Governance frameworks people actually follow — mapped to POPIA and GDPR.

Agilus designs and implements data governance for enterprises: policies, ownership, data classification, lineage, retention and access control, mapped to your POPIA and GDPR obligations. The work covers the Data Governance, Data Security and Metadata Management knowledge areas of DAMA-DMBOK2.

Why data governance programmes fail

Most governance programmes die one of two deaths. Either they produce a policy library nobody reads — governance as documentation — or they create a committee with no decision rights — governance as theatre. Both leave the actual data exactly as ungoverned as before.

What our governance engagement delivers

Governance framework and policies

A practical framework — principles, policies, standards — sized to your organisation. Short enough to be read, specific enough to be enforced.

Ownership and stewardship

Data domains mapped, owners named, steward roles defined with time commitments their managers have agreed to. Governance that fits inside real jobs.

POPIA and GDPR compliance by design

Data classification, records of processing, retention schedules, lawful-basis mapping, access controls and breach-response readiness — built into how data is managed, not bolted on for the auditor. For organisations processing European data, the same design extends to GDPR.

Sequenced roadmap and business case

What to do first, what it costs, what it unlocks — sized in rand terms a CFO can interrogate.

Measurement

Governance maturity scored against DAMA-DMBOK2 via DM360, so the board sees progress as a number, not an assurance.

Common questions

What is data governance?

Data governance is the exercise of authority and control over the management of data: who owns it, what policies apply to it, how quality and security are enforced, and how decisions about it are made. It is the first knowledge area of the DAMA-DMBOK2 framework, and the foundation the other ten depend on.

The Protection of Personal Information Act requires organisations to process personal information lawfully and transparently: knowing what personal data they hold and why, securing it appropriately, retaining it no longer than needed, honouring data-subject rights, and being able to demonstrate all of this. In practice that demands data classification, records of processing, retention schedules, access control and breach-response procedures — the core deliverables of a governance programme.

Data management is the whole discipline of handling data as an asset — quality, architecture, integration, storage, analytics and more. Data governance is the authority layer above it: the policies, ownership and decision rights that direct how the rest is done. DAMA-DMBOK2 places governance at the centre of its eleven knowledge areas for exactly this reason.

Govern the data before someone else asks why you didn't

Take the free 6-minute AI Readiness Scorecard

1