Data
Who owns a piece of data? Lightweight governance for SMEs
Data without an owner degrades as it gets used. How to name an owner for each critical piece of data, what they decide, and how to set it up without committees.
6 MIN READ
When a critical piece of data fails — an out-of-date price list, a margin that doesn't add up, an order status nobody has touched in weeks — the usual reaction is to look for the tool that will fix it. The useful question is a different one: who answers for that data? In most small and mid-sized companies the honest answer is "nobody", and that is where the problem sits, not in the software. This article is about one concrete decision: naming a responsible owner for each critical piece of data in the business. What owning data means, what exactly that person decides, and how to set it up without committees or bureaucracy.
What a data owner is (and is not)
A data owner is not a new job title or someone you need to hire. It is someone already in the company who takes on a clear responsibility: for this piece of data, I set the rules and I answer for them being followed.
One frequent misunderstanding is worth clearing up early: the owner of a piece of data is not the IT person or the vendor who administers the tool it lives in. Running the system is one thing; answering for what it contains is another. Whoever manages CRM permissions has no reason to know whether a price is current — just as whoever maintains the building doesn't decide what goes in each office.
Nor is the owner the person who types everything in or fixes every error. The owner does not do all the work on the data: they decide the rules of the data and have the final word when questions come up. Execution can be shared; responsibility cannot.
What a data owner actually decides
Data ownership boils down to a handful of decisions. For their data, the owner decides:
- What counts. What it means in practice: from when a price is considered current, what makes a customer "active". You don't need a treatise; you need there to be an answer, and for it to be theirs.
- Who creates and modifies it. Which people or systems can add it or change it, and from where. Data anyone can touch from anywhere doesn't have rules: it has habits.
- What minimum quality it requires. Which fields cannot be empty, what format is used, what gets validated before saving.
- How an error gets corrected. Where it gets fixed — at the source, not in the report copy — and who needs to be told.
- What happens with exceptions. All real data has them; the difference between order and chaos is whether they are resolved by a rule or by the mood of the day.
None of this requires technical knowledge. It requires knowing the business and having the authority to make the decision stick.
What happens when there is no owner
Data without an owner degrades at the pace of its own use: the more people touch it, the worse it gets, because everyone feeds it and nobody answers for it. The consequences follow a recognisable pattern.
The same arguments repeat in every meeting, because nobody has the authority to close them: each department defends its version and the conversation gets postponed to next month. Data clean-ups come undone within weeks, because the records were corrected but nobody changed the rules at the point of entry — bailing water without plugging the leak. And when the data fails at a moment that matters — a quote sent with the old prices, an order shipped against months-old information — the energy goes into finding someone to blame instead of fixing the rule that was missing.
The striking thing is that all of this coexists with competent people and perfectly decent tools. No one in particular is failing: what's failing is that there is no one in particular.
Lightweight governance: a list, one name per line
The phrase "data governance" conjures committees, offices and documents nobody reads. For a small or mid-sized company, almost all of that is surplus. Lightweight governance fits in three steps:
- A short list of critical data. The data that feeds invoicing, recurring decisions or legal obligations. If the list doesn't fit on one page, half of it doesn't belong there: critical means its failure costs money or decisions, not merely that somebody uses it.
- One name next to each line. A name, not a department: "sales" doesn't answer questions, a person does. Shared ownership doesn't work, because "everyone's" is the polite way of saying "no one's".
- The decisions, written where the team will read them. The rules the owner sets go somewhere accessible. Without that, governance lives in conversations and dies with them.
And nothing more, for now. Governance grows when a real problem asks for it, not before. Starting with the full org chart of your data is the surest way to have nothing left standing a few months later.
How to choose the owner
The practical rule: the natural owner of a piece of data is whoever suffers the consequences when it is wrong, not whoever administers the system it lives in. The person who answers for margin is the natural candidate for the price list; the person who answers for delivery, for order status. That alignment matters because it turns self-interest into maintenance: looking after the data is looking after yourself.
If two areas suffer equally, the tie-breaker is who uses it more often to make decisions. And whoever accepts the role needs two things from leadership: real authority — if they decide a field is mandatory, it has to actually become mandatory, and everyone else has to comply — and recognised time, even if it's little. Naming owners without granting either is just renaming the problem.
Three questions to start this week
- Which data, when it's wrong, costs us money or decisions? That is the list.
- Who suffers today when each of those fails? That is your candidate owner.
- Where will they write their rules down so the rest of the team follows them?
Naming owners doesn't fix the data by itself, but it changes the conversation: from "the data is wrong" — which nobody can act on — to "this is decided this way and this person answers for it", which someone can. It is, in fact, one of the first questions we ask in a data & systems assessment: who answers for each piece of data the business depends on. The silence that usually follows is, more often than not, the first finding.
After reading
Does this sound like your case?
If this describes something sitting on your desk, tell us about it. We'll come back with a first read before proposing anything.
A first 30-minute call with direct senior interlocution — no commitment and no sales pitch.