Skip to content
Atlas
GET IN TOUCH

B://ASSESS18Data Governance

Know what you hold,
and why.

Data governance establishes what information your organisation holds, where it lives, who may use it, how long it is kept, and who is accountable for each answer. It is for organisations facing a privacy obligation, a customer audit, or an AI project that needs trustworthy data.

Most organisations cannot say what personal information they hold, which makes both compliance and AI adoption a guess.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Data inventory

    What you hold, where it lives, and which of it is personal information under the Privacy Act 2020.

  • 02

    Mapped to the frameworks that apply to you

    One set of controls, evidenced against several standards. The Privacy Act 2020 governs how you handle personal information here, ISO 27001 and NIST give you a recognised control framework, NZISM applies if you work with government, and GDPR follows any European personal data you hold. They overlap heavily, and doing the work once against a combined control set is far cheaper than four separate projects.

  • 03

    Ownership

    A named owner per data set, because accountability without a name is not accountability.

  • 04

    Retention and access

    How long each category is kept, what happens at the end, and who may see what by role. Applied automatically rather than documented and forgotten.

Scope, assess, report, support

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Scope

    We agree what is being examined and what a useful answer looks like, so the work is not open-ended.

  2. 02Weeks 2 – 3

    Assess

    Evidence gathered from your systems and your people, because the documented process and the real one rarely match.

  3. 03Week 4

    Report

    Findings written for a decision maker: what is true, what it means, and what we would do about it, ranked.

  4. 04As needed

    Support

    We can hand the report over and step back, or stay and deliver the remediation. Both are normal.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is data governance?

Data governance establishes what information your organisation holds, where it lives, who may use it, how long it is kept, and who is accountable for each answer. It is for organisations facing a privacy obligation, a customer audit, or an AI project that needs trustworthy data.

02What does the Privacy Act 2020 require of a New Zealand business?

In broad terms it sets out thirteen information privacy principles covering how you collect, store, use, disclose, and dispose of personal information, gives people the right to access and correct what you hold about them, makes you responsible for information you send overseas, and requires you to notify the Privacy Commissioner and affected people about a privacy breach that causes serious harm. Practically, the two things most organisations are missing are a current record of what personal information they hold, and a breach process that exists before a breach. For a view on your specific obligations, take legal advice.

03How do the Privacy Act, ISO 27001, NIST, NZISM, and GDPR relate to each other?

They answer different questions about the same material. The Privacy Act and GDPR are law, and govern personal information. ISO 27001 and the NIST frameworks are control frameworks, voluntary but widely asked for in tenders and by insurers. NZISM applies where you handle New Zealand government information. Their requirements overlap a great deal, so the practical approach is one control set, implemented once, with a mapping that lets you evidence it against whichever standard a given customer, auditor, or insurer asks about.

04Does GDPR apply to a New Zealand company?

It can. GDPR follows the data rather than the company, so if you hold personal information about people in the European Union, whether they are customers, staff, or contacts, you may be in scope regardless of where you are based. New Zealand holds an adequacy decision from the European Commission, which makes transfers here considerably simpler than to most countries, but it does not remove your obligations for the data you hold.

05We want to use AI on our data. Why does governance come first?

Because an AI tool pointed at a poorly governed file store will happily surface information to people who were never meant to see it. Permissions that were roughly right when finding a document required knowing where it was become badly wrong when a search tool can retrieve it by meaning. Getting ownership, permissions, and retention right is the unglamorous prerequisite for every AI project that does not end in an incident.

06How long does a data governance engagement take?

An initial inventory and gap assessment for a mid-sized organisation is usually a matter of weeks, and that alone answers most of the urgent questions. Applying retention and access changes across live systems takes longer and is best done in stages. We would rather give you a defensible picture quickly than a perfect one eventually.

07How much does data governance cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with data governance?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver data governance alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to use Atlas for the work the report recommends?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Do you work with organisations outside Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who does the assessment, and who presents the findings?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What do we actually receive at the end?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services