holds your data on your behalf needs a written contract with the required data protection terms, a defined purpose, security commitments and a deletion obligation at the end. Keep the list of processors in the same inventory as the systems — in practice they are usually the same rows. Our AI procurement checklist covers the diligence questions worth asking before signing.

International transfers

If a supplier stores or supports data outside the UK, the transfer needs a lawful mechanism and a record of the assessment. For most SMEs this is a paperwork exercise rather than an architectural one, but it must exist, and the tooling questions in our cloud exit strategy guide are worth asking at the same time.

Your data governance framework and AI: the new pressure

AI has changed the cost curve of poor governance more than any regulation. It is worth adding a small AI section to the data governance framework rather than starting a separate one.

AI inherits every problem in the data

A retrieval assistant pointed at a document library will surface exactly what the permissions allow, including the payroll spreadsheet somebody shared with everyone in 2023. Over-permissioned storage was previously a latent risk; a search-and-summarise layer converts it into an active one, immediately and at scale.

What to add to the framework

Three additions cover most of it: a rule on which classifications may be sent to which AI services, a register of AI tools that touch company data, and a requirement that any assistant with broad read access is scoped to a reviewed set of locations. Our AI system inventory template provides the register format.

Shadow AI and copy-paste leakage

The dominant real-world leak is not an integration; it is a person pasting a customer list into a consumer chatbot to reformat it. That is a classification and training problem, and it responds to a clear rule about what may leave the estate far better than to a technical block that people route around.

Tooling: what your data governance framework should buy, and what it should defer

Almost every SME already owns more data governance framework capability than it uses, and the licence is already paid for.

Start with what you already own

Microsoft 365 Business Premium includes sensitivity labels, retention policies and data loss prevention. Google Workspace has equivalents. Turning those on with three labels and a retention schedule is usually a two-day exercise that delivers most of the enforceable controls in the data governance framework.

Cloud platform services

If you run analytics on AWS, Azure or Google Cloud, each platform has a catalogue and access-governance layer worth using before buying anything independent. These matter once data is being copied into a warehouse; before that point they solve a problem you do not yet have. Our data warehousing work is where that boundary usually falls.

When a dedicated catalogue is worth it

A standalone catalogue starts to earn its cost when there are more than roughly ten analytical data sources, more than one team consuming them, or a regulatory requirement for demonstrable lineage. Below that, a maintained spreadsheet inventory is not a compromise — it is the correct tool.

Spreadsheets as a legitimate starting point

A data governance framework inventory, retention schedule and role matrix can all live in one workbook for the first year. The failure mode is not the format; it is the absence of a named owner and a review date. Add those two things and the workbook outperforms most tool deployments.

TierWhat it coversIndicative annual costWorth it when
Workbook plus existing licencesInventory, retention, labels, access matrix£0 beyond current spendUnder 50 staff, single office suite
Suite governance add-onsAutomated labelling, retention, loss prevention£3-8 per user per monthConfidential data at volume
Cloud platform catalogueTechnical catalogue, lineage, fine-grained accessConsumption-basedA warehouse and multiple consumers exist
Dedicated governance platformBusiness glossary, workflow, quality rules£12k-40k10+ sources, regulated reporting

A 90-day data governance framework implementation plan

Ninety days is enough to produce every data governance framework artefact that matters, provided the scope is fixed on day one and the sponsor holds it.

Days 1-30: sponsor, scope and inventory

Name the sponsor and the owners in week one. Agree that the first pass covers systems rather than fields, and set the boundary explicitly — for most businesses, everything holding customer, employee or financial data. Then build the inventory: one workshop per department, eight columns, twenty to forty rows. Close the month by circulating the register and letting people argue with it, which is how the missing rows appear.

Days 31-60: classification, retention and access

Agree three tiers and write the handling rules. Turn on labels in the office suite for those tiers. Draft the retention schedule and get the sponsor to approve it — this is the data governance framework decision people avoid, so it needs a date in a diary. Run the first access review across Confidential systems and close the ex-employee accounts the inventory found.

Days 61-90: quality baseline, policy and training

Take the quality baseline on the two data sets that drive decisions. Write the policy last, in three pages, describing what the previous sixty days established. Then run one thirty-minute session for everybody covering the tiers, the export rule and what to do with a data request. Book the quarterly reviews before the ninety days are up, because a data governance framework with no next date in the calendar is already decaying.

Where the effort actually goes across a 90-day rollout
Inventory workshops and follow-up 34%
Retention schedule and sign-off 22%
Labels, permissions and access review 21%
Quality baseline measurement 13%
Policy writing and training 10%
Policy writing is the smallest line and the one most plans allocate first.

What a data governance framework costs and what it saves

The honest answer is that a data governance framework costs time rather than money in year one, and the money it saves arrives in places the budget does not label as governance.

The realistic first-year cost

For a fifty-person business doing the work internally, expect roughly fifteen to twenty-five days of effort spread across the year, concentrated in the first quarter. If a consultant runs the inventory and retention work, the market rate for that scope is typically five to twelve thousand pounds. Tooling is often zero, because the capability is inside licences already bought.

Where the savings come from

Four places, in rough order of size: storage and licence reduction after disposal; hours no longer lost to reconciling conflicting reports; faster response to subject access requests, questionnaires and audits; and reduced breach impact because there is simply less data to lose. None of these appears on a governance line, which is why the business case has to name them explicitly.

The cost of not doing it

The asymmetry is what makes the data governance framework business case. A regulatory penalty is the visible risk, but the more common costs are a lost enterprise deal because the security questionnaire could not be answered, a cyber insurance renewal priced on unknowns, three weeks of an operations manager’s life during due diligence, and decisions taken on numbers that were wrong. Our compliance and incident response services deal with the aftermath of each.

Cost line20-50 staff50-250 staffNotes
Internal effort, year one12-18 days25-40 daysTwo thirds in the first quarter
External facilitation (optional)£4k-8k£8k-18kInventory and retention workshops
Tooling£0-2k£2k-15kOften inside existing licences
Ongoing effort per year6-10 days12-20 daysQuarterly reviews and onboarding
Typical storage saving10-25%15-35%After first disposal cycle

Measuring whether the data governance framework is working

A data governance framework decays silently. Six numbers, reported quarterly, make the decay visible while it is still cheap to reverse.

Six metrics worth reporting

Inventory currency, expressed as the share of systems reviewed in the last quarter. Ownership coverage, the share of systems with a named, current owner. Retention execution, the number of disposal runs completed against those scheduled. Access review completion across Confidential systems. Two quality measures on the data sets that drive decisions. Request response time for subject access and similar requests. Six numbers fit on one slide.

The board-level view

Directors do not want the metrics; they want the exposure. Translate it: how many systems hold personal data, how many have no current owner, how much data is held beyond its retention period, and how long it would take to answer a regulator. Four sentences, once a quarter, is a proportionate data governance framework report for an SME board and satisfies the accountability expectation.

Reviewing the framework itself

Once a year, review the data governance framework rather than the estate: are the tiers still right, is the retention schedule still aligned to how the business operates, have the roles moved with the people. This is also where the business-IT alignment question belongs — a framework that no longer matches how decisions are actually made will be routed around within months.

Data governance framework failure modes and how to avoid them

The same five failures account for most abandoned data governance framework attempts, and each has a cheap countermeasure.

The policy nobody reads

Symptom: a signed twenty-page document and no change in behaviour. Cause: writing the policy first. Countermeasure: write it last, in three pages, describing decisions already made and controls already turned on.

The inventory that ages out

Symptom: a register accurate for six weeks. Cause: no owner and no trigger. Countermeasure: one named owner, a quarterly review date in a calendar, and an inventory question in the procurement of any new system.

Governance run as an IT project

Symptom: technically correct rules the business ignores. Cause: owners assigned in IT rather than in the departments that create the data. Countermeasure: business owners decide, IT implements, and the sponsor is a director rather than a technician.

Boiling the ocean

Symptom: nine months of cataloguing with nothing to show. Cause: field-level scope on the first pass. Countermeasure: systems not fields, three tiers not five, ten record types not fifty. A narrow data governance framework that is finished beats a comprehensive one that is not.

The one-person dependency

Symptom: the whole thing pauses when one person is on leave. Cause: stewardship concentrated in a single enthusiast. Countermeasure: two named people per data governance framework artefact, and everything stored where the business can reach it rather than in a personal drive.

Data governance framework: frequently asked questions

How small is too small to need one?

If you hold customer or employee records in more than one system, you already need the inventory and the retention schedule. Below roughly ten people a full data governance framework is disproportionate, but those two artefacts still are not — they take a day and answer most of what anyone will ever ask you.

Do we need a data protection officer?

Most SMEs do not meet the statutory test, which turns on public authority status, large-scale systematic monitoring or large-scale special category processing. Everyone needs a named accountable person regardless. The ICO’s guidance for small organisations is the right place to check your specific position.

How does this relate to ISO 27001 or Cyber Essentials?

They overlap but answer different questions. Cyber Essentials and ISO 27001 ask whether data is protected; a data governance framework also asks whether it is correct, whether it should still exist and who is allowed to decide. Businesses pursuing certification find the data governance framework inventory and asset ownership work transfers directly.

Who should own the retention schedule?

Usually finance or the company secretary, because most statutory retention periods are financial or corporate, and because that role is comfortable with a decision that has a legal basis. The owner of each system executes it; one person owns the schedule itself.

What is the first thing to do on Monday?

List the systems that hold personal data and put a name next to each one. It takes about two hours, needs no budget or approval, and it is the artefact everything else in the data governance framework is built on.

How long before it is worth anything?

A data governance framework inventory pays back immediately, because it answers questionnaires and due diligence. Retention pays back within one disposal cycle. Quality improvement is the slowest, typically two to three quarters before the trend is convincing enough to change how people treat reporting.

Should we hire someone for this?

Almost never at SME scale. Data governance framework work is a fraction of a role, and the decisions have to be made by people who already own the business processes. External help is most useful for facilitating the inventory and drafting the retention schedule — the two tasks that stall internally because they need someone to hold the room.

What if we are about to migrate systems?

Do the inventory first. A migration is the cheapest possible moment to apply retention, because you decide what to carry across rather than what to delete, and nobody has to sign off destroying anything. Migrating an ungoverned estate simply reproduces it somewhere more expensive.

References