Definition
What is information governance?
Information governance is the system of accountability, decision-making, controls and assurance through which an organisation manages information throughout its lifecycle. It connects ownership, records management, privacy, security, retention, access, policy and oversight so information is managed consistently and important decisions can be evidenced.
Information governance is not the same as data protection
The disciplines overlap and depend on each other, but they are not interchangeable.
Focus of this page
Information Governance
- accountability
- records
- lifecycle
- decision rights
- policy
- assurance
The wider management and accountability environment around organisational information.
Data Protection
- lawful processing
- individual rights
- DPIAs
- transparency
- privacy accountability
Legal obligations relating to personal data. May sit within, alongside or intersect with information governance.
Cybersecurity
- confidentiality
- integrity
- availability
- technical and organisational security controls
Protects information and systems, but does not by itself establish ownership, lifecycle management or executive accountability.
Where they meet — for example retention of personal data, access control or incident handling — information governance provides the ownership and decision routes that let privacy and security controls work together.