learn-data-governance-with-phoebe / Exec session 3 of 4
Learn Data Governance with Phoebe · Executive track · Session 3 of 4

Five questions to ask your data team

You cannot audit the pipelines yourself - and you don't need to. Five questions, asked in the right order, tell you everything about your data risk. This is the interrogation kit.

🟡 Exec track C-level & boards No tech required The interrogation kit 30 min self-read · 45 min live
0-3 · Welcome 3-25 · The five questions 25-42 · The boardroom moment 42-45 · Q&A
Part 0

You don't need to see the pipelines

Executives get talked out of asking data questions because the answers arrive wrapped in architecture diagrams. Ignore the wrapping. Data risk reduces to five questions any leader can ask in thirty minutes, no technical vocabulary required. For each one, this session gives you why it works, what a pass sounds like, and what a shrug is actually telling you. The shrug, it turns out, is the most informative answer in the set.

Live - presented in session Self-study - read after class ★ Ask it in your next meeting PDPA-primary · GDPR mirror
★ What you walk out with today The five questions in the right order, a pass-versus-red-flag key for each, a scoring system that turns the answers into a funding decision, and the meta-signal that matters more than any single answer: whether your team responds with documents or with vibes.
Part 1 · the interrogation kit

The five questions, in order 14 min live

Ask them in sequence - each one only makes sense if the one before it has an answer. Together they walk the whole lifecycle of your data: what you hold, whether you may use it, what happens when it leaks, when it dies, and who answers for it.

1 What personal data do we hold, and where? Pass: a living inventory with an owner. Red flag: "it's mostly in the warehouse." 2 Who said we could use it this way? Pass: consent and purpose records you can open. Red flag: "users clicked accept at some point." 3 Are we breach-ready? Pass: a drilled playbook, named roles, clocks known cold. Red flag: "IT handles security." 4 How long do we keep it - and does data actually die? Pass: a retention schedule with real deletion. Red flag: "storage is cheap." 5 Who owns each dataset? Pass: named owners plus a steward doing the day-to-day. Red flag: "the data team." One point per confident, documented answer. Bring the score to session 4 - it prices your program.
🔍 Click to zoom - the five questions and what a pass sounds like
LiveQ1 · What personal data do we hold, and where?3 min

Why it works: every other promise your company makes about data - keeping it safe, deleting it, honouring consent - is impossible without knowing what and where it is. This question tests the foundation everything else stands on.

  • A pass sounds like: "Here's the inventory - what we hold, where it lives, why we have it, who owns it. Updated last quarter." The formal version is called a record of processing; your practitioners build one in DPO session 3.
  • The red flag: "It's mostly in the warehouse." Mostly is doing a lot of work in that sentence, and none of it is reassuring.
Real world

At Himalaya, from your chair as CEO: personal data on 8 million consumers is scattered across forty-plus warehouse schemas and three SaaS tools, and when you asked this exact question, the room produced a diagram of the pipelines but not a list of the data. A map of the plumbing is not a map of what's in the pipes.

LiveQ2 · Who said we could use it this way?3 min

Why it works: holding data legally and using it legally are different things. This question tests the two promises from session 2 that trip companies most - consent and purpose. Data collected to deliver a service does not automatically become fuel for marketing, analytics, or your next AI feature.

  • A pass sounds like: "Consent captured at signup, purpose statements on every form, records in the CRM - here's one." Openable records, tied to actual people.
  • The red flag: "Users clicked accept at some point." At some point. On some version of some form. Covering some uses. That answer has funded a lot of regulatory enforcement.
Real world

At Himalaya, the 8-million-consumer marketing list runs on exactly this vintage of consent - nobody can say which consumers agreed to what, or when. You met this risk in session 2 as Ilsa's campaign problem; this question is how you would have found it a year earlier.

LiveQ3 · Are we breach-ready?3 min

Why it works: breaches are a when, not an if - so this question tests preparation, which is measurable, instead of prevention, which is a wish. Readiness also happens to be what regulators weigh most heavily after an incident.

  • A pass sounds like: "There's a playbook, we drilled it in March, these three people run it, and the clocks are on the wall: assess within 30 days, notify the regulator within 3 if it's notifiable." Named roles, real rehearsal, deadlines known cold.
  • The red flag: "IT handles security." A breach is a whole-company incident with a legal clock - the moment your team frames it as an IT matter, you know nobody has thought past the firewall.
Real world

At Himalaya, a misconfigured export left consumer records - including health notes - exposed for six days before anyone noticed. Nobody knew whose job it was to notice. That is what an honest "no" to this question looks like in the wild; your practitioners drill the full response in DPO session 5.

LiveQ4 · How long do we keep it - and does data actually die?3 min

Why it works: every record you hold is risk on the balance sheet - it can leak, be subpoenaed, or show up in a headline. Data you no longer need is risk with no offsetting return. This question tests whether anyone in your company ever deletes anything on purpose.

  • A pass sounds like: "There's a retention schedule - this data type lives this long, then it's deleted, and here's the log showing deletion actually runs." The second half matters: schedules without deletion are decoration.
  • The red flag: "Storage is cheap." Storage is cheap. Liability is not. That answer confuses the cost of keeping data with the cost of holding it.
Real world

At Himalaya, consumer data belonging to clients who left the platform years ago still sits in the warehouse - people with no relationship to the company, whose data can now only ever hurt it. Retention policy: "keep everything." Which is to say: none. The fix is built in DPO session 6.

LiveQ5 · Who owns each dataset?3 min

Why it works: this is the thirty-second test from session 1, weaponised. Every strong answer to questions 1 through 4 depends on someone being accountable for each dataset. No owner, and every fix you fund this year quietly decays by next year.

  • A pass sounds like: "Customer data - owned by the VP of Customer Success, stewarded day-to-day by a named person on her team. Here's the full owner list." Names, not org boxes.
  • The red flag: "The data team." A team name is where accountability goes to hide. The data team runs the systems; owning what the data means and who may use it is a business job - and if it belongs to everyone, it belongs to no one.
Real world

At Himalaya, Raj's platform team "owns" all forty-plus schemas - meaning they keep the pipelines running while nobody decides what's allowed. When you asked who approved keeping ex-clients' data forever, the answer was silence. Ownership with names is what DPO session 7 builds.

Part 2 · scoring

Reading the answers 6 min live

The questions are half the kit. The other half is knowing what to do with the answers - and noticing the signal underneath them.

5 of 5 Fund maintenance and re-ask next year 3 - 4 Fund the fixes you now know which ones 0 - 2 Fund a program your competitors likely scored the same Answered with documents ✓ Answered with vibes ◐ Answered with a shrug ✗ The meta-signal: HOW your team answers matters more than what they say.
🔍 Click to zoom - the score bands and the documents-vibes-shrug signal
LiveThe score is a funding decision4 min

Score one point per question answered confidently, with documents. Then the score tells you what to fund:

  • 5 of 5: rare and excellent. Fund maintenance - governance decays without care - and re-run the interrogation annually so it stays true.
  • 3 to 4: the healthy-company norm. You now know precisely which gaps to fund, which beats every consultant's assessment you could commission.
  • 0 to 2: you have a program to start, not a crisis to panic over. The genuinely good news: most of your competitors would score the same - which means moving first is available.

And watch the texture of the answers, not just the count. Documents beat vibes, vibes beat shrugs. A team that says "here's the schedule, here's the log" has a system. A team that says "we're generally pretty careful" has a culture, which evaporates with its next resignation. A shrug is the most honest answer you'll get all day - it tells you exactly where the risk lives, free of charge.

Self-studyThe maturity idea, in one paragraph1 min read

What you just did informally, the industry does formally: capability maturity scoring. Frameworks exist for it - DCAM from the EDM Council is the best known - where a team self-scores each governance capability and repeats the exercise yearly to show progress. The full framework is member-gated, so we teach the concept honestly rather than inventing its contents; your practitioners get the scoring concept in DPO session 7. The exec version needs one sentence: ask your team for a one-page scorecard, refreshed annually - your five-question score is the napkin edition, and it is a perfectly respectable napkin.

The boardroom moment

Run the interrogation ★ 15 min · work it live

This one isn't hypothetical. You are Mara, the five questions are printed, and Raj - Head of Data - has thirty minutes on your calendar. Here is exactly how to run it.

Schedule 30 minutes with your data lead. Frame it honestly: "I want to understand our data risk - five questions, no prep, no slides." No prep is the point; you want the real state, not the rehearsed one.

Ask the five in order, and resist the urge to soften them. Silence after a question is data. Let it sit.

Note each answer as document, vibes, or shrug. Three columns on one page. Don't argue with any answer, don't fix anything live - you are measuring, not managing.

Score it: one point per confident, documented answer. Then place yourself on the band: 5 fund maintenance, 3-4 fund fixes, 0-2 fund a program.

Pick ONE question to fund fixing first. Not all five - one. Usually the worst-scoring one, since each question underpins the next. That single choice becomes the memo you'll write in session 4.

★ Ask it in your next meeting - the answer-reading promptYou are my data protection adviser. I just asked my data team five questions: (1) what personal data do we hold and where, (2) who said we could use it this way, (3) are we breach-ready, (4) how long do we keep it and does data actually die, (5) who owns each dataset. Here are their raw answers, roughly as spoken: [paste the answers, one per question - include the hedges and the "I think"s, they matter]. Give me: 1. A pass / vibes / red-flag verdict on each answer, with the one detail that decided it 2. The two follow-up questions most likely to expose whether the good answers are real 3. An overall risk read in three sentences of plain business language - no legal citations 4. Which ONE of the five I should fund fixing first, and why that one unlocks the others Be blunt. If an answer is confident but content-free, say so.
Why no prep beats prepared A prepared session tests your team's slide-making. An unprepared one tests your company. You are not trying to catch anyone out - you're finding out what would surface in the first hour of a real incident, while it's still cheap to know.
Homework

Run it for real ◐ 45 min total

Source material

What this session covers

Each question fronts a discipline your practitioners build hands-on in the 8-session DPO track on this site - sessions 3 through 7. You get the interrogation; they get the machinery.

Data inventory / record of processing - Q1Exec-level; built for real in DPO session 3
Consent + purpose records - Q2Exec-level; the fix in DPO session 4
Breach readiness + the PDPA clocks - Q330-day assess / 3-day PDPC; drilled in DPO session 5
Retention + real deletion - Q4Exec-level; schedule built in DPO session 6
Ownership + stewardship - Q5Exec-level; operating model in DPO session 7
Maturity scoring (DCAM concept)Concept only - the framework is member-gated; DPO session 7
Check yourself

Three questions before you go 🎯 ◐ 90 seconds

1 · You've asked the five questions. The strongest signal of your real risk is...

How people answer beats what they say. Documents mean a system; vibes mean a culture that leaves with its next resignation; a shrug is a free risk report.

2 · "Storage is cheap - we keep everything." That answer is...

Storage is cheap; liability is not. Every record you no longer need can still leak, be subpoenaed, or headline - encryption doesn't change whether you should hold it at all.

3 · "Who owns the customer dataset?" - "The data team." That answer is...

The data team runs the plumbing. Deciding what the data means and who may use it is a business accountability - it needs a name, not an org box.

Exec session 3 cheat sheet · pin this

Q1 · What personal data do we hold, and where?Red flag: "it's mostly in the warehouse."
Q2 · Who said we could use it this way?Red flag: "users clicked accept at some point."
Q3 · Are we breach-ready?Red flag: "IT handles security."
Q4 · How long do we keep it - and does data actually die?Red flag: "storage is cheap."
Q5 · Who owns each dataset?Red flag: "the data team."
The scoring5 = fund maintenance · 3-4 = fund the fixes · 0-2 = fund a program (so did your competitors).
The meta-signalDocuments beat vibes, vibes beat shrugs. How they answer > what they say.
The clocks your team should know coldAssess a breach within 30 days; notify the PDPC within 3 days if it's notifiable.