Data Governance Policy

1. Purpose

The purpose of the Data Governance Policy is to:

  • Define the roles and responsibilities for different data usage and establish clear lines of accountability.
  • Develop best practices for effective data management and protection.
  • Align with the applicable policies that ensure the protection of the company’s data against internal and external threats (e.g. breach of privacy and confidentiality).
  • Ensure that the company complies with applicable laws, regulations, and standards.
  • Ensure that a data trail is effectively documented within the processes associated with accessing, retrieving, reporting, managing, and storing data.

2. Roles and Responsibilities

See Data Governance Hierarchy (Section 5.1.3) below

3. Scope

This policy applies to all company data used in the administration of the company and all its business units. This policy covers, but is not limited to, the company’s data in any form, including print, electronic, audio-visual, and backup and archived data. This policy applies to all EON associates, contractors, consultants, temporaries, and other personnel using and accessing EON data in print or stored within its information processing and communications equipment.

4. Background Information

Institutional data is a strategic asset of EON and the appropriate governance for management and use of data is critical to the company’s operations. Inappropriate governance can result in inefficiencies and exposes the company to unwanted risk. A consistent, repeatable, and sustainable approach to data governance is therefore necessary in order to protect the security and integrity of the company’s data assets.

5. Policy Statement

5.1. Definitions and Terms

To establish operational definitions and facilitate ease of reference, the following terms are defined:

5.1.1. Access: the right to read, copy or query data.

5.1.2. Data: a general term used to refer to the company’s information resources and administrative records, which can be assigned to one of four categories:

  • Public access data: data that is openly available to all staff and the general public.
  • Internal general data: data used for company administration activities and not for external distribution unless otherwise authorized.
  • Internal protected data: data that is only available to staff with the required access in order to perform their assigned duties.
  • Internal restricted data: data that is of a sensitive or confidential nature and is restricted from general distribution. Special authorization must be approved before access or limited access is granted.

5.1.3. Data Governance Hierarchy: outlines the access rights, roles, and responsibilities of EON staff in relation to the management and protection of data (see section 5.4 for the assignment of these roles within EON):

  • Data Trustee: a member of the Executive Team with planning and decision-making authority for EON’s institutional data. The Data Trustee is responsible for overseeing the continuous improvement of the company’s data governance and management.
  • Data Manager: a senior staff member who oversees the capture, maintenance, and dissemination of data for the company. Data Managers are responsible for assuring the requirements of the Data Governance Policy is followed within the company. The Data Manager is responsible for day-to-day data administration activities, including, but not limited to, developing, maintaining, distributing, and securing institutional data. They are expected to have high-level knowledge and expertise in the content of data within their responsible area.
  • Data User: any staff or authorized agent, who accesses, inputs, amends, deletes, extracts and analyses data in order to carry out their day-to-day duties. Data Users are not generally involved in the governance process but are responsible for the quality assurance of data.

5.1.4. Data Management Life Cycle: refers to the process for planning, creating, managing, storing, implementing, protecting, improving, and disposing of all institutional data of the company (see Section 5.3).

5.1.5. Integrity/Data Integrity: refers to the accuracy and consistency of data over its entire life cycle.

5.1.6. Member of the Executive: defined as the positions which normally report to either the Chief Operating Officer, Chief Technology Officer, or Chief Strategy Officer of the company, having staffing and supervisory responsibilities.

5.1.7. Quality/Data Quality: refers to the validity, relevancy, and currency of data.

5.1.8. Security: refers to the safety of company data in relation to the following criteria:

  • Access control.
  • Authentication.
  • Effective incident detection, reporting and solution.
  • Physical and virtual security; and
  • Change management and version control.

5.2. Policy Principals

The following principles outline the minimum standards that guide the company’s data governance procedures and must be adhered to by all EON staff:

5.2.1. EON, rather than any individual or Business Unit, is the owner of all data. A Data Trustee has the responsibility for the management of data assigned within their portfolio and is responsible for the overall management of the company’s data governance.

5.2.2. Every data source must have a Data Manager who is responsible for the quality and integrity, implementation, and enforcement of data management within their Business Unit. Data Managers are responsible for ensuring effective local protocols are in place to guide the appropriate use of data.

5.2.3. Access to, and use of, institutional data will be administered by the appropriate Data Manager.

5.2.4. The Data Manager, having determined the category of the institutional data as confidential, will approve access based on the appropriateness of the Data User’s role and the intended use. Where necessary, approval from the Data Trustee may be required prior to authorization of access.

5.2.5. The Data Manager must ensure the process for the administration of data is in accordance with the Data Management Life Cycle (See Section 5.3).

5.2.6. The Data Users must ensure appropriate procedures are followed to uphold the quality and integrity of the data they access.

5.2.7. Data records must be kept up to date throughout every stage of the workflow and in an auditable and traceable manner.

5.2.8. Data for all clients will remain logically separated within the CRM master clients’ database, which is architected from a performance standpoint for multi-tenancy. The solution is designed with embedded security to ensure individual client data integrity and prevent cross-pollination.

5.2.9. Data should only be collected for legitimate uses and to add value to the company.

5.2.10. Extraction, manipulation, and reporting of data must be done only to perform company business. This direct access to the data stores to manipulate the data is limited to authorized personnel only. End users access the data through predefined applications, reports, and dashboards.

5.2.11. Personal use of institutional data, including derived data, in any format and at any location, is prohibited.

5.2.12. Where appropriate, before any data (other than publicly available data) is used or shared outside the company, prior approval by the Data Trustee and verification with the Data Manager is required to ensure the quality, integrity and security of data will not be compromised.

5.2.13. Data stored in an electronic format must be protected by appropriate electronic safeguards and/or physical access controls that restrict access only to authorized user(s). Similarly, data in hard copy format must also be stored in a manner that will restrict access only to authorized user(s).

5.2.14. Appropriate data security measures must be adhered to at all times to assure the safety, quality, and integrity of company data.

5.2.15. The definition and terms used to describe different types of data should be defined consistently across the company.

5.2.16. Data shall be retained and disposed of in an appropriate manner in accordance with the company’s Records Management Policy.

5.3 Data Management Life Cycle

6. Related Policies and Procedures

A. Corporate Data Security Policy B. Record Management Policy