Governance, privacy, and security

Governance done right is an operating capability: everyone knows who owns each domain, what each metric means, where each number came from, and who can see what. Done wrong, it’s a compliance binder nobody opens. I build the first kind, and I’ve done it inside a regulated bank, a global media company, and a ticketing platform holding PII across 9 jurisdictions.

What’s usually broken

  • Definitions disagree. Revenue means 3 things in 3 dashboards, and every executive meeting starts with an argument about whose number is right.
  • Nobody owns anything. Critical domains have no named owner, so quality problems bounce between teams until they land on nobody.
  • PII is wherever it landed. There’s no inventory and no classification, and the access controls were never designed for it.
  • Audits are fire drills. Every regulator or customer security review triggers a scramble because evidence isn’t produced continuously.
  • Governance arrived after AI. Models and agents already query data that was never classified, with permissions nobody scoped.

What I do

  • Governance programs: ownership and stewardship models, business glossary, data catalog, and lineage, run as one program rather than 4 disconnected tools.
  • Privacy and compliance: PII inventory and remediation, consent management, and regulatory frameworks across GDPR, UK-DPA, CCPA/CPRA and other US state regimes, HIPAA, and SOC 2.
  • Access control and security: RBAC design, column and row-level security, classification taxonomies, and data-sovereignty patterns for cross-border estates.
  • Data quality as infrastructure: automated quality checks, data contracts, and quality SLAs wired into pipelines rather than run as an annual cleanup.
  • AI governance: extending the governance program to model and agent access, so sensitive columns stay out of prompts and embeddings, and every model invocation is attributable and auditable.

How it works

Governance fails when it’s imposed as ceremony, so I scope it to the decisions it has to support and the regulations it has to satisfy, then build the smallest set of artifacts that does both. Policies, glossary, lineage, ownership registries: real systems, maintained where the work happens.

Proof

At Goldman I ran governance for Marcus to a regulated bank’s standard: lineage and catalog for audit-readiness, contracts and quality SLAs on regulated datasets, daily reconciliation on transaction streams, and a model-risk partnership for credit data. At TelevisaUnivision I ran PII inventory, remediation, RBAC, and a CCPA/CPRA framework as a single program that passed its audits. At AXS I completed a full-estate PII inventory and operationalized privacy across a 9-jurisdiction consent matrix on OneTrust, with automated quality on Great Expectations and lineage in DataHub.

Start a conversation

If a regulator asked tomorrow where a specific customer’s data lives, how long would the answer take? If the honest answer is weeks, start here.

sandro@engramdataworks.com