Spotify - Data Governance Framework¶
Context¶
Spotify faces rapidly growing data volumes, increasing regulatory requirements (GDPR, AI Act, Data Act), and rising cybersecurity risks. This project proposes a data governance framework structured around four pillars, supported by a pilot deployment plan.
Current Maturity¶
Spotify currently sits between Proactive (Level 3) and Managed (Level 4) data governance maturity. Governance already exists at both the global and local levels, but roles are not yet formally defined across the organization.
The five pillars¶
| Pillar | Description | Details |
|---|---|---|
| Data Quality | Consistency, accuracy, completeness, and availability of data | → Data Quality |
| Regulatory Compliance | Alignment with GDPR, CCPA, and local regulations | → Regulatory Compliance |
| Data Architecture | Integration, pipelines, and elimination of silos | → Data Architecture |
| Roles & Responsibilities | CDO, DPO, Data Stewards, and organizational governance | → Roles & Responsibilities |
| Data security | Proactive Risk Management and key measures | → Data security |
Data Governance Committee¶
A Data Governance Committee, composed of representatives from key roles (CDO as chair, Data Stewards, DPO, Head of Engineering oversees the implementation of the framework and ensures its coherence across departments.
See Roles & Responsibilities).
Implementation¶
The framework rollout follows a progressive approach: a pilot plan is first tested within the Marketing department before a company-wide deployment.