Aller au contenu

Spotify - Data Governance Framework

Context

Spotify faces rapidly growing data volumes, increasing regulatory requirements (GDPR, AI Act, Data Act), and rising cybersecurity risks. This project proposes a data governance framework structured around four pillars, supported by a pilot deployment plan.

Current Maturity

Spotify currently sits between Proactive (Level 3) and Managed (Level 4) data governance maturity. Governance already exists at both the global and local levels, but roles are not yet formally defined across the organization.

The five pillars

Pillar Description Details
Data Quality Consistency, accuracy, completeness, and availability of data → Data Quality
Regulatory Compliance Alignment with GDPR, CCPA, and local regulations → Regulatory Compliance
Data Architecture Integration, pipelines, and elimination of silos → Data Architecture
Roles & Responsibilities CDO, DPO, Data Stewards, and organizational governance → Roles & Responsibilities
Data security Proactive Risk Management and key measures → Data security

Data Governance Committee

A Data Governance Committee, composed of representatives from key roles (CDO as chair, Data Stewards, DPO, Head of Engineering oversees the implementation of the framework and ensures its coherence across departments.

See Roles & Responsibilities).

Implementation

The framework rollout follows a progressive approach: a pilot plan is first tested within the Marketing department before a company-wide deployment.

See the pilot plan