Data & AI
A Data Governance Framework for Indian Companies
Affix Center · · 6 min read

Ask three departments in the same company how many active customers you have and you will often get three different answers. Sales counts anyone who ordered in the last year, finance counts accounts with open balances, and the CRM includes duplicates nobody has cleaned. Meanwhile, customer phone numbers sit in spreadsheets on shared drives, and nobody is sure who is allowed to see them. A data governance framework for Indian companies fixes both problems: it makes data trustworthy and makes clear who is responsible for it.
Many governance programmes fail because they start with a thick policy document and a committee that meets twice. Staff see it as paperwork, and nothing changes in daily work. The practical approach is smaller: a few clear roles, a handful of rules for your most important data, and simple controls built into the systems people already use.
What Data Governance Covers
Data governance is the set of roles, rules and processes that decide how data is defined, stored, used, protected and retired. It is different from data management, which is the hands-on work of running databases and pipelines. Governance sets the rules; management follows them.
A workable framework covers six areas:
- Ownership: who is accountable for each type of data
- Definitions: agreed meanings for key terms and metrics
- Quality: standards for accuracy, completeness and timeliness
- Access and security: who can see and change what
- Privacy and compliance: how personal and regulated data is handled
- Lifecycle: how long data is kept and how it is deleted
Why It Matters More Now for Indian Companies
Three pressures are pushing governance up the agenda.
First, privacy law. The Digital Personal Data Protection Act, 2023 sets duties for organisations that process digital personal data, including purpose limitation, security safeguards and responding to requests from individuals. The DPDP Rules, 2025 were notified in November 2025, with most obligations phased in over the following 18 months. That window is time to prepare, not time to wait. You cannot meet these duties without knowing what personal data you hold, where it is and who uses it.
Second, analytics and AI. Dashboards, forecasting models and AI assistants are only as good as the data fed into them. Poor governance produces confident but wrong answers.
Third, sector rules. Banks, NBFCs, insurers, listed companies and government suppliers often face additional record-keeping, audit and security expectations. Governance gives you one consistent way to meet them.
Roles: Keep Them Few and Clear
You do not need a large team. You need named people with defined responsibilities:
- Executive sponsor: a senior leader, often the CFO, COO or CIO, who approves priorities and resolves disputes.
- Data owners: business heads accountable for a data domain, such as customer, product, employee or vendor data. They approve definitions and access.
- Data stewards: people in each team who maintain quality day to day, fix errors and flag issues.
- Data custodians: IT staff or partners who run the systems, backups and security controls.
- Governance lead: one person who coordinates the programme, tracks issues and reports progress.
In a mid-sized company, these roles are part-time additions to existing jobs. Write them into job descriptions so they are not forgotten.
A Practical Data Governance Framework in Six Steps
1. Pick your critical data
Start with the two or three data domains that cause the most pain or risk. Customer master data and employee data are common starting points. Do not try to govern everything at once.
2. Build a data inventory
List the systems that hold this data, what fields they contain, which fields are personal or sensitive, who can access them and where the data is hosted. A spreadsheet is fine to start.
3. Agree on definitions
Create a short business glossary: "active customer", "revenue", "employee headcount", "overdue". Get the data owner to sign off each definition, and publish the glossary where everyone can find it.
4. Set quality rules and measure them
Define simple checks such as no duplicate customer GSTINs, mandatory PIN codes, or valid email formats. Measure them monthly and assign stewards to fix failures at the source system, not in reports.
5. Control access
Apply role-based access, remove shared logins, mask sensitive fields in reports and test that departing employees lose access promptly. Our cybersecurity services can help design and review these controls.
6. Define retention and deletion
For each data type, record how long it must be kept for legal, tax or business reasons, and how it will be deleted or anonymised after that. Personal data should not be kept longer than the purpose requires.
Policies You Actually Need
Keep the policy set short and readable. Most companies can start with five documents of a few pages each:
- Data governance charter: scope, roles and decision rights.
- Data classification policy: levels such as public, internal, confidential and restricted, with handling rules for each.
- Access control policy: how access is requested, approved, reviewed and removed.
- Data quality standard: the rules and targets for critical data.
- Retention and disposal schedule: how long each data type is kept.
Link your privacy notice and consent processes to these policies so they stay consistent.
Tools and Automation
Tools help, but only after roles and rules are in place. Useful capabilities include:
- A data catalogue that records sources, owners, definitions and lineage
- Automated data quality checks in pipelines, with alerts to stewards
- Discovery tools that scan systems for personal data such as Aadhaar numbers, PAN, phone numbers and email addresses
- Master data management for customer, vendor and product records
- Access reviews and audit logs from your identity and database platforms
Our data and AI team can build quality checks and cataloguing into your existing data platform so governance becomes part of daily operations rather than a separate task.
Measuring Progress
Track a small set of indicators each quarter: percentage of critical fields meeting quality rules, number of systems inventoried, number of open data issues, time taken to fulfil access removals, and number of reports using approved definitions. Share these with the executive sponsor. Visible progress keeps the programme funded and taken seriously.
Frequently Asked Questions
What is a data governance framework?
It is a structured set of roles, policies and processes that decide how an organisation defines, protects, uses and retires its data, so that data is accurate, secure and compliant.
Is data governance required under the DPDP Act?
The Act does not use the term, but its duties on purpose limitation, security and handling individual requests are very hard to meet without knowing what data you hold and who controls it. Governance provides that foundation.
Who should own data governance in a company?
A senior executive sponsor should own it, with business heads as data owners. IT runs the systems, but the business must own definitions and access decisions.
How long does it take to set up?
A focused first phase covering one or two data domains can be set up in a few months. The programme then expands domain by domain.
How Affix Center Can Help
We help Indian companies design practical data governance frameworks, build data inventories, set up quality checks and access controls, and prepare data for analytics and AI projects.
To start with a focused assessment of your critical data, talk to Affix Center.