2018 – 2019: Data Governance Becomes a Business Priority
The Digital Workplace Matures
By the time companies moved into 2018, the digital workplace was no longer an emerging idea. It was already in place, being used every day, and continuing to evolve as platforms expanded and user expectations matured. Work was distributed across email, file systems, and collaboration tools – all connected but distinct, and all contributing to a growing body of information that was increasingly central to how businesses operated.
With that shift came a change in focus. In earlier phases, attention had been placed on moving data and making it accessible. Once those objectives were largely achieved, a more fundamental question began to take shape. It was no longer enough to know where data was or how to access it. Companies needed to understand how it was being used, how long it should be retained, and what obligations were attached to it.
GDPR Changes the Conversation
This became particularly clear in May 2018, when the General Data Protection Regulation came into force across the European Union, superseding the previous Data Protection Act which took force all the way back in 1998.
Unlike many previous regulations, GDPR was explicit in its requirements. Companies were expected to demonstrate control over personal data, to show that it was being processed lawfully, and to provide clear evidence of how it was managed. This was not limited to new data – it applied to everything that had been accumulated over time, regardless of where it was stored or how it had originally been created.
For many companies, this brought existing uncertainties into sharper focus. Earlier efforts to identify and structure data estates had already highlighted the scale and complexity of what was being held. PST files, legacy archives, and distributed file systems had revealed how easily data could become fragmented over time. The transition to Cloud platforms had addressed some of these issues, but it had also introduced new ones. Data was now easier to access and share, which increased both its value and the need to manage it carefully.
GDPR made those requirements unavoidable. It required companies to be able to answer questions that were not always straightforward. What data do we hold? Where is it located? Who has access to it? How long should it be retained? In many cases, the answers were incomplete, not because companies were unwilling to provide them, but because the information itself was not structured in a way that made those answers easy to produce.
Governance Moves Up the Business Agenda
This created a renewed focus on governance. Data needed to be organised in a way that supported accountability. Retention policies had to be defined and applied consistently. Access controls needed to reflect actual usage, rather than assumptions about who might need information. The goal was not simply to store data, but to manage it in a way that aligned with both operational needs and regulatory expectations.
At the same time, the broader technology landscape continued to develop. Artificial Intelligence began to appear more frequently in everyday applications. Voice assistants, automated recommendations, and increasingly capable search functions demonstrated how data could be used to provide more responsive and personalised experiences. For companies, these developments highlighted the potential value of the information they held, particularly when it could be analysed effectively.
Data offered the opportunity to generate insight and support decision-making, but it also required careful handling to avoid introducing risk. The same information that could provide value could also expose companies to regulatory scrutiny if it was not managed appropriately. As a result, governance became closely linked to the ability to use data effectively.
Migration Becomes Part of Governance
Transvault’s work during this period aligned with these requirements. Migration was no longer seen solely as a technical exercise. It became part of a broader process of ensuring that data was structured, traceable, and suitable for long-term management. Moving information between systems needed to preserve not only the content, but also the context in which it existed. Metadata, timestamps, and relationships between items all contributed to the ability to demonstrate control and provide evidence when required.
This emphasis on accuracy and completeness supported both compliance and operational use. By ensuring that data was transferred in a controlled and consistent way, companies were better positioned to apply governance policies and respond to regulatory requirements. At the same time, they were able to make more effective use of that data within their own processes.
Data Becomes Both an Asset and a Responsibility
By the end of 2019, the role of data within companies had become more clearly defined.
It was understood as an asset that could support analysis and decision-making, but also as something that required careful management to avoid potential liabilities. This dual perspective influenced how companies approached both technology and policy, bringing data governance into closer alignment with broader business objectives.
The digital workplace remained in place, and the systems supporting it continued to evolve. Collaboration tools became more deeply embedded in daily operations, and data continued to flow between platforms as part of normal activity.
The difference was that this activity was now taking place within a more structured framework. Expectations around accountability had been established, and companies were increasingly aware of the need to demonstrate control over their information. Processes were being put in place to support this, and systems were being configured to align with those processes.
A More Controlled Environment Faces New Pressure
This created a more stable environment, but it also introduced new pressures. Maintaining governance across distributed systems required ongoing attention. Policies needed to be applied consistently, and data needed to remain accurate and accessible over time. As volumes continued to grow, the effort required to maintain this balance increased.
These conditions would be tested in ways that few had anticipated. Because just as companies were beginning to establish a more controlled and accountable approach to managing their data, the environment in which they operated changed significantly.
And, in the next article, details about how that change would place new demands on the systems they had built.