Project information
- Category: Governance
- Type: Personal case study (illustrative)
- Frameworks: DMBOK, LGPD, RACI
Description
This is a hypothetical case study built from general data governance practice: a fictional company, illustrative numbers. It is not tied to any current or former employer's real data, systems, or confidential decisions.
The problem. "NovaMercado" is a fictional online marketplace three years into hypergrowth. Every team (logistics, catalog, payments, marketing) built its own reports on its own definition of "active seller" or "order." Nobody owns the customer table, and a recent audit flagged LGPD gaps in how support tickets store personal data. None of this is unusual. It's exactly what happens when a company scales analytics faster than it scales ownership.
Diagnostic. Before writing any policy, the real work is mapping what exists: which datasets are business-critical, who actually maintains them today (versus who is supposed to), where access is granted informally over Slack, and where the LGPD exposure sits. A short maturity assessment, scored across ownership, quality, access control, and documentation, turns "governance feels messy" into a prioritized list of what to fix first.
The framework. The operating model is deliberately federated, not centralized. A small governance team can't own every dataset in a fast-moving company, and shouldn't try to. Instead, a Data Leadership Council, a cross-functional forum with representation from each data-owning team, sets policy and resolves cross-team disputes. Data Owners (one per domain) are accountable for their data's quality and access decisions. Data Stewards handle the day-to-day: metadata, quality checks, catalog upkeep. The governance function itself focuses on tooling, policy design, and reporting. It isn't there to police every request by hand. See the operating model and access-flow diagrams for how a request actually moves through this structure end-to-end, with every approval traceable.
90-day roadmap. Governance programs that try to boil the ocean on day one tend to stall. The plan here is phased. The first 30 days go into assessment, domain mapping, and defining roles and RACI. Days 31–60 stand up the Council and pilot the model with one or two domains before asking the whole company to change how it works. The final 30 days scale what worked, launch a KPI dashboard, and set a recurring review cadence. A governance model that isn't revisited quietly rots within two quarters.
Expected outcomes. Programs like this are typically judged on a handful of numbers: reduction in access-request turnaround time, percentage of critical datasets with a named owner, drop in data-quality incidents, and LGPD audit findings closed. The specific targets depend entirely on where a company starts. What matters more is having a dashboard that makes governance's impact visible to leadership, not just to the data team.