Definition
Data governance brings together the policies, roles, responsibilities and processes that determine how an organisation manages data throughout its lifecycle, including quality, security, access, compliance, retention and availability. Its aim is to give the right people access to dependable, protected and compliant data.
Core elements
- Quality and ownership: who is responsible for which data and under which standards.
- Security and access: who can read, write or delete, together with the relevant encryption and audit trail.
- Regulatory compliance: GDPR, NIS2, DORA and sector-specific requirements.
- Lifecycle and retention: how long to retain data, how to archive it and when to delete it.
- Availability and integrity: keeping data accessible and trustworthy, including after an incident.
The link with backup and sovereignty
Governance does not stop at production. Backups are data that must also be governed. Three questions follow directly:
- Integrity: are restore points protected from tampering? Oxibox uses an append-only write path for this purpose.
- Retention: is retention controlled and impossible for an attacker to revoke? A retention floor that can only be extended provides that protection.
- Jurisdiction and residency: where is the data located, and who can access it? With Full Cloud, Oxibox stores data across two geo-redundant French datacentres without transfer outside the European Union. An HDS option is available through an HDS-certified hosting partner.
