ISO/IEC 38505-1:2026
(Main)Information technology — Governance of data — Part 1: Application of ISO/IEC 38500 to the governance of data
General Information
- Abstract
This document provides principles for governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient and acceptable use of data within their organizations by: applying the governance principles and model of ISO/IEC 38500 to the governance of data; assuring stakeholders that, if the principles and practices proposed by this document are followed, they can have confidence in the organization’s governance of data; informing and guiding governing bodies in the use and protection of data in their organizations. This document can also provide guidance to a wider community, including: executive managers; external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies; internal and external service providers (including consultants); auditors. This document applies to the governance of the current and future use of data that is created, collected, stored, secured, protected, or controlled by IT systems, and impacts the management processes and decisions relating to data. This document defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance. This document is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. This document is applicable to organizations of all sizes, regardless of the extent of their dependence on data.
- Status
- Published
- Publication Date
- 19-Aug-2026
- Technical Committee
- ISO/IEC JTC 1/SC 40 - IT service management and IT governance
- Drafting Committee
- ISO/IEC JTC 1/SC 40 - IT service management and IT governance
- Current Stage
- 6060 - International Standard published
- Start Date
- 20-Aug-2026
- Due Date
- 09-Jun-2026
- Completion Date
- 20-Aug-2026
Overview
ISO/IEC 38505-1:2026 is an international standard that provides guiding principles for governing bodies on the effective, efficient, and acceptable use of data within organizations. Building on the ISO/IEC 38500 framework, this standard specifically adapts IT governance principles to the governance of data. Applicable to all types of organizations-public, private, government, or not-for-profit-of any size or sector, ISO/IEC 38505-1:2026 supports organizations in leveraging data as a valuable asset, managing related risks, and assuring stakeholders of the organization’s commitment to responsible data governance.
Key audiences for this standard include members of governing bodies, executive managers, technical specialists (such as legal or accounting professionals), service providers, consultants, and auditors. The guidance is designed to inform high-level oversight and strategic decision-making, rather than operational data management processes.
Key Topics
- Governance Principles and Models: ISO/IEC 38505-1:2026 applies the ISO/IEC 38500 principles to data, emphasizing purpose, value generation, strategy, oversight, accountability, stakeholder engagement, leadership, risk governance, decision making, social responsibility, and ongoing viability.
- Good Governance Outcomes:
- Effective Performance: Ensuring data supports innovation, business clarity, and accountability.
- Responsible Stewardship: Fulfilling data protection responsibilities in line with legal and societal expectations, including considerations for intellectual property and privacy.
- Ethical Behaviour: Promoting transparency, data integrity, and stakeholder trust through ethical data handling.
- Data-Specific Aspects:
- Value: Importance of data quality, timeliness, context, and volume.
- Risk: Recognition of data-associated risks, such as breaches or regulatory non-compliance, alongside competitive challenges.
- Constraints: Addressing external obligations (regulation, legislation, contracts) and internal policies governing data use.
- Accountability and Oversight: Defines the roles and obligations of governing bodies, encouraging the establishment of policies and strategies to direct, monitor, and evaluate data use across the organization. Mechanisms for oversight, such as dedicated subcommittees and audits, are recommended for maintaining effective data governance.
Applications
ISO/IEC 38505-1:2026 is practical for any organization seeking to:
- Assure Stakeholders: Demonstrate sound data governance and instill confidence in data-related practices to shareholders, partners, and clients.
- Guide Strategic Decisions: Help governing bodies make informed decisions about how data is collected, stored, secured, and used.
- Manage Risks: Identify and mitigate risks associated with poor data governance, including legal penalties, reputation loss, data breaches, and compromised business functions.
- Comply with Regulations: Align with regulatory, legislative, and contractual data obligations, reducing exposure to penalties and ensuring best practices.
- Drive Innovation: Harness data for innovation, business growth, and enhanced service delivery while upholding ethical standards.
- Promote Social Responsibility and Inclusion: Ensure the rights, cultural identities, and needs of individuals (including special consideration for indigenous data) are respected in data practices.
Related Standards
- ISO/IEC 38500 - Information technology - Governance of IT for the organization
- The foundational framework for IT governance on which 38505-1 builds its principles and model.
- ISO 37000 - Governance of organizations - Guidance
- Aligns governance outcomes and supports broader organizational governance concepts.
- ISO/IEC/TS 38501 - Implementation arrangements for IT governance
- Offers practical guidance for enacting IT governance standards, referenced for implementing effective data governance systems.
- ISO/IEC 29100 - Privacy framework
- Provides privacy principles and terminology relevant to personal data governance.
By adopting ISO/IEC 38505-1:2026, organizations can achieve more robust and resilient data governance, ensuring that data-driven opportunities are maximized while mitigating associated risks and fulfilling all societal, legislative, and stakeholder expectations. This standard represents best practice for organizations seeking effective governance of data in today’s information-driven environment.
Relations
- Effective Date
- 10-Jun-2023
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
ISO/IEC 38505-1:2026 is a standard published by the International Organization for Standardization (ISO). Its full title is "Information technology — Governance of data — Part 1: Application of ISO/IEC 38500 to the governance of data". This standard covers: This document provides principles for governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient and acceptable use of data within their organizations by: applying the governance principles and model of ISO/IEC 38500 to the governance of data; assuring stakeholders that, if the principles and practices proposed by this document are followed, they can have confidence in the organization’s governance of data; informing and guiding governing bodies in the use and protection of data in their organizations. This document can also provide guidance to a wider community, including: executive managers; external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies; internal and external service providers (including consultants); auditors. This document applies to the governance of the current and future use of data that is created, collected, stored, secured, protected, or controlled by IT systems, and impacts the management processes and decisions relating to data. This document defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance. This document is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. This document is applicable to organizations of all sizes, regardless of the extent of their dependence on data.
This document provides principles for governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient and acceptable use of data within their organizations by: applying the governance principles and model of ISO/IEC 38500 to the governance of data; assuring stakeholders that, if the principles and practices proposed by this document are followed, they can have confidence in the organization’s governance of data; informing and guiding governing bodies in the use and protection of data in their organizations. This document can also provide guidance to a wider community, including: executive managers; external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies; internal and external service providers (including consultants); auditors. This document applies to the governance of the current and future use of data that is created, collected, stored, secured, protected, or controlled by IT systems, and impacts the management processes and decisions relating to data. This document defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance. This document is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. This document is applicable to organizations of all sizes, regardless of the extent of their dependence on data.
ISO/IEC 38505-1:2026 is classified under the following ICS (International Classification for Standards) categories: 35.020 - Information technology (IT) in general. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC 38505-1:2026 has the following relationships with other standards: It is inter standard links to ISO/IEC 38505-1:2017. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
ISO/IEC 38505-1:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
International
Standard
ISO/IEC 38505-1
Second edition
Information technology —
2026-08
Governance of data —
Part 1:
Application of ISO/IEC 38500 to the
governance of data
Technologies de l'information — Gouvernance des données —
Partie 1: Application de l'ISO/IEC 38500 à la gouvernance des
données
Reference number
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Good governance of data . 4
4.1 General .4
4.2 Effective performance .4
4.3 Responsible stewardship .4
4.4 Ethical behaviour .4
4.5 Benefits of good governance of data .4
4.6 Responsibilities of the governing body .6
4.7 Governing body and oversight mechanisms .6
5 Principles, model and aspects for good governance of data . 6
6 Data accountability . 7
6.1 General .7
6.2 Collect .8
6.3 Store .9
6.4 Report .9
6.5 Decide .10
6.6 Distribute .10
6.7 Dispose .10
7 Guidance for the governance of data — Principles .11
8 Guidance for the governance of data — Model .12
8.1 General . 12
8.2 Model for the governance of data. 13
8.3 Engage stakeholders. 13
8.4 Evaluate .14
8.5 Direct . .14
8.6 Monitor . 15
9 Guidance for the governance of data — Data-specific aspects .15
9.1 General . 15
9.2 Value.16
9.2.1 General .16
9.2.2 Quality .16
9.2.3 Timeliness .16
9.2.4 Context .16
9.2.5 Volume .16
9.3 Risk .17
9.3.1 General .17
9.3.2 Management .17
9.3.3 Data classification schemes .17
9.3.4 Security . . .17
9.4 Constraints.18
9.4.1 General .18
9.4.2 Regulation and legislation .18
9.4.3 Societal .18
9.4.4 Organizational policy .18
10 Application of the data accountability map .18
Bibliography .20
© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC/JTC 1, Information technology,
Subcommittee SC 40, IT service management and IT governance.
This second edition cancels and replaces the first edition (ISO/IEC 38505-1:2017), which has been technically
revised.
The main changes are as follows:
— alignment with ISO/IEC 38500:2024, which is itself aligned to ISO 37000.
A list of all parts in the ISO/IEC 38505 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
iv
Introduction
The objective of this document is to provide principles, definitions and a model for governing bodies to use
when evaluating, directing and monitoring the handling and use of data in their organizations.
This document is high-level, principles-based and advisory. In addition to providing broad guidance on
the role of a governing body, it encourages organizations to use appropriate standards to underpin their
governance of data.
All organizations use data; and the major proportion of the data is stored electronically across IT systems.
With the advent of cloud computing, the realization of the potential of the “internet of things” and the
increasing use of “big data” analytics and artificial intelligence (AI), data have become easier to generate,
gather, store and mine for useful information. This flood of data brings with it an urgent requirement and
responsibility for governing bodies to ensure that valuable opportunities are leveraged, and sensitive data
are protected and secured.
Governance of data plays a critical role in ensuring the responsible, innovative, sustainable, and ethical use
of data.
Governance of data is an ongoing practice, adapting to the evolving data landscape.
This document has been prepared to provide guidance to the members of governing bodies to apply a
principles-based approach to the governance of data to increase the value of the data while preventing the
risks associated with the data. ISO/IEC 38500 provides principles, model, and framework for the governing
bodies of organizations to guide their current use and to plan for their future use of Information technology
(IT), and this document concerns the application of ISO/IEC 38500. While this document describes the
governance of data and its use within an organization, guidance on the implementation arrangement for the
effective governance of IT in general is found in ISO/IEC/TS 38501. The constructs in ISO/IEC/TS 38501 can
help to identify internal and external factors relating to the governance of IT and help to define beneficial
outcomes and identify evidence of success.
The use of AI and the growth of data have created extensive opportunities for the analysis and use of data
in decision making. Because legal regulations sometimes lag behind or are not developed, it is up to an
organization to ensure the ethical use of data.
As with ISO/IEC 38500, this document is addressed primarily to the governing body of an organization and
applies equally regardless of the size of the organization or its industry or sector. The principles of this
document can be relevant for the governing bodies of data exchange networks, platforms, spaces and for
other inter-organizational data governance contexts. However, the inter-organizational aspects of data
governance are outside the scope of this document.
Governance is distinct from management and concerns evaluating, directing and monitoring the use of
data, rather than the mechanics of storing, retrieving or managing the data. This document outlines an
understanding of various data management and techniques to enunciate the strategies and policies that can
be directed by the governing body.
© ISO/IEC 2026 – All rights reserved
v
International Standard ISO/IEC 38505-1:2026(en)
Information technology — Governance of data —
Part 1:
Application of ISO/IEC 38500 to the governance of data
1 Scope
This document provides principles for governing bodies of organizations (which can comprise owners,
directors, partners, executive managers, or similar) on the effective, efficient and acceptable use of data
within their organizations by:
— applying the governance principles and model of ISO/IEC 38500 to the governance of data;
— assuring stakeholders that, if the principles and practices proposed by this document are followed, they
can have confidence in the organization’s governance of data;
— informing and guiding governing bodies in the use and protection of data in their organizations.
This document can also provide guidance to a wider community, including:
— executive managers;
— external businesses or technical specialists, such as legal or accounting specialists, retail or industrial
associations, or professional bodies;
— internal and external service providers (including consultants);
— auditors.
This document applies to the governance of the current and future use of data that is created, collected,
stored, secured, protected, or controlled by IT systems, and impacts the management processes and
decisions relating to data.
This document defines the governance of data as a subset or domain of the governance of IT, which itself is a
subset or domain of organizational, or in the case of a corporation, corporate governance.
This document is applicable to all organizations, including public and private companies, government
entities, and not-for-profit organizations. This document is applicable to organizations of all sizes, regardless
of the extent of their dependence on data.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 38500, Information technology — Governance of IT for the organization
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 38500 and the following apply.
© ISO/IEC 2026 – All rights reserved
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— IEC Electropedia: available at https:// www .electropedia .org/
— ISO Online browsing platform: available at https:// www .iso .org/ obp
3.1
anonymization
process by which personally identifiable information (PII) is irreversibly altered in such a way that a PII
principal can no longer be identified directly or indirectly, either by the PII controller alone or in collaboration
with any other party
[SOURCE: ISO/IEC 29100:2024, 3.2]
3.2
big data
extensive datasets — primarily in the data characteristics of volume, variety, velocity, and/or variability —
that require a scalable technology for efficient storage, manipulation, management, and analysis
Note 1 to entry: Big data is commonly used in many different ways, for example as the name of the scalable technology
used to handle big data extensive datasets.
[SOURCE: ISO/IEC 20546:2019, 3.1.2]
3.3
cloud computing
paradigm for enabling network access to a scalable and elastic pool of shareable physical or virtual resources
with self-service provisioning and administration on-demand
Note 1 to entry: Examples of resources include servers, operating systems, networks, software, applications, and
storage equipment.
Note 2 to entry: Self-service provisioning refers to the provisioning of resources provided to cloud services performed
by cloud service customers through automated means.
[SOURCE: ISO/IEC 22123-1:2023, 3.1.1]
3.4
data accountability
property that ensures that the actions of an entity can be traced uniquely to the entity
Note 1 to entry: The “use” of data includes all activities associated with data.
3.5
de-identification
general term for any process of removing the association between a set of identifying data and the data
subject
[SOURCE: ISO 25237:2017, 3.20]
3.6
governance of data
system by which current and future data is collected, stored, secured, protected or controlled by IT systems,
and impacts the management processes and decisions relating to data
© ISO/IEC 2026 – All rights reserved
3.7
internet of things
IoT
global infrastructure for the information society, enabling advanced services by interconnecting (physical
and virtual) things based on existing and evolving interoperable information and communication
technologies
Note 1 to entry: Through the exploitation of identification, data capture, processing and communication capabilities,
the IoT makes full use of things to offer services to all kinds of applications, whilst ensuring that security and privacy
requirements are fulfilled.
Note 2 to entry: In a broad perspective, the IoT can be perceived as a vision with technological and societal implications.
[SOURCE: Rec. ITU-T Y.2060]
3.8
machine learning
ML
process of optimizing model parameters through computational techniques, such that the model's behaviour
reflects the data or experience
[SOURCE: ISO/IEC 22989:2022, 3.3.5]
3.9
pseudonymization
process applied to personally identifiable information (PII) (3.10) which replaces identifying information with
an alias
Note 1 to entry: Pseudonymization can be performed either by PII principals themselves or by PII controllers.
Pseudonymization can be used by PII principals to consistently use a resource or service without disclosing their
identity to this resource or service (or between services), while still being held accountable for that use.
Note 2 to entry: Pseudonymization does not rule out the possibility that there can be (a restricted set of) privacy
stakeholders other than the PII controller of the pseudonymized data which are able to determine the PII principal’s
identity based on the alias and data linked to it.
[SOURCE: ISO/IEC 29100:2024, 3.22]
3.10
personally identifiable information
PII
information that (a) can be used to establish a link between the information and the natural person to whom
such information relates, or (b) is or might be directly or indirectly linked to a natural person
Note 1 to entry: The “natural person” in the definition is the PII principal. To determine whether a PII principal is
identifiable, account should be taken of all the means which can reasonably be used by the privacy stakeholder holding
the data, or by any other party, to establish the link between the set of PII and the natural person.
[SOURCE: ISO/IEC 29100:2024, 3.7]
3.11
PII principal
data subject
natural person to whom the personally identifiable information (PII) (3.10) relates
[SOURCE: ISO/IEC 29100:2024, 3.9]
3.12
risk management
coordinated activities to direct and control an organization with regard to risk
[SOURCE: ISO 31000:2018, 3.2]
© ISO/IEC 2026 – All rights reserved
4 Good governance of data
4.1 General
Organizations make decisions based on data. When that data has integrity, there is a greater opportunity
to make informed decisions. Good governance of data provides an oversight environment in which
organizational data can be collected, stored, processed and reported with integrity while making the data
available as required and maintaining the confidentiality requirements that the organization has adopted or
has been forced to adopt. Good governance of data supports governing bodies in ensuring that the use of data
throughout an organization contributes to the fulfilment of the organizational purpose and the realization
of the key governance outcomes outlined in ISO 37000. These outcomes are effective performance (4.2),
responsible stewardship (4.3) and ethical behaviour (4.4).
4.2 Effective performance
Governance of data enhances the organization's performance through:
— innovation in services, markets and business; appropriate implementation and operation of data assets;
— clarity of responsibility and accountability for both the protection and potential to add value;
— minimization of adverse or unintended consequences.
4.3 Responsible stewardship
Good governance of data ensures that governing bodies are responsible stewards of the organization’s data,
leading to:
— proper protection and ethical use of data, including the organization’s intellectual property and
stakeholder data;
— the ability to meet legislative, regulatory and contractual obligations related to data protection, privacy
and use;
— increased preparedness to prevent and mitigate data risks, including data breaches, misuse or loss of
trust from stakeholders;
— inclusive practices, especially in government contexts, where data governance supports the delivery of
services that respect the rights, cultural identity and needs of all citizens and individuals protected by
relevant legislation, with special consideration for indigenous peoples' data and social inclusivity.
4.4 Ethical behaviour
Good data governance ensures the ethical use of organizational data through:
— ensuring that data is handled in a way that respects stakeholder rights and fosters transparency,
integrity and compliance with regulations;
— protecting the confidentiality of sensitive business data (e.g. proprietary recipes, design specifications);
— safeguarding the trust of stakeholders, including business partners, customers and the public;
— ensuring that data is used responsibly, without compromising ethical standards or social responsibilities.
4.5 Benefits of good governance of data
Good governance of data assists governing bodies in ensuring that the use of data throughout an organization
contributes positively to the performance of the organization through enabling:
— innovation in services, markets and business;
© ISO/IEC 2026 – All rights reserved
— appropriate implementation and operation of data assets;
— clarity of responsibility and accountability for both the protection and potential to add value;
— minimization of adverse or unintended consequences;
— sound decision making based on the data assets collected, stored, processed and reported.
Organizations with good governance of data should be expected to be:
— trustworthy organizations for data owners and data users to transact with;
— able to provide reliable data for sharing;
— protectors of the organization’s intellectual property, other party intellectual property, and other value
derived from data;
— organizations with policy and practice in place to deter hackers and fraudulent activity;
— prepared to minimize the impact of data breaches;
— aware of when and how data can be reused;
— able to demonstrate good data handling practices.
This document applies to all organizations, including governments who are dependent on data to inform
national decision making. Good governance of government data results in the delivery of services and
solutions that are appropriate for every citizen. This involves respecting the rights, the cultural identity
and the needs of each citizen. Special consideration should be given to the rights and obligations relating to
indigenous peoples’ data, and to the appropriate handling and use of data that reflects a position of social
inclusivity.
This document guides the effective, efficient and acceptable use of data by applying governance principles.
Governing bodies, by ensuring that their organizations follow these principles, are assisted in managing
risks and encouraging the exploitation of opportunities arising from the sage handling and accurate
interpretation of quality data.
Good governance of data also assists governing bodies in assuring conformance with obligations (regulatory,
legislative, contractual) concerning the acceptable use and handling of data.
This document establishes a model for the governance of data (see Figure 1). The risk of governing bodies
not fulfilling their obligation is mitigated by giving due attention to the model and in appropriately applying
the principles.
Inadequate provision for the governance of data can expose an organization to several risks and adverse
outcomes including:
— penalties of not complying with legislation, especially legislation relating to required privacy measures;
— loss of confidentiality of business data, e.g. recipes or design specifications;
— loss of trust from stakeholders, including business partners, customers and the public;
— inability to carry out critical organizational functions due to lack of trustworthy or business-relevant
data;
— increased competition through the strategic use of data by competitors.
Governing bodies can be held accountable for data related issues, including:
— breaches of privacy, spam, health and safety, record keeping legislation and regulations;
— nonconformity with mandated standards relating to security and social responsibility;
© ISO/IEC 2026 – All rights reserved
— matters relating to intellectual property rights.
4.6 Responsibilities of the governing body
The governing body’s authority, responsibility and accountability for the effective, efficient and acceptable
use of data arise from its overall responsibility for governance of the organization, and its obligations to its
external stakeholders, including regulators.
A key focus of the governing body’s role in the governance of data is to ensure that the organization obtains
and protects value from investments in data and associated IT, while managing risk and taking constraints
into account.
Additionally, the governing body should ensure that there is a clear understanding of what data are being
used by the organization and for what purpose, and that there is an effective management system in place
to ensure the obligations, such as data protection, privacy and respect for intellectual property, can be met.
4.7 Governing body and oversight mechanisms
The governing body should establish oversight mechanisms for governance of data that are appropriate to
the level of business dependency on data and risk exposure regarding data.
The governing body should have a clear understanding of the importance of data to the organization’s
business strategies as well as the potential strategic risk to the organization from the use of that data. The
level of attention that a governing body gives to data should be based on these factors.
The governing body should ensure that its members and associated governance mechanisms (such as audit,
security, risk management and related committees) as well as managers have the requisite knowledge and
understanding of the importance of data.
The governing body may establish a subcommittee to assist the governing body in overseeing the
organization’s use of data from a strategic point of view. The need for a subcommittee depends on the
importance of data to the organization and its size.
The governing body should ensure that an appropriate governance framework is established for the
governance and management of data.
The governing body should monitor the effectiveness of the mechanisms for the governance and management
of data by requiring processes such as audit and independent assessments to gain assurance that governance
is effective.
5 Principles, model and aspects for good governance of data
As ISO/IEC 38500 highlights, the governance of IT is a subset or domain of organizational governance, or
in the case of a corporation, corporate governance. This document builds on and extends ISO/IEC 38500 to
specifically examine data and its use by the organization.
ISO/IEC 38500 outlines 11 principles for good governance of IT, as follows:
a) purpose;
b) value generation;
c) strategy;
d) oversight;
e) accountability;
f) stakeholder engagement;
g) leadership;
© ISO/IEC 2026 – All rights reserved
h) data and decisions;
i) risk governance;
j) social responsibility;
k) viability and performance over time.
Adherence to the ISO/IEC 38500 principles requires all data use activities (collection, storage, reporting,
decision-making, distribution and disposal) to be carried out in full alignment with the stated purpose,
strategy and values of the organization and in accordance with compliance requirements, stakeholder and
societal expectations.
ISO/IEC 38500 introduces a model for the governance of IT that establishes governance practices of engaging
stakeholders, evaluating, directing and monitoring activities. This model describes the four main tasks for
governing IT and highlights that “accountability for the governance of IT remains with the governing body
regardless of delegation.” To apply the principles and model to the governance of data, it is necessary to
examine data-specific aspects of governance to the guidance. These aspects apply to all data and should
be considered in understanding data and its impact across the organization. They also highlight the
opportunities that the use of data (particularly with emerging technologies) provides to the organization, as
well as the extra accountabilities that data brings to the governing body.
The data-specific aspects of governance that are introduced in this document are the following.
— Value: Data is the raw material for useful knowledge. Some data may not be very useful, while other
data is extremely valuable to the organization. However, this value is not known until it is used by the
organization and therefore all data is of interest to the governing body that is ultimately accountable
for it. The term “value” in this case also includes the quality and quantity of the data, its timeliness, the
context (which is in itself data) and the cost of its storage, maintenance, use and disposal.
— Risk: Different classes of data bring different levels of risk, and the governing body should understand
the risks arising from poor governance of data and how to direct managers to manage these risks. The
risks not only manifest in data breaches, but also in the misuse of data as well as the competitive risks
involved in not properly utilizing data. Different classes of risk include disaster prevention or disaster
management, climate-related hazards, corruption, and bribery (ISO 37001).
— Constraints: Most data are associated with constraints on use. Some of these constraints are imposed
externally on the organization through legislation, regulation or contractual obligations and include
issues of privacy, copyright, commercial interests and so on. Other constraints on data include ethical or
societal obligations or organizational policies that restrict the use of the data. Strategies and policies are
required to account for these constraints in any use of the data by the organization.
Data and its use by organizations are becoming increasingly important for all organizations and their
stakeholders. By applying the principles, model and data-specific aspects of governance outlined in this
document, governing bodies can take actions that maximize their investment in data use, manage the risks
involved and provide good governance for their organization.
6 Data accountability
6.1 General
Data is a key asset to any organization. It is used to keep track of the business (e.g. people, accounting,
inventory) and as a raw material for knowledge, innovation and insight. The accountability for data and its
use rests with the governing body of the organization.
© ISO/IEC 2026 – All rights reserved
Figure 1 — Governance of data map
NOTE Like any model, this diagram is simplified in order to highlight specific concepts relating to items of
interest for the governing body. The titles of the elements give an indication of the activity and are further explained in
subclauses 6.2 to 6.7.
Figure 1 shows the areas of data accountability within an organization.
For any organization and for any business type, the map identifies the topics that are of interest from a
governance perspective. While the actual processes and implementations are the responsibility of
management, the lines indicate both data flow and a gating mechanism where it is necessary to ensure
governance policies and strategies are in place and accountabilities can be met. The data-specific aspects of
governance in the context of these accountabilities are discussed further in Clause 9.
The focus of this document is the governance of data which should not be confused with the management
of data. Whereas the governing body is concerned with applying the principles of governance as outlined
in Clause 7, the field of data management has well-defined methods for the processing of data as well as
mechanisms for ensuring the confidentiality, integrity and availability of that data.
6.2 Collect
The "collect" activity includes the data acquisition, gathering and creation process, learning from previous
decisions made and additional context extracted from other data sets (internal or external). Collecting data
requires equipment, maintenance and energy. The decision to gather or store date should be considered in
light of sustainability and eco-responsibility obligations.
Data exists in many forms and can be created and collected for use by the organization in different ways,
including the following.
— Data entry: Data entry occurs through internal business systems - Enterprise Resource Planning (ERP)
systems and Customer Relationship Management (CRM) systems - or through external data environments
such as traffic and weather information sources.
— Transactions from other systems and services: Data entry or updating done on external systems can
flow through to the organization’s system through electronic data interchange (EDI), data exchange
networks or other interfacing processes.
© ISO/IEC 2026 – All rights reserved
— Machine-generated and sensor-based data sources: An increasing amount of data is ingested into the
organizations from digital monitoring systems and physical sensors. These include a wide range of data
sources such as web site logs, social media platforms and “internet of things” devices which include
everyday devices from simple temperature sensors to TVs, cars, traffic lights and buildings. Data from
sensors can also include potentially urgent signals such as alerts and alarms.
— New context: Data from reports can be combined with other data to provide additional information,
which is itself fed back into the organization. In many cases, this additional data gives new context to
the original data and may need to be treated differently from the original data. New contextual data
can come from decisions which may give relevance or value to existing data, for example newer data on
climate induced risk, climate action, sustainability, social considerations could be considered.
— Subscription: Data may become available to the organization through a subscription to a data feed or
virtual data store.
6.3 Store
The "store" activity includes locating the data where it can be physically or logically retrieved. This includes
data stored on devices owned and operated by the organization, devices external to the organization and
also virtual stores such as data feeds where the data is only collated when needed. In each case, the stored
data can be retained for reporting purposes pending a decision to dispose.
As data is collected through the above actions, it is ingested into a data store where it is secured and managed
and possibly archived. The amount of data that organizations control is increasing rapidly due to technologies
such as the internet of things that use sensors to collect data, and big data that uses large amounts of data to
look for trends and make predictions using machine learning. Many of these technologies run in public cloud
computing environments where the economies of scale enable large storage and processing capabilities at
much lower cost. In all cases, disconnection from an external storage can be anticipated through causes
such as natural disasters and invasion of the site(s) via illegal activities (data breach). Modification of data
by unauthorised users is also possible.
In some cases, the organization uses a data store that is outside its location. Traditionally, this has been
through offsite hosting operations where the storage is outsourced. Cloud computing takes this to the next
stage where the operation of the store is not visible to the client organization. Furthermore, the organization
may use a “virtual store” where data is provided only as a data feed which can flow directly into reports or
analysis.
It should also be noted that even though the organization may control the data in its store, it may not “own”
that data because of intellectual property rights such as copyright or other legal issues including personal
or health information handling laws. The “ownership” can also be shared or made public in order to promote
data-enabled innovations and data sharing. Special care may also be necessary in understanding the rights
of authorities to request data from organizations and where the storage and use of data cross jurisdictional
boundaries. In either case, the stewardship of data remains with the governing body.
6.4 Report
The "report" activity includes manual or automated extraction and analysis of data for the purpose of
supporting decision making, distribution or disposal.
An important capability of an information system is to extract data from the data store in the form of a
data feed. This feed should have associated properties such as quality and currency of the data so that the
business can determine its usefulness to the reports they produce from that data.
During the extraction and reporting process, many data feeds may be used, and these may come from a
data store within the organization or may come from a virtual data store outside the organization. The
combination of these data feeds m
...



