News

SMEs face rising data governance risks as privacy rules tighten, expert warns

SMEs face rising data governance risks as privacy rules tighten, expert warns

By Nnasom David

Small and medium-sized enterprises (SMEs) across Nigeria and other countries are struggling to keep pace with growing data governance obligations as privacy regulations become more stringent, according to data governance specialist Olamide Bakare.

Bakare said while businesses increasingly collect sensitive customer, employee and financial information, many lack the expertise, personnel and compliance tools needed to manage such data responsibly.

She described the situation as a widening “governance gap” between large organisations with dedicated compliance teams and smaller businesses operating with limited resources.

According to her, SMEs now handle many of the same categories of sensitive information as hospitals, banks and government agencies, making effective data governance essential despite their resource constraints.

“Small businesses are collecting many of the same categories of sensitive information as hospitals, banks, and government agencies,” Bakare said. “The governance obligations are often similar, but the resources available to manage those obligations are dramatically different.”

She noted that although governance frameworks such as COBIT, NIST and ISO 27001 provide valuable guidance, many smaller organisations struggle to implement them because of the cost and complexity involved.

As a result, she said businesses often delay governance activities until they experience a data breach, regulatory sanction or customer complaint.

“The reality is that governance failures rarely begin with malicious intent,” Bakare said. “More often, organisations simply do not know what information they hold, who has access to it, how long it should be retained, or what obligations apply to that data.”

Bakare warned that poor governance practices can lead to data breaches, regulatory violations, operational inefficiencies and loss of customer confidence.

Drawing from her experience managing healthcare data systems at University College Hospital, Ibadan, between 2019 and 2022, and later working within the United Kingdom’s Department for Work and Pensions from 2024, she identified poor visibility into organisational data as one of the biggest governance challenges facing SMEs.

“You cannot govern what you cannot see,” she said, stressing that many organisations store information across spreadsheets, cloud platforms, email systems, messaging applications and third-party software without maintaining a comprehensive inventory.

To improve governance readiness, Bakare recommended that businesses prioritise data inventories, ownership assignment, access reviews, retention policies, privacy awareness and regular governance assessments.

She argued that effective governance should not be viewed as an enterprise-only responsibility but as a fundamental business practice that promotes accountability, transparency and responsible information management.

As part of efforts to make governance more accessible for smaller organisations, Bakare developed DataShield in 2025, a governance assessment platform designed to help SMEs evaluate their governance readiness and identify practical improvement opportunities.

Looking ahead, she projected that governance requirements would become increasingly important as organisations adopt more cloud computing, advanced analytics and artificial intelligence technologies.

“The organisations that succeed in the future will not necessarily be the ones with the most data,” Bakare said. “They will be the ones that know how to govern it responsibly.”

She added that narrowing the governance gap has become more than a regulatory issue, describing it as a business resilience, customer trust and national economic priority as data continues to grow in strategic value.