In The Matrix, the operators don’t watch the war unfold in three dimensions. They sit in front of a black screen and read a waterfall of green symbols — numbers, letters, no faces, no rooms — because rendering the whole simulated world just for the people watching it from outside would waste memory nobody has. Tank and Dozer don’t see Neo dodging bullets. They see rain. They’ve trained themselves to read the rain and know, somehow, that it means a hallway, a gun, an exit.
Ask anyone in a large organisation what data actually is, and you get the same rain. Everyone can point at a column of it. Almost nobody can tell you what the whole screen shows.
We default to thinking of data as a noun. A table. A file. A dataset you request access to, borrow for a quarter, hand back. That’s not wrong, exactly, it’s just the view from one terminal. The more accurate picture is data as a verb: a continuous flow of bits crossing the entire organisation at every moment, in every direction. A transaction. A sensor reading. A click. A form abandoned halfway through. A call transcribed by an API somewhere and forgotten. A permission granted eighteen months ago by someone who has since left. Data doesn’t sit still long enough to be a thing. It’s weather, not furniture.
For years this didn’t matter much, because the only people asking serious questions about data were analytics teams, and analytics teams have always operated on the “borrowing” model. They take a slice, do something clever with it, give it back. The slice was the unit of concern. Nobody needed a map of the whole rainfall, because nobody was being asked to produce one.
Then regulation changed the question. It stopped asking “what did you do with this dataset” and started asking “where is this customer’s data” — full stop, no slice, no quarter, the entire flow from the moment it entered the organisation to every system, backup, log file, spreadsheet, and vendor contract it has touched since. That question doesn’t belong to analytics. It doesn’t really belong to IT either, or to the business, or to legal. It belongs to all of them at once, which in most organisations is another way of saying it belongs to no one.
This is the part I think is worth sitting with, more than the part where we try to solve it. Once you accept that data is an end-to-end flow rather than a set of stored objects, you run straight into a question nobody’s org chart was built to answer: who is accountable for a flow? We know how to assign ownership to a system. We know how to assign a steward to a dataset. We do not have a native concept for assigning responsibility to something that has no fixed location, touches forty departments, and outlives most of the people who ever handled it. Governance committees get formed to fix this and mostly end up as rooms full of people with no actual decision rights, reporting to someone two levels below where the authority to decide anything lives.
So the honest answer, today, in most organisations, to “who’s accountable for the customer’s data, end to end” is: nobody is watching the whole screen. There are dozens of people watching their own column of rain very carefully, and each of them is quietly assuming someone else has the wide shot.
I don’t think this piece needs to end with a framework. I’ve read enough of those, and written a few. The point isn’t the fix. The point is that we’ve spent a decade building regulation for a question — where is the data — that presupposes an answerer who doesn’t yet exist in most organisational structures. We built the question before we built the operator’s chair.
Nobody’s unplugged. Nobody can see the room.
Sources: Dataversity, “Why Data Governance Fails in Many Organizations” (accountability crisis and IT-business divide, 2024-26 analysis); The Data Governor, “Data Steward vs Data Owner vs Data Custodian” (2026).




Leave a Reply