How to implement data governance in your company?
Implementing data governance means clarifying who owns data, what quality rules apply, and how compliance obligations (GDPR, CSRD) are met. A 7-step method and practical insights from advisory missions.
Expert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.
Implementing data governance is not about creating another steering committee. It means organising, in a lasting way, who can create, modify, use, share or delete data, under what rules, and with what controls. In 2026, the subject is pressing for SMEs and mid-sized companies for at least four simultaneous reasons: GDPR compliance obligations, the expansion of sustainability reporting under CSRD, the proliferation of digital tools, and increasing use of AI on data whose reliability is not always guaranteed.
A company that generates large volumes of data without clear governance tends to lose confidence in its own figures. Two dashboards return contradictory results, indicator definitions vary across teams, and overly broad access rights allow sensitive data to circulate without adequate control. Data governance is not a large-group luxury. It is a precondition for reliable management, compliance, and sound decision-making.
Data governance is first and foremost a matter of organisation and accountability, not an IT project. Clear, simple rules that are actually followed over time are worth more than an ambitious framework that teams never adopt.
Where to begin when starting from scratch?#
The first mistake is trying to map everything before assigning responsibilities. In advisory mandates, the most effective starting point is always the same: identify the data that is already causing problems.
Practical warning signals include contradictory figures across tools, indicators that no one can explain consistently, sensitive data accessible too broadly, or ESG and financial reporting whose definitions shift depending on the person asked. These are the friction points that justify governance — not a theoretical ambition.
The recommended starting sequence: identify two or three priority areas, appoint a responsible owner for each, and formalise the first rules on those perimeters before attempting full coverage.
Is a DPO mandatory to implement data governance under GDPR?#
No. The Data Protection Officer (DPO) is not required for every organisation. Article 37 of GDPR (Regulation EU 2016/679) sets out three cases where designation is mandatory:
- Public authorities and bodies (except courts acting in their judicial capacity).
- Controllers or processors who carry out large-scale regular and systematic monitoring of individuals.
- Those who process, at large scale, special categories of data (health, ethnic origin, biometrics, etc.) or data relating to criminal convictions.
There is no employee headcount threshold. A ten-person medical practice may be subject to the obligation, while a 150-person industrial SME may not be, depending on the nature of processing. The DPO may be internal, external, or shared between multiple organisations. The CNIL maintains a list of declared external DPOs.
What this means in practice: an SME not subject to mandatory DPO designation is not exempt from GDPR. The processing register remains mandatory (Art. 30), and a Data Protection Impact Assessment (DPIA, Art. 35) is required whenever a processing operation is likely to result in a high risk to individuals' rights and freedoms. Voluntary designation of a DPO or a dedicated GDPR referent is advisable once processing activities become complex or involve sensitive data.
Which roles to define in a data governance framework?#
Data governance rests on a few key roles. The table below summarises the main functions to define, whether in a 50-person SME or a 500-person mid-market company:
| Role | Primary mission | Typical profile |
|---|---|---|
| Data owner | Sets usage, quality, and access rules for a data domain | CFO, CCO, CHRO depending on scope |
| Data steward | Applies rules, monitors quality, manages corrections day-to-day | Management controller, CRM manager, payroll manager |
| DPO / GDPR referent | Ensures processing compliance, maintains the register, coordinates DPIAs | Legal counsel, external DPO, compliance officer |
| IT / CISO | Manages technical permissions, backups, and system security | Head of IT or information systems |
| Governance committee | Arbitrates definition conflicts, validates changes, oversees reviews | Executive + data owners + IT |
In an SME context, these roles are often combined. What matters is not the org chart but the clarity of who decides what on each critical data domain.
7-step method for implementing data governance#
The recommended sequence for getting started without over-engineering:
-
Identify critical data. Not all data carries equal weight. Start with data that serves management, compliance, customer relations, or payroll: revenue, stock, HR data, customer data, ESG indicators, sensitive data.
-
Appoint responsible owners per domain. Each important data block needs an identified data owner. Without a named owner, rules remain theoretical.
-
Set minimum quality rules. What constitutes a complete record? Who can correct data? How is a modification traced? When is data archived? These simple questions have significant practical impact.
-
Map flows and access. Establish where data originates, who transforms it, which tools it passes through, who accesses it, and for what purposes. For personal data, this mapping forms the basis of the mandatory processing register (Art. 30 GDPR).
-
Document essential definitions. Revenue, active customer, margin, headcount, or an ESG indicator cannot mean different things in different teams. These definitions must be written down, shared, and kept current.
-
Integrate security and compliance. Governance extends beyond quality. It covers access rights, confidentiality, retention periods, GDPR obligations, and, where applicable, DPIA requirements. For high-risk processing, a DPIA (Art. 35 GDPR) is mandatory before implementation.
-
Establish periodic review. Governance is not a one-time deliverable. It is a discipline to maintain, particularly when tools, processes, or organisational structures change. A minimum annual review is recommended.
GDPR compliance: what data governance must address#
GDPR formalises several requirements that are intrinsic to sound data governance.
The processing register (Art. 30) is the central instrument: it records processing activities involving personal data, their purposes, data categories, recipients, retention periods, and security measures. It must be kept current and made available to the CNIL upon inspection.
The DPIA (Art. 35) is mandatory before implementing any processing operation likely to result in a high risk to individuals. The CNIL publishes a list of processing types for which a DPIA is systematically required.
Sanctions for serious breaches reach up to 20 million euros or 4% of annual global turnover, whichever is higher. This level applies to the most significant violations (no legal basis, breach of data subjects' rights, unlawful transfers). Lower sanctions apply to formal obligations (absent register, missing mandatory DPO, etc.).
Data governance and CSRD: an increasingly important intersection#
The CSRD directive and its ESRS standards (in particular the ESRS GOV framework) require companies to document how sustainability information is governed and who is accountable for it. Concretely, this means that E, S, and G indicators must rest on stable definitions, identified sources, documented perimeters, and validation processes.
These are exactly the same requirements as good internal data governance: identified owners, quality rules, flow mapping, periodic review. Companies that have already built data governance handle CSRD audits with significantly less friction. Those that produce ESG indicators on an ad hoc basis, without traceability or designated owners, encounter difficulties as soon as a sustainability auditor arrives.
For further reading, see our articles on ESG reporting and organisational audit.
Common mistakes to avoid#
The most frequently observed pitfalls when implementing data governance are:
- Believing that a new data management tool will resolve organisational problems by itself. A tool amplifies an organisation; it does not replace it.
- Launching a governance committee before clarifying actual responsibilities. Meetings multiply, decisions do not get made.
- Over-documenting at the start and losing teams in complexity.
- Omitting sensitive data and access rights from the initial mapping.
- Treating governance as a purely technical subject without management and business unit involvement.
- Setting up governance without a revision mechanism: within twelve months, tools change, teams evolve, and rules become stale.
How to keep data governance alive over time#
The greatest risk is not a poor start. It is framing governance well at launch and then letting practices drift back to ambiguity. Useful data governance is sustained through a small number of regular practices:
- Annual review of access permissions for sensitive data.
- Periodic quality checks on critical datasets.
- Update of definitions and the processing register whenever a tool or process changes.
- Documented tracking of data incidents and anomalies.
- Clear arbitration when an indicator becomes strategic for management or reporting purposes.
This approach avoids two equally damaging extremes: forgotten governance and bureaucratic governance. The right level is the one that sustains confidence in data without unnecessarily slowing down operational teams.
Our view: what actually makes a difference#
The companies that derive the most value from data governance share three characteristics: senior management is involved (not only IT), definitions are established before tools are selected, and governance is connected to a concrete business objective — GDPR compliance, reporting reliability, CSRD preparation, or an AI project.
Projects that fail, by contrast, remain confined to IT, exclude business decision-makers, and attempt to cover the entire data landscape from day one. Starting small, on the data that is already causing problems, with named owners and rules that are actually followed: that is the sequence that works.
To connect your data governance to your broader digital transformation strategy, see our digital finance transformation for SMEs and our compliance audit service.
Important note: this article sets out general principles of data governance and applicable legal obligations. It does not constitute personalised legal advice. For questions relating to GDPR, DPO designation, DPIA requirements, or specific compliance matters, consulting a data law specialist or a qualified DPO is strongly recommended. Current as of 30 May 2026.
English practical addendum#
This English section is written for international readers who need to apply the French guidance to a real management decision. The key point for establishing data governance in a French SME or mid-cap in 2026 is not to memorise every technical rule, but to connect the rule to documents, deadlines, cash impact and governance. For CFOs, COOs and CDOs preparing for AI Act, GDPR and CSRD-driven reporting, the right approach is to identify the decision to be made, collect reliable evidence, and only then choose the accounting, tax, payroll or legal treatment.
The practical decision is which roles, processes and tools are needed to demonstrate data quality, security and lineage to auditors and regulators. That decision should be documented before the year-end close, financing discussion, payroll run, transaction signing or tax filing concerned by the topic. When the matter is material, the file should include who decided, which assumptions were used, and which professional advice was obtained.
Evidence to keep#
- data-governance charter;
- RACI matrix;
- data catalogue;
- data quality KPIs;
- AI risk register;
Without a documented data-governance framework, AI-driven decisions cannot be audited and may not pass the AI Act high-risk classification controls. A clean file also helps the company answer questions from banks, investors, auditors, tax authorities, employees or buyers. It is usually cheaper to prepare that evidence during the process than to reconstruct it after a dispute, audit or urgent financing request.
Management checklist#
Before acting, management should run a short checklist. First, confirm that the entity, period and perimeter are correct. Second, compare the accounting treatment with the tax, payroll or legal consequence. Third, quantify the cash effect, because a technically valid option may still be unsuitable if it creates a short-term liquidity issue. Fourth, make sure the decision can be explained in plain English to a shareholder, lender, employee or buyer who is not familiar with French terminology.
For French subsidiaries of foreign groups, translation is also a control topic. A term that sounds familiar in English may not have the same legal meaning in France. The safer method is to keep the French source wording in the working file, then add a short English management note explaining the decision, the financial effect and the residual risk.
How Hayot Expertise would frame the work#
In a professional review, the starting point is the business objective. Is the company trying to reduce risk, close the accounts, prepare a filing, obtain financing, retain employees, sell a business or improve reporting? Once the objective is clear, the technical analysis becomes more useful because it is attached to a concrete decision. Hayot Expertise would generally separate the work into three layers: compliance, numbers and management judgement.
The compliance layer answers whether a rule applies and which documents are required. The numbers layer measures the effect on profit, tax, payroll, cash, equity, valuation or working capital. The management layer decides whether the option is consistent with the company's strategy and risk appetite. This separation avoids a common mistake: treating a French technical rule as if it were only an administrative formality.
A fuller decision framework#
For a director who does not work daily with French accounting and tax rules, the safest framework is sequential. Start with the legal form and tax regime of the business. Then identify the income stream, expense, asset, employee benefit, transaction or reporting obligation concerned. Then test the accounting treatment, the tax treatment and the cash effect separately. Only after those three views are consistent should the company automate the process in accounting software or payroll.
This matters because French compliance is document-heavy. A bank feed, invoice, contract, payroll notice or tax form may each be correct on its own, while the overall file remains inconsistent. For example, the accounting entry may not match the tax return, the VAT position may not match the invoice wording, or the management report may not match the board minutes. English-speaking directors should therefore ask for a short reconciliation note whenever the amount is significant.
Questions to ask before closing the file#
- What is the exact French rule or accounting principle being applied?
- Which document proves the amount, date, counterparty and business purpose?
- Does the treatment affect VAT, corporate tax, income tax, payroll or social contributions?
- Is the cash impact immediate, deferred or only visible at sale, audit or financing?
- Who inside the company owns the update next year?
Why this improves SEO and real usefulness#
For an English reader, the value of this article is not a literal translation of the French version. It is the bridge between French terminology and management action. The content should help the reader understand what to verify, what to ask the accountant, and where the risk may sit in the financial statements or cash forecast. That is also the reason the English version keeps the French concepts visible while explaining them in operational language.
When to ask for help#
Professional input is useful when the topic changes the tax result, payroll cost, legal position, financing capacity, valuation or shareholder relationship. It is also useful when the company is growing quickly and the same decision will repeat every month. A small error in a one-off file is inconvenient; the same error embedded in a recurring workflow becomes expensive.
Frequently asked questions
Par où commencer concrètement la mise en place d'une gouvernance de données ?
Commencez par les données qui causent déjà des problèmes : chiffres contradictoires entre outils, indicateurs aux définitions instables, données sensibles accessibles trop largement. Identifiez deux ou trois domaines prioritaires, nommez un responsable pour chacun, et formalisez les premières règles avant de chercher à couvrir l'ensemble du périmètre. Une gouvernance simple et tenue dans le temps vaut plus qu'un schéma complet jamais approprié.
Le DPO est-il obligatoire pour toutes les entreprises sous le RGPD ?
Non. L'article 37 du RGPD prévoit trois cas de désignation obligatoire : les organismes publics, ceux qui effectuent un suivi régulier et systématique des personnes à grande échelle, et ceux qui traitent à grande échelle des données sensibles ou des données relatives à des condamnations pénales. Il n'existe pas de seuil de salariés déclencheur. En dehors de ces cas, la désignation est volontaire mais reste recommandée dès lors que les traitements deviennent complexes.
Quelles sont les sanctions RGPD en cas de manquement à la gouvernance des données personnelles ?
Les sanctions les plus graves peuvent atteindre 20 millions d'euros ou 4 % du chiffre d'affaires annuel mondial, le montant le plus élevé étant retenu. Ces niveaux s'appliquent aux violations substantielles (absence de base légale, atteinte aux droits des personnes, transferts illicites). Des sanctions moins élevées s'appliquent aux manquements formels, comme l'absence de registre des traitements ou l'absence de désignation de DPO lorsqu'elle est obligatoire.
Quel lien concret entre gouvernance de données et reporting CSRD ?
Les normes ESRS (European Sustainability Reporting Standards), notamment le référentiel ESRS GOV, imposent de documenter la gouvernance des informations de durabilité publiées. Cela signifie que les indicateurs E, S et G doivent reposer sur des définitions stables, des sources identifiées, des périmètres documentés et des procédures de validation — exactement ce qu'une bonne gouvernance de données garantit. Les entreprises dotées d'une gouvernance interne robuste abordent les audits de durabilité avec significativement moins de friction.
Faut-il obligatoirement un outil spécialisé pour mettre en place une gouvernance de données ?
Pas nécessairement au départ. Beaucoup d'entreprises progressent fortement avec des responsabilités clairement définies, une cartographie simple des flux, quelques règles communes documentées et un meilleur paramétrage des outils existants (ERP, CRM, droits d'accès). Un outil spécialisé (catalogue de données, data catalog) apporte une valeur réelle à partir d'un certain niveau de maturité et de volume de données à gérer, mais il n'est pas un prérequis pour démarrer.

Article written by Samuel HAYOT
Chartered Accountant, registered with the Institute of Chartered Accountants. Certified Pennylane trainer.
Regulated French accounting and audit firm based in Paris 8, built to support companies across France with a digital and decision-oriented approach.
Sources
Official and operational sources cited for this page.
- CNIL — RGPD : par où commencer ?
- CNIL — Guide de la sécurité des données personnelles
- CNIL — Le délégué à la protection des données (DPO)
- CNIL — Le registre des activités de traitement
- CNIL — Analyse d'impact relative à la protection des données (AIPD)
- ANSSI / cyber.gouv.fr — Gouvernance de la sécurité numérique
This topic is part of our service Finance transformation | Automation & dashboards
Need a quote or personalised advice?
Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.