Data governance & compliance
The non-negotiable foundation of every CDO's agenda: governance frameworks, data quality, Master Data Management, lineage, GDPR and global privacy regulation, data contracts, and data risk management.
Most data governance programs are theater. A council that meets quarterly, a policy nobody reads, a compliance checkbox that satisfies auditors and protects no one. This block is for the CDO who refuses to run that circus.
You start with frameworks that actually earn their keep. DAMA-DMBOK stripped down to what matters, a Data Governance Council built to make decisions instead of slides, and ownership models where stewardship and accountability are real, not assigned to a committee. Then you fix the foundation. Data quality dimensions that expose why 'good enough' quietly erodes trust across the org, Master Data Management in practice with styles, tools, and the Golden Record, and lineage and metadata so you always know where your data was born.
Regulation is not optional and neither is your fluency. You will work through the ten GDPR mistakes CDOs make on repeat, navigate the CCPA, LGPD, and AI Act patchwork without panic, and push past compliance toward data ethics that build institutional trust. Then you modernize. Data contracts as the new quality standard between teams, shift-left governance embedded in the engineering pipeline, and a clear-eyed comparison of Alation, Collibra, and DataHub.
Finally, you prepare for the day it goes wrong. A breach playbook for the first 72 hours, data classification and zero-trust access control, and the insider threats and shadow IT that no strategy paper ever mentions.
This is governance that engineers respect, auditors approve, and executives fund. You leave able to defend your data, your decisions, and your reputation. Governance stops being the department that says no and becomes the reason the business can move fast without breaking things.
What you'll master
- Build a Data Governance Council that makes real decisions instead of producing slides
- Assign data ownership, stewardship, and accountability that actually holds across the org
- Implement Master Data Management and lineage so you trust every Golden Record
- Navigate GDPR, CCPA, LGPD, and the AI Act without slowing the business down
- Introduce data contracts and shift-left quality into the engineering pipeline
- Select the right data catalog by comparing Alation, Collibra, and DataHub on merit
- Execute a breach playbook and zero-trust access model under real pressure
Modules
Covers how to structure governance frameworks, councils, and ownership models that work in practice.
Covers data quality dimensions, master data management, and lineage and metadata practices.
Covers GDPR, global privacy regulations, and data ethics beyond pure compliance.
Covers data contracts, shift-left quality, and modern data catalog tooling.
Covers breach response, data classification, access control, and insider and shadow IT risks.
Frequently asked questions
What does the Data governance & compliance block actually cover?
It covers five modules of three lessons each, for 15 lessons total: governance frameworks and councils, data quality and Master Data Management, privacy and regulation (GDPR, CCPA, LGPD, AI Act), data contracts and catalogs, and breach response and access control. It sits inside the CDO Track and treats governance as an operating discipline rather than a compliance checkbox.
Who is this for if I'm not a Chief Data Officer?
It works for anyone accountable for data reliability or data risk: data platform leads, heads of analytics, data protection officers, and engineering managers who own pipelines. The material is written from the CDO's seat, so it assumes you have to defend decisions to executives, auditors, and engineers at the same time.
Does this teach compliance or does it teach governance?
Both, but they are handled as separate problems. Compliance is the regulatory module: GDPR mistakes, the CCPA/LGPD/AI Act patchwork, and data ethics. Governance is the operating layer: councils that make decisions, ownership and stewardship models, quality dimensions, lineage, and data contracts embedded in the pipeline.
Where should I start if my governance program is already running but nobody uses it?
Start with the frameworks module, specifically the lesson on setting up a Data Governance Council that doesn't become theater, then the one on ownership, stewardship, and accountability across the org. A program nobody uses is usually a program with no real decision rights and no named owners, not a tooling problem.
What's the difference between data contracts and traditional data quality rules?
Traditional quality rules are checks run downstream, after data has already landed and broken a dashboard. Data contracts are agreements between producing and consuming teams, enforced upstream in the engineering pipeline. The block covers both, plus shift-left quality as the practice that moves governance from detection to prevention.
Are Alation, Collibra, and DataHub compared with a recommendation, or just described?
They are compared on merit in a dedicated lesson on data catalogs in practice, covering where each one fits rather than crowning a single winner. The point is to give you selection criteria you can defend, since the right catalog depends on your lineage needs, your metadata maturity, and whether your engineers will adopt it.