Every growing business ends up with more data than it planned for. And somewhere along the way, nobody's entirely sure what's being collected, where it's sitting, or who's responsible for it.
That's not a sign you're doing something wrong. It's just what happens when a business grows faster than its processes do.
The good news is that data governance for scaling businesses doesn't have to mean a wall of policies nobody reads. It comes down to three things: knowing what you're collecting, using it properly, and being ready for when something goes wrong.
So in one of our latest webinars, we sat down with data protection and operations experts, to get find out what you actually need to know when it comes to data governance, and the practical steps you can take next.
Kayleigh Logan-Cleghorn, Lead DPO @ Trust Keith
Kayleigh is the Lead DPO at Trust Keith, where she leads a team of privacy experts dedicated to helping customers manage data compliance with confidence. Before moving into data protection full-time, she spent over 6 years in operations roles, so she's coming at this from both sides of the fence.
Michelle is the Founder of Standards International and the Business and Operations Management Network. With nearly 30 years' experience in financial services, she's spent her career helping business and operations teams run better, and now champions a dedicated global community built to elevate the value of operations and to support all those in these key roles.
In a small team, everyone roughly knows what's going on. You know who's handling what, which spreadsheet has which numbers, and what's in the CRM. As the business grows, that visibility disappears. Not because anyone's careless, but because there's simply too much ground to cover.
Data tends to follow business activity, not an org chart. It shows up in CRMs, finance spreadsheets, survey tools, support inboxes, and increasingly, in AI note-takers and chat tools. And all usually without anyone deciding, upfront, that it should be collected that way.
"No business sits down and says, 'Right, over the next ten years we're going to capture A, B, C, D, E, F and G.' They don't think about it as part of their strategic plan. Data is almost the last thing they think about. It just appears."
— Michelle Hoskin, Co-Founder & CEO, Business and Operations Management Network
Left unmanaged, this creates a second problem: hoarding. It's a very natural instinct to keep data "just in case it's useful later."
"There's a tendency among a lot of people to just gather as much as they possibly can, like squirrels hoarding for the winter. Get as much data as we can, because you don't know when it's going to be useful. We all turn a bit Gollum-like about it."
— Kayleigh Logan-Cleghorn, Lead DPO, Trust Keith
The problem with hoarding data isn't just clutter. Every extra piece of personal data your business holds has to be found, checked, stored, maintained, protected, reviewed, and eventually deleted. And if you're ever hit with a data breach or a subject access request, the more you're holding that you don't actually need, the more painful that process becomes.
Data minimisation is one of the core principles of UK GDPR: you should only collect personal data that's adequate, relevant, and limited to what's necessary for the purpose you're collecting it for. In plain English, collect what you need, not what you might one day find useful.
That doesn't mean being precious about data. It means being deliberate.
"The key point that I really like is: start from a problem statement. What are we trying to solve? Then decide what data is genuinely needed for that. It needs to be lawful, you need to tell people what you're collecting in plain, transparent language, and critically, why you're collecting it."
— Kayleigh Logan-Cleghorn
A few practical questions to ask before you add a new field to a form, a new tracking event, or a new data source:
If you can't answer the first question clearly, that's usually the sign to leave the field blank.
Collecting more personal data than you need doesn't just create admin. It raises your risk profile.
"My corny little catchphrase is: data protection is people protection. Every single one of those data points is about a person."
— Kayleigh Logan-Cleghorn
If you're processing thousands of records you didn't strictly need, a breach involving that data is a much bigger problem than a breach involving the minimum you actually required. Minimisation isn't just a compliance box to tick, it directly reduces the size of any future incident.
Using data well isn't the risky part. Using it for something it wasn't originally collected for, without thinking it through, is where businesses trip up. Data protection professionals call this "function creep", and it tends to happen gradually, not all at once.
"Data is a superpower. It's your intelligence, it's your indicators, it's everything a business owner and their leadership team need."
— Michelle Hoskin
The clearest example is CCTV. A business installs cameras to prevent theft. Reasonable enough. But then:
"There's a bit of function creep. You install CCTV to prevent crime, but then managers start wanting to review the footage to monitor staff. Clock-in times, disciplinaries, performance issues. There's a gradual creep into: well, how has this just become monitoring?"
— Kayleigh Logan-Cleghorn
Nobody sat down and decided "let's start monitoring employees." It happened one reasonable-sounding request at a time. That's exactly why new tools, new AI features, and new "let's just have a quick look at X" requests need a moment of deliberate thought before they become standard practice.
Before repurposing data you already hold, maybe for a new report, a new AI tool, or a new use case, Kayleigh suggests running it through four checks:
"Is it necessary? Could we do this in another way? Would the person reasonably expect it? And can you clearly explain it? If you can answer those positively, you're good to go."
— Kayleigh Logan-Cleghorn
If the answer to any of those is genuinely "no," that's worth pausing on.Nnot necessarily stopping altogether, but checking whether you need to update your privacy notice, reconsider your lawful basis, or run a data protection impact assessment before you go ahead.
This matters even more where AI is involved. AI note-takers, meeting summarisers, and "interrogate this file for me" tools can quietly expand what a piece of data gets used for, turning a single email into a fully searchable profile. If your business uses any of these tools, people need to know, clearly, when and how AI is going to see and process their data, not just that a call is "being recorded."
Every business experiences a data incident at some point. Emailing the wrong recipient counts. So does a misdirected letter, an over-broad CCTV disclosure, or a laptop left on a train. The ICO's own data on reported incidents shows the most common causes are ordinary, everyday mistakes, not sophisticated attacks.
"The best thing to do is to assume compromise. All organisations will get a data breach at some point, be prepared for it. Know what a data breach looks like, know what you need to do when it comes in, and know when it meets the threshold for reporting to the regulator. None of it needs to be the biggest lift in the world."
— Kayleigh Logan-Cleghorn
Preparation is what determines the outcome, not the breach itself. Businesses with a basic incident process — who's told, what gets logged, how you decide whether it meets the threshold for reporting to the ICO — handle these calmly. Businesses without one tend to lose days figuring out what to do while the problem gets worse.
Data subject access requests are a legal right, and they're increasingly used strategically, particularly by departing employees or in disputes.
That's the real cost of an unprepared business facing a DSAR: it's not the request itself, it's the disruption of scrambling to answer it with no process in place. A clear, repeatable DSAR process turns a genuinely unpleasant experience into a manageable one.
"It's crippling, and it can be done with the wrong intentions. Not somebody actually wanting their data. But we almost had to cease all client service, because all of the manpower was on this one piece of work. I couldn't develop the business, I couldn't grow it. My team were pulling the data together instead. Service stopped. There's the reputational impact, significant management time diverted, business development stopped, decision-making slowed right down, because it was all anyone was focused on."
— Michelle Hoskin
It's also worth knowing that under the Data (Use and Access) Act 2025, UK organisations now have a formal obligation to have a data protection complaints procedure in place. Handling a complaint badly costs you the customer's trust. Handling it well can actually build it.
The businesses that handle all of the above calmly aren't the ones with the most policies. They're the ones who've built data protection into how they already work, rather than treating it as a separate process bolted on afterwards.
Privacy by design (or "data protection by design and default") is a UK GDPR requirement to build data protection into new products, processes, and systems from the outset, not retrofit it once something's already live.
"Good data protection and good operations come from the same principles. If you build data protection into your everyday processes from the start, rather than trying to retrofit it after an incident or after you've grown really quickly, you're on to a winner."
— Kayleigh Logan-Cleghorn
In practice, that means baking privacy checks into procurement (before you sign up to a new tool), HR (before you roll out new monitoring or AI systems), and product development (before a feature ships), rather than running a separate, parallel "compliance process" that everyone tries to avoid.
If there's one habit worth building above all others, it's this:
"Know when to just pause and ask questions, about a new technology, a new type of processing, or a new use of personal data. Knowing when to pause and ask the question is the most valuable skill you can have."
— Kayleigh Logan-Cleghorn
You don't need a DPIA for every decision, or a policy for every process. You need someone in the business who's thinking about it, and who knows when it's worth stopping to check.
Data minimisation is the UK GDPR principle that personal data collected must be adequate, relevant, and limited to what's necessary for its stated purpose. In short, collect only what you need, and be able to explain why you need it.
Data governance is how a business manages the data it holds. Who owns it, where it lives, how it's used, and how decisions about it get made. Good data governance means you always know what personal data you hold and why.
Privacy by design (formally, "data protection by design and default") is a UK GDPR requirement to build data protection into new systems, products, and processes from the outset, rather than adding it on afterwards.
Not every business is legally required to appoint one, but any business processing personal data at scale, especially special category data, or data belonging to customers across multiple countries, benefits from dedicated privacy expertise, whether in-house or outsourced.
More than a hack or a leak. Sending data to the wrong recipient, losing an unencrypted device, or over-disclosing information in a CCTV request can all count. Most reported breaches are everyday mistakes, not sophisticated attacks.
Between hiring, closing deals, and everything else that comes with scaling, it's easy for this to slip down the list. Trust Keith gives you a dedicated privacy expert, so it's one less thing you have to figure out on your own.