The purpose of this Data Governance (DG) Framework is to establish the guiding principles, governance structure, roles and responsibilities, and processes required to manage institutional data as a strategic asset. The framework supports consistent, secure, and ethical handling of data across McMaster University.
This Framework applies to all institutional data created, collected, stored, processed, and reported by the University. It includes student data, HR data, financial data, and system-generated data.
Administrative data related to research grants and publications generated are considered in scope of Data Governance. However, research data collected and created through research or scholarly activities are out of scope and generally covered by best practices in Research Data Management (RDM) Framework.
In recognition of Indigenous Data Sovereignty principles, data pertaining to Indigenous Peoples, communities, and Nations may be subject to distinct governance requirements and authorities. Where applicable, the governance, stewardship, access, and use of Indigenous data will be guided by relevant Indigenous governance frameworks, agreements, and protocols. Such data may fall outside the authority of the McMaster Data Governance Framework or require additional governance processes established in partnership with Indigenous communities.
The McMaster Data Governance Program works collaboratively with the IT Security and Privacy offices which retain final authority within their respective domains.
McMaster University’s vision emphasizes excellence, transformation, and community impact. Data Governance enables these objectives by ensuring that data is accurate, secure, accessible, and trusted to support evidence-based decision making and institutional planning.
Accessibility – Authorized users can access data they require to support the performance of their duties.
Accountability – Clear ownership and responsibility for data.
Authorized Use – Ethical and legal use of data.
Availability – Data is available to support operations.
Compliance – Alignment with regulations and policies.
Efficiency – Streamlines processes for data management.
Effectiveness – Data supports institutional outcomes.
Fit for Use – Data meets quality standards.
Protection – Safeguards protect data across its lifecycle.
Respect – Protection of personal information and privacy.
Security – Data is secured against unauthorized access.
Trust – Transparent and reliable data management.
Transparency – Data processes, decisions, and lineage are openly communicated to ensure clarity, traceability, and confidence in how data is managed.
Adaptability – Governance supports rapid adjustments to the data ecosystem to meet evolving institutional needs and strategic priorities.
Enablement – Fostering an environment where data can support strategic goals.
The governance structure includes the Executive Sponsors, Steering Committee, the Data Governance Council (DGC), Data Governance Networking Group, and operational roles such as Data Stewards, Data Custodians, Data System Stewards, Privacy Office, IT Security, and other Data Governance Support Units. These groups collectively ensure strategic oversight, operational consistency, and compliance.
The DGC includes representation from the following domain areas:
Financial Affairs, Human Resources, Institutional Research and Analysis (IRA), Office of the Registrar, University Library, University Technology Services (UTS), University Secretariat – Privacy Office, and Guests – As required.
This section defines the formal responsibilities for individuals and bodies involved in Data Governance. Data Governance RACI document is enclosed in the Supporting Documents section.
The Data Governance Program prioritizes Stewardship, Data Classification, and Metadata Management through the University’s data catalogue, the Data Cookbook. These components provide foundational support for consistent data use, documentation, and risk management.