DATA GOVERNANCE CONSOLE

Know what data exists, why it exists, who owns it and when it leaves.

The target governance layer makes data classification, legal basis, retention, residency, export and deletion operational rather than burying them in a privacy policy.

Data classExampleDefault handlingControl
Public intelligencePublished institutional capabilityVersioned + provenanceFreshness/review
Organisation confidentialInternal workflow configurationTenant restrictedRBAC + audit
Personal dataUser identity/contact dataMinimise + protectAccess/export/delete
Special-category health dataProduction patient informationNot part of public demoStrict lawful basis, encryption, consent/policy, audit
SecretsAPI/database credentialsNever in page sourceManaged secret store + rotation

Retention schedules

Policy by data class and jurisdiction, not one indefinite retention period.

Data rights

Export, correction, deletion/anonymisation and consent withdrawal workflows where applicable.

Residency

Track where production data is stored and which subprocessors receive it.

Ownership

Assign business and technical owners for every governed dataset.