Data stewardship
Data stewardship is the care of the data a service holds across its whole life, from the first record it collects to the day that record is destroyed. The Government of Canada treats information and data as a public trust, managed as a strategic asset, under the Policy on Service and Digital and its directive. For the data inside one service, that comes down to four things: knowing who is accountable for it, keeping it fit to use, keeping it only as long as it is needed, and moving it safely when the service changes. These decisions are made early and revisited as the service grows.
THE CORE OF DATA STEWARDSHIP
What good looks like
One person is accountable for the data the service holds, and the rules for managing it are written down.
The data is fit for its purpose: accurate, complete, and current enough for the decisions it supports.
Only the data the service needs is collected, and it is kept only as long as it is needed.
Every retention period has three parts: a length, a trigger that starts the clock, and a reason.
Nothing is destroyed without the disposition authority that covers it.
Personal information follows the extra rules that protect it.
When the service moves to a new system, the data is cleaned first, moved with its meaning intact, and checked before the old system is switched off.
Data is open by default where it can be, and protected where it must be.
Why it matters
Data is the part of a service that outlives the software. A team can replace the system and keep the records, so the records are worth more care than the code. When data quality slips, decisions get made on wrong information, and the error spreads to everyone downstream who trusts it. Holding data longer than allowed, or destroying it without authority, both break the rules: the Policy on Service and Digital and its directive require an institution to manage data quality, set retention periods, and run a documented disposition process, and under the Library and Archives of Canada Act no government record may be destroyed without the written consent of the Librarian and Archivist.
Whose job it is
Data stewardship is shared across the team, with each role holding a different part:
- The department's information management office sets the standards and holds the disposition authorities; some departments name a Chief Data Officer to lead this.
- Developers build the service so it captures data cleanly, applies the retention rules, and can export the data without losing its meaning.
- The business owner of the application decides what data the service needs, makes sure retention and disposition are set before launch, and answers for the data's quality and its lawful disposal.
A closer look
Deciding what happens to the data
Working out what happens to a service's data is one of the most-missed jobs in government. The rule itself is simple. The process behind it is rarely laid out, so a service can reach its end with no one sure who to ask, what to ask, or when. The work then starts as the service is being switched off, which is the hardest time to do it.
It turns on timing: the data decisions are made early, and the clean-up and the move come later. Settle during the build and the running years what will be kept, moved, or destroyed, and retiring or replacing the service becomes a task to work through rather than a scramble at the end.
1. The one rule that governs all of it
Under the Library and Archives of Canada Act, no government record may be destroyed without the written consent of the Librarian and Archivist. That consent is a disposition authority: the standing permission that lets a record be destroyed. Without one that covers the record, nothing is deleted, and a service cannot be cleaned up or shut down on its own schedule. The authority has to exist first, or be requested and granted.
2. Is an authority already in place?
An authority attaches to a department and a kind of record, not to a single project, so one may already be in place. Either way, the Information Management (IM) office confirms it.
- Usually, it is already covered. Common admin records (human resources, finance) sit under government-wide authorities every department already holds. The program's own records may be covered too, if the department obtained an authority for that kind of record before, or if they fall under a shared authority for operational case files. Then there is nothing to request, only to confirm.
- Sometimes, it is not. If the records are genuinely uncovered, the department requests a new authority for them, through the IM office. This is where to act early: there is no set timeline, and it can take months, sometimes years.
3. How to sort it out: when, who, and what to ask
Three things settle it.
- When. Early, in Beta, before the service launches. An authority is never refused, so this is not a pass-or-fail checkpoint; the only risk is how long a new one takes, which is why it starts early.
- Who. The Information Management (IM) office. They hold the authorities, know what covers the records, and request new ones from Library and Archives Canada through its Liaison Centre.
- What to ask them. Two questions:
- Is an authority already in place for these records, and if not, how is one requested and how long will it take?
- What can be cleaned up on an ongoing basis once the service is live, and under which authority?
4. While the service runs: keep it cleaned up
A running service should not simply pile up data until it closes. Clearing records on schedule is allowed, and it uses the same authority each time: a disposition authority is standing permission, not a one-time ticket. As each record reaches the end of its retention period (how long it must be kept), it can be destroyed under the authority that already covers it.
- Transitory records. Drafts, duplicates, and working notes with no lasting value can be destroyed at any time, under a standing government-wide authority made for them.
- Records past their retention period. Once the period ends, the existing authority is the consent to destroy them.
- Personal information. The Privacy Act requires it to be disposed of once it is no longer needed, and at the latest two years after it was last used to decide about a person.
Deciding a record is no longer needed is not the same as being allowed to delete it.
Three parties share the work, in order:
- 1
The records' owner approves that a set of records is no longer needed.
- 2
The IM office confirms an authority covers it, checks for legal holds or open access-to-information requests, destroys it securely, and records what was done.
- 3
The supplier carries out the technical deletion, where the contract requires it.
For a small team running a bought product, the disposal does not happen on its own; it happens only where the contract requires it. So these duties belong in the contract from the start: dispose on schedule, return the data, destroy copies securely, and show it was done. They form the data schedule of a good contract, set when the service is bought.
Why clear records as you go? Three reasons.
A smaller, safer Sunset.
Less data at the end means less to migrate, less to dispose of, and less to work out whether an authority exists.
Privacy compliance.
Holding personal information past its retention period is a Privacy Act problem in its own right.
A smaller target.
Data kept is data to protect. (Storage cost can matter too, but only where the contract charges by usage; under a fixed fee the saving is mostly risk.)
5. When the service is replaced or retired
Retiring or replacing a service runs through its own steps: assess, decide, plan, then move. The data work splits across them.
- The decision comes at the planning step, near the start. For each set of records, choose whether it is migrated to the new system, transferred to Library and Archives Canada, or destroyed under an existing authority. The migration plan depends on this, because the plan cannot be made without knowing what may be destroyed and what must be kept.
- The move comes later, as the old service winds down, finishing only once the new service is live.
- Run the data migration as its own project, ahead of decommission. Departmental decommissioning guides start the migration separately and hold the shutdown until it has finished.
- Decide early. Data kept past need costs storage and effort, so the sooner what leaves is decided, the less is carried into the move.
Records that are kept are cleaned first, because fixing quality before a migration costs less than after, and moved with their meaning intact. Records that are destroyed are destroyed securely. Nothing is destroyed without the authority that covers it.
6. Who you talk to
- Information Management (IM) office — holds the authorities, knows what covers the records, requests new ones, tracks the schedule, and does and documents the disposal. First call.
- ATIP / privacy office — for the Privacy Act duty to dispose of personal information on time.
- Library and Archives Canada, through its Liaison Centre — where the department requests a new authority, reached through the IM office.
Comparison
Two ways to look after data
Pax
Meet Pax, a service manager. They treated the grant portal's data as something owned and cared for:
- named one person accountable for it
- set a retention period for each kind of record (a length, a trigger, a reason), using Library and Archives Canada's Generic Valuation Tools as a starting point
- kept the data clean, fixing duplicates and errors as they appeared
- when the portal was replaced, migrated the data with its meaning intact and disposed of the rest on schedule
The result: trustworthy records, decisions made on good data, and lawful disposal.
What Data stewardship looks like in each phase
The data work changes shape across the life of a service.
Most data decisions are cheapest at the start. The team decides what data the service needs and collects no more, names who is accountable for it, and sets a retention period for each kind of data (a length, a trigger, a reason), using Library and Archives Canada's Generic Valuation Tools as a starting point. The service is designed so data is captured cleanly and can be exported later, and the quality rules and metadata standards are chosen now. If the data includes personal information, the privacy requirements apply on top.
The official instruments behind data stewardship
Everything official this subject brings with it, and where in a service's life each one comes up. The full detail, including who does the work and what the business owner personally does, is in the table on the home page.
The government-wide register of what services exist, who they serve, how digital they are, and how much volume they handle. Its 70 published fields include nothing about criticality, recovery or continuity.
- StabilizationSubmit
- MaturityKeep current
- SunsetClose out
- Application Portfolio Management (APM)Every serviceRegister
The register of the applications behind the services, rated for business value, technical condition, support cost and criticality, and sorted into tolerate, innovate, mitigate or eliminate. This is where criticality actually gets recorded, since the service inventory has no field for it.
- StabilizationSubmit
- MaturityKeep current
- SunsetClose out
The written consent from Library and Archives Canada without which no government record may be destroyed, plus the department's own schedule saying how long each kind of record is kept. The authority is permission to dispose. It is not an instruction to dispose, and it does not set retention periods.
- AlphaGather
- BetaFill
- MaturityKeep current
- SunsetClose out
- Access to information readiness, and the duty to documentEvery serviceStanding duty
Everything the service records is subject to an access request, and decisions of business value have to be documented in the first place. That shapes what gets written down, what the system keeps, and whether records can be retrieved and released when someone asks.
- AlphaGather
- BetaFill
- MaturityKeep current
- Proactive publicationOnly ifFiling
Publication that happens without anyone asking. For a procured digital service the live ones are contracts over $10,000, grants and contributions over $25,000, and titles of briefing materials. It is a statutory duty, not a courtesy.
- BetaSubmit
- MaturityKeep current
- Open data and open informationEvery serviceFiling
The expectation that data and information of business value are released openly by default, in reusable formats, unless something specific stops it. Info Source separately describes what information the institution holds.
- AlphaCheck
- MaturityKeep current
Further reading
See also
Assumptions this page makes
You are already working to the Government of Canada Digital Standards, design with users, iterate and improve frequently, work in the open, use open standards, address security and privacy, build in accessibility, empower staff, be good data stewards, design ethical services, and collaborate widely, and to the law on privacy, security, official languages, and accessibility. The standards say how the government works in the digital world. The six Government of Canada digital competencies say what every public servant has to be able to do to work that way, and the team page covers them. This guide builds on those.