University Data Governance Committee (UDGC)

Purpose: Set institutional policy, maintain data standards, and oversee governance execution across all domains.

  • Chair, Chief Data Officer (CDO)

    • Sponsors governance, leads UDGC meetings, sets strategy (~0.2 FTE)
    • Liaises with executive leadership
  • Program Manager / Secretariat

    • Administers governance workflows, scheduling, documentation (~0.5 FTE)
  • Domain Representatives (Research, Clinical Ops, Finance, Student Services)

    • Advocate domain priorities, ensure policy alignment downstream (~0.1–0.2 FTE each)
  • Campus Privacy Officer (CPO) / Compliance Lead

    • Advises on FERPA, HIPAA, educational privacy risk policies (~0.3 FTE) (YouTube, Wikipedia)

Domain Sub-Committees (Research, Clinical Ops, Finance, Student Services)

Purpose: Customize access workflows, compliance frameworks, and data definitions per domain.

Role Responsibilities Effort
Domain Data Steward Maintains metadata standards, defines key data elements, responds to data-related inquiries (~0.25–0.5 FTE) (Wikipedia) 0.3–0.5 FTE
Compliance Approver / Reviewer Approves access requests per domain-specific criteria (e.g., IRB sign-off / supervisor approval) ~0.2 FTE
Domain Data Custodian Coordinates with platform team on transformations, data ingestion, and ensures stewardship enforcement (~0.25 FTE) (Wikipedia) ~0.25 FTE

Informatics Platform Engineering Team

Your core group running the platform infrastructure and user support.

  • Platform Engineering Lead / Senior Engineer

    • Oversees Azure + Databricks infrastructure, upgrades, runtime maintenance, security patches (1 FTE)
  • Access & Compliance Engineer

    • Manages RBAC implementation, access provisioning, audit logging, policy enforcement (1 FTE)
  • User Support & Documentation Specialist

    • Creates onboarding materials, runs training sessions, handles user queries (~0.5 FTE)
  • Reporting / Audit Automation Engineer

    • Builds dashboards for governance KPIs, automates compliance reports (~0.5 FTE)

Training, Literacy, & Community Support

Purpose: Build data capability across the institution and maintain community-based support.

  • Enterprise Data Steward / Instructor

    • Designs training curricula, runs workshops across domains (~0.5 FTE)
  • Data Steward Peer Network (cross-domain)

    • Domain-level stewards collaborate for best practices, share updates (~collective >0 FTE)

Key Role Definitions (from external standards)

  • Data Steward

    • The business-facing role accountable for data definitions, quality, metadata governance, and fitness for purpose. A steward connects governance policy to team-level usage. (Wikipedia, Wikipedia, Royal Society)
  • Data Custodian

    • The technical role responsible for system-level control: data integrity, storage, versioning, access controls, and technical enforcement of governance rules. (Wikipedia)
  • Campus Privacy Officer (CPO)

    • Oversees institutional privacy policy compliance (FERPA, HIPAA, learning analytics). Advises domain sub-groups and UDGC on regulatory obligations. (Wikipedia)
  • Chief Medical Informatics Officer (CMIO) (if clinical domain includes physician leadership)

    • Provides clinical informatics oversight—particularly needed for clinical operations workflows and governance integration with hospital systems. (Wikipedia)

Summary Table: Heads & Effort Estimate

Team Role Effort
UDGC CDO (Chair) 0.2 FTE
UDGC Governance Program Manager 0.5 FTE
Domain Sub-Committees Data Steward (each domain) ~0.3–0.5 FTE
Domain Sub-Committees Compliance Approver (each domain) ~0.2 FTE
Platform Team Platform Engineering Lead 1 FTE
Platform Team Access & Compliance Engineer 1 FTE
Platform Team Documentation & Support Specialist 0.5 FTE
Platform Team Reporting / Audit Engineer 0.5 FTE
Training / Literacy Enterprise Data Steward / Instructor 0.5 FTE
Community / Peer Network Data Steward Network Distributed, fractional

Adoption Examples from Peer Institutions

  • Stanford Medicine’s STARR / SDSR:

    • Utilizes a robust infrastructure for patient record ingestion, self-service analytics tools, and a governance layer that separates self-service from concierge access. Domain stewards and compliance leads are embedded alongside technical operations. (Wikipedia, ResearchGate, ResearchGate)
  • Duke University Protected Network:

    • Combines domain-specific isolation via virtual enclaves with centralized platform control. Roles of both stewards and custodians are clearly delineated between business-led governance and technical operations. (arXiv)

Case studies of hospital data governance highlight the importance of a separate clinical data governance role interacting with domain approval workflows while aligning with central architecture. (YouTube)


This structure ensures clarity of responsibilities, compliance alignment, and scalable analytics delivery across a university with a medical center, grounded in proven practices from peer institutions.


Updated on August 7, 2025