
Introduction
As the use of Data Products and self-service BI continued to grow, this global industrial and consumer goods company wanted to strengthen how data access is requested and managed, while keeping governance, data protection, and compliance requirements embedded in the process.
The problem
Self-service data access was growing. That was the good news. The challenge was keeping governance, data protection, and compliance requirements embedded in the process as it scaled.
Access requests were not consistently documented. Approval responsibilities were unclear. Data classification existed but was not connected to access decisions or protection measures. Without those links, the company risked inappropriate data exposure, audit gaps, and a compliance framework that looked good on paper but didn't hold up in practice.
The company needed one consistent, auditable process.
How we solved it
Make the Data Catalog the single entry point for access requests
DTA positioned Data Products as the governed objects at the centre of every access request. Each request links directly to the relevant Data Product in the Data Catalog; creating one documented, traceable process for all access decisions. Users get a consistent experience. The business gets full traceability.
Build role and approval logic into the workflow
DTA defined who can request access and who must approve it, and embedded that logic directly into the workflow. Data Stewards maintain Data Products and the governance metadata that underpins access decisions. Accountability is clear. The process stays efficient.
Connect classification to access decisions and protection measures
DTA linked data classification maintained at Business Term and field level, to the workflow logic. For sensitive data, classification now determines whether additional protection measures like obfuscation apply. This means protection isn't a manual afterthought. It triggers automatically, as part of the access process itself.
The results
DTA designed a single, governed access workflow inside the Data Catalog: connecting Data Products, classification, roles, and protection measures in one consistent process. The goal was simple: make data easier to access without making it harder to control.
A fully auditable access process
Access requests and approvals run through one consistent workflow. Every decision is traceable: who requested access, who approved it, and on what basis. Audit readiness is no longer a separate exercise.
Clear accountability at every step
Roles, ownership, and classification are embedded in the process. Access decisions draw on maintained, reliable governance information, not guesswork or ad hoc checks.
Controlled self-service with a path to automation
Classification now triggers protection measures like obfuscation directly. Sensitive data is protected as part of the normal flow. The same reliable metadata creates the foundation for more automated data provisioning down the line.
Key Learnings
Three things made the difference on this engagement and they apply to any organisation trying to scale self-service without losing grip on governance.
Governance
enables scale when it's built into the process. Self-service only works at scale when the controls travel with it. Bolting governance on after the fact creates friction; embedding it from the start keeps things moving.
Classification
is only as valuable as what it drives. A classification framework that sits in a spreadsheet changes nothing. The moment it connects to workflow logic and protection measures, it starts doing real work.
Reliable metadata
is a prerequisite for automation. More automated provisioning depends on Data Products, ownership, and classifications being actively maintained, not set once and forgotten. This is an ongoing discipline, not a one-time project.
More case studies
We deliver impact where it matters most.


From fragmented controls to scalable regulatory data quality
Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.


Managing GDPR compliance across a complex stakeholder landscape
Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.


From regulatory scrutiny to demonstrated compliance
LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.