Data Strategy pillar

Make data usable, governed, and portable

Connect data ownership, quality, access, interoperability, privacy, retention, migration, and exit requirements into one operating model instead of separate documentation exercises.

Regulatory and interoperability requirements change. Treat dated research as publication context and verify current obligations and technical specifications at the authoritative source.

Start with the data lifecycle

Know what data exists, why it exists, and who can decide

A data strategy becomes operational when ownership, purpose, quality, access, movement, retention, evidence, and disposition are clear enough to test.

Inventory and purpose

Identify authoritative datasets, source systems, derived data, purpose, sensitivity, records status, consumers, dependencies, and known quality limitations.

Ownership and stewardship

Separate business ownership, technical custody, privacy/security responsibilities, quality stewardship, and approval authority so decisions have accountable owners.

Access and interoperability

Define identity, authorization, interfaces, schemas, contracts, lineage, validation, versioning, and downstream-use expectations instead of relying on informal exports.

Retention and exit

Specify retention, legal holds, archival, deletion, export, migration, evidence preservation, and provider-exit requirements before the data becomes trapped in a workflow.

Governance evidence

Turn data policy into observable operations

Policies are easier to defend when the organization can show who approved access, how quality is measured, where data moved, and what happened when requirements changed.

Evaluation brief

Capture the users, data classes, interfaces, constraints, evidence needs, risks, and unknowns for a data platform or workflow decision.

Build the brief

Security assurance

Require evidence for access, encryption, data handling, logging, vulnerability management, incident response, resilience, and subprocessors.

Use the security questionnaire

Accessibility

Data-driven portals, dashboards, forms, and generated interfaces still need usable and testable accessibility evidence.

Review accessibility evidence

Decision scoring

Weight governance, interoperability, quality, portability, security, operations, and cost before demonstrations shape the criteria.

Use the scorecard
Portability and continuity

Prove the data can move before you need it to

Migration readiness

  • Confirm export rights, formats, APIs, schemas, attachments, history, and audit data.
  • Define mapping, validation, reconciliation, cutover, rollback, and acceptance evidence.
  • Identify identity, integration, retention, and records dependencies.

Exit readiness

  • Test repeatable exports rather than relying on contract language alone.
  • Preserve documentation, lineage, decisions, and operational knowledge.
  • Define deletion confirmation and post-termination access boundaries.
Dated research

Published data strategy briefings

Use these for the legal, standards, product, and interoperability context available at publication. Verify current law, regulator guidance, specifications, and product behavior before making a present-day decision.

Verify at the source

Data governance and interoperability references

Use current official sources to confirm legal scope, version status, and implementation requirements.

For sector-specific interoperability requirements, use the responsible regulator or standards body for the exact jurisdiction and workflow. See editorial standards for source hierarchy and historical-content handling.