Data owner vs data steward vs data custodian: who is accountable for what
The data owner is accountable, the data steward manages definitions and quality, the custodian runs the systems. How to assign the roles in Luxembourg.
Key takeaways
- A data owner is a senior business person accountable for a data domain; a data steward runs its definitions, quality and documentation day to day; a data custodian operates the systems that store and protect it.
- GDPR Article 5(2) has made the controller responsible for demonstrating compliance since 25 May 2018, and the DPO's monitoring tasks under Article 39 explicitly include the assignment of responsibilities.
- DORA, applicable in Luxembourg since 17 January 2025 and supervised by the CSSF and the CAA, requires financial entities to identify and document roles and responsibilities alongside their information assets.
- Article 10 of the AI Act requires documented data governance practices for high-risk AI training data; after the Digital Omnibus (Regulation (EU) 2026/1744), these obligations apply from 2 December 2027 for Annex III systems.
- The most common mistake is naming IT as data owner: IT can be custodian, but it cannot decide what a customer or a valid record is.
In a Luxembourg organisation, the data owner is the senior business person accountable for a data domain, the data steward looks after that domain’s definitions, quality and documentation day to day, and the data custodian runs the systems that store and protect it. Since GDPR’s accountability principle (in force since 25 May 2018) and DORA (applicable since 17 January 2025), supervisors expect named people behind these roles, not a generic reference to “IT”.
Three roles, three questions
The vocabulary varies between frameworks, but the split is stable. DAMA-DMBOK, the reference body of knowledge of DAMA International, treats data stewardship as the formalisation of accountability and responsibility for data. The UK government’s data ownership model, published by the Government Digital Service, defines the same three roles in plain terms and is a useful public reference.
| Data owner | Data steward | Data custodian | |
|---|---|---|---|
| Question answered | What should this data mean, who may use it, how good must it be? | Is the data actually meeting those rules today? | Is the data stored, secured and available as required? |
| Typical seniority | Head of a business function or domain | Specialist or team lead who uses the data daily | IT, database or platform team, or an outsourced provider |
| Decides | Definitions, quality targets, access, retention | Day-to-day triage and corrections within agreed rules | Technical implementation within the owner’s requirements |
| Typical domains | Customer, supplier, product, finance, HR | Same domain as the owner | Systems spanning several domains |
The UK model states the principle bluntly: data ownership is the responsibility of the business and not the technology domain. It also stresses that ownership is shared across levels, with senior owners delegating tasks to stewards.
A RACI for the core activities
RACI stands for Responsible (does the work), Accountable (answers for the outcome, one person only), Consulted and Informed. A workable starting matrix for one data domain:
| Activity | Owner | Steward | Custodian |
|---|---|---|---|
| Approve business definitions and the glossary entry | A | R | I |
| Set data quality rules and thresholds | A | R | C |
| Monitor quality and coordinate fixes | I | A/R | C |
| Approve access requests | A | C | R |
| Implement access controls, backup, encryption | I | C | A/R |
| Decide retention and deletion | A | C | R |
| Keep the GDPR record of processing current for the domain | A | R | C |
| Approve changes to structure or source systems | A | C | R |
The “A” sits with the owner for almost every decision. That is the point: accountability is concentrated, while the work is distributed.
Why regulation makes named ownership necessary
GDPR. Article 5(2) makes the controller “responsible for, and able to demonstrate” compliance. Article 24 requires appropriate technical and organisational measures, and Article 30 requires a record of processing activities. None of this uses the word “owner”, but demonstrating compliance for each processing activity is hard without a person who answers for it. The Commission nationale pour la protection des données (CNPD) monitors and enforces GDPR in Luxembourg. Article 39 also tells the data protection officer to monitor compliance “including the assignment of responsibilities”, which presupposes that responsibilities have been assigned.
DORA. Article 5(2) requires the management body of a financial entity to set clear roles and responsibilities for all ICT-related functions and to put in place policies on the availability, authenticity, integrity and confidentiality of data. Article 8(1) requires entities to identify, classify and document their ICT-supported business functions, roles and responsibilities and the information assets supporting them, and to review this at least yearly. In Luxembourg, the law of 1 July 2024 designates the Commission de Surveillance du Secteur Financier (CSSF) and the Commissariat aux Assurances (CAA) as competent authorities.
BCBS 239. The Basel Committee’s principles of January 2013 on risk data aggregation say that roles and responsibilities should be established for the ownership and quality of risk data, for both business and IT functions (paragraph 34). They are addressed first to systemically important banks, and national supervisors may apply them more widely.
AI Act. Article 10 requires training, validation and testing data for high-risk AI systems to be subject to data governance and management practices covering, among other things, data collection and origin, preparation steps such as labelling and cleaning, bias examination and data gaps. Following the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), these obligations apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for systems covered by Annex I. Someone has to own those practices for each data set.
The most common mistake: making IT the owner
When nobody in the business volunteers, ownership tends to land with IT because IT “has the database”. The result is predictable. IT can guarantee that a customer table is backed up and access-controlled, but it cannot decide whether a dormant client is still a customer, which address is legally valid, or what level of completeness is good enough for regulatory reporting. Those are business decisions. Disputes then escalate with nobody empowered to settle them, and quality issues bounce between departments.
IT is the natural custodian. It can also provide technical stewards for specific systems. But the owner of customer data should sit where customer decisions are taken, for example in sales, client services or operations.
Assigning roles in a mid-sized organisation
A mid-sized company does not need a large governance office. A pragmatic approach:
- List five to eight data domains that matter most: typically customer, supplier, product or service, employee, finance and, in financial services, counterparty and risk data.
- Name one owner per domain at head-of-function level. Accept that some people will own two domains.
- Name one steward per domain, ideally the person who already answers questions about that data informally.
- Confirm the custodian for each system holding the domain, including outsourced and cloud providers.
- Write it down in a one-page role description and in the RACI above, and link it to the GDPR record of processing and, for financial entities, the DORA asset inventory.
- Set a review rhythm: a short quarterly meeting per domain on open issues and quality figures.
Organisations that want more structure than a RACI can work with a practical framework for data accountability that ties roles to decisions and escalation paths.
What to do now
- Check whether every data set in your GDPR record of processing has a named business person, not a department, answering for it.
- For DORA entities, verify that the Article 8 inventory lists roles and responsibilities next to information assets, and that it was reviewed within the last twelve months.
- Identify any domain where IT is currently recorded as owner and move ownership to the business, leaving IT as custodian.
- If you develop AI systems that may be classified as high-risk under Annex III, assign an owner for each training and evaluation data set before 2 December 2027.
Questions & answers
What is the difference between a data owner and a data steward?
The data owner is accountable and takes decisions for a data domain, such as approving definitions, quality targets and access. The data steward is responsible for carrying those decisions out day to day: maintaining definitions, monitoring quality and coordinating fixes.
Is a data custodian the same as the IT department?
In practice the custodian role usually sits in IT or with an outsourced provider, because it covers storing, securing, backing up and disposing of data. The custodian implements the owner's requirements but does not set them.
Does GDPR require a data owner?
GDPR does not use the term data owner. It makes the controller responsible for, and able to demonstrate, compliance (Article 5(2)), which in practice requires named people inside the organisation who answer for each processing activity and data set.
Can one person be both data owner and data steward?
In a small team it happens, but it weakens the separation between deciding and executing. Where possible, the owner should be a senior manager and the steward someone who works with the data every day.
Should the DPO be the data owner for personal data?
No. Under GDPR Article 39 the DPO informs, advises and monitors compliance, including the assignment of responsibilities. Owning the data would put the DPO in the position of monitoring their own decisions.
Sources
- Regulation (EU) 2016/679 (GDPR), Articles 4(7), 5(2), 24, 30 and 39 · EUR-Lex
- Regulation (EU) 2022/2554 (DORA), Articles 5, 8 and 64 · EUR-Lex
- Regulation (EU) 2024/1689 (AI Act), Article 10 · EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) · EUR-Lex
- Luxembourg DORA law published in the Official Journal · CSSF
- Principles for effective risk data aggregation and risk reporting (BCBS 239) · Basel Committee on Banking Supervision
- CNPD duties · CNPD
- Data ownership model · UK Government Digital Service
- DAMA-DMBOK: Data Management Body of Knowledge · DAMA International
Written and fact-checked against primary sources.