Lakshya

Data Platform & Analytics

Data Governance & Quality

Data · privacy and compliance in 82%

Named in more postings than SQL. Where an organisation's regulatory exposure physically lives.

Privacy and compliance language appears in 82% of these postings — higher than any tool and higher than SQL. This is not paperwork attached to a data team; it is increasingly the reason the data team exists in the shape it does.

TimeWhat you are actually doing
09:00An erasure request. Finding every copy of one subject, which is a lineage test wearing a legal costume.
10:30Classification at ingestion — tagging columns rather than tables, so everything does not inherit the strictest label.
13:00An access review that is about to be rubber-stamped. Reworking it to show unused entitlements rather than all of them.
14:30Residency. A replica quietly crossed a border and nobody noticed because nothing checks.
16:00Writing the retention schedule that will actually delete things, which requires somebody senior to accept that deletion is safe.

The decisive round

“How would you know whether our data governance actually works?”

Interviewer: “We have a catalogue, classification and an access review process. How would you assess whether it is real?”

A weak answer. “I'd check that the catalogue is populated, classification is applied across systems, and reviews are completed on schedule.” Measures the existence of controls rather than their operation. All three can be true of a programme that governs nothing.

A strong answer. “I would test operation rather than existence, with four things.

The erasure drill. Pick a synthetic subject and try to find and delete every copy. This exercises inventory, lineage, backups and exports simultaneously, and if it takes more than about an hour the inventory is fiction. I would run it as a drill rather than waiting for a real request.

Revoke rate on access reviews, not completion rate. A campaign closing at 98% completion with a 0.4% revoke rate is a rubber stamp, and completion rate is a vanity metric that rewards exactly that.

Classification granularity. Is it applied at column level or table level? Table-level classification means everything inherits the strictest tag, which means either over-restriction that pushes people into shadow copies, or a tag nobody honours.

A two-user test. Two accounts with different entitlements querying the same asset. If they see the same thing, the access model did not survive whatever pipeline produced that table — and this is where retrieval indexes for AI are currently failing badly.

Then the structural question: is governance a gate people pass through, or a default they get for free? A gate produces shadow pipelines. Classification applied at ingestion, access derived from it, retention scheduled automatically produces compliance nobody had to choose.”

Testing operation rather than existence, and knowing that completion rate and table-level classification are both ways of appearing governed.

  • Run an erasure drill on something you control and write down every copy you found and how long it took.
  • Build classification-derived access and prove it with two users.
  • Convert an access review to exception-based and report the revoke rate.
  • Have a retention schedule that actually deletes, and the story of getting someone to accept that.

Compensation

MarketBandNotes
United States$120k – $210kEngineering-capable governance sits well above policy-only roles
India₹12L – ₹40L totalLarge BFSI and healthcare GCC demand

The book for this field

Data Platform & Analytics

What the job actually is now, modelling and grain, data contracts and who gets paged, quality that is not a dashboard, streaming and when you need it, governance and the 82%, cost, and serving the AI workload.

CHAPTER 6Governance, privacy and the 82%Named in more postings than SQL. Treat it as the job rather than as paperwork.READ THE CHAPTER →CHAPTER 4Data quality that is not a dashboardMost quality programmes produce alerts nobody actions. This is about the small number of tests that earn their place.READ THE CHAPTER →CHAPTER 3Data contracts, and who gets pagedThe structural fix for the defining problem of the field: your pipeline breaks because of a change you did not make.READ THE CHAPTER →

All 8 chapters in Data Platform & Analytics →

Cross-cutting

Skills every archetype tests

These are shared across every field on this site — the same question asked in different vocabulary — so preparation here compounds rather than being spent once. The book above is specific to your field.

The controlOne habit separates strong candidates from plausible ones more reliably than any technical depth.READ THE CHAPTER →Measuring what resists measurementTested in every field on this site under a different name — evals, SLOs, DORA, ablations. Named in 59% of AI and 42% of platform postings, and almost nobody studies it deliberately.READ THE CHAPTER →Reading a job descriptionAbout 70% of a posting is boilerplate. Knowing where the other 30% lives changes how you apply.READ THE CHAPTER →

Practice questions across all themes →  ·  Back to Data Platform & Analytics →