Data Governance Trust • Value • Accountability
⚠ Raise an Issue ✉ Contact Us
Shoprite Group • Data Governance Office

Data is how we lead. Governance supports that trust.

Shoprite Group manages information assets across retail operations, digital commerce, financial services, pharmacy, distribution, loyalty, property, supplier ecosystems, analytics and AI-driven platforms. Data Governance establishes the authority, accountability, standards and controls that enable responsible, secure, ethical and high-value use of information assets across the Group.

Explore the foundations →
Why this exists

Data Governance is a Board-level mandate, not a departmental preference

The governing body is accountable for how the Group creates, uses, shares, protects and disposes of data, information and technology. Management must be able to demonstrate that accountability with evidence, not assertion. King V applies to financial years beginning on or after 1 January 2026 and elevates data, information and technology to a standalone principle that expressly covers artificial intelligence, human oversight and technology literacy at Board level.

Our Data Governance Promise

Data Governance is not a compliance function that says no. It is the Group capability that helps teams move faster with trusted data, manage risk proportionately, protect people, improve decisions and create sustainable value from information assets.

Start Here

Governance obligations differ by role. Choose the description closest to your work to see what is expected of you, what to check first and where to go next.

Make Governance Easier

Use the Governance Guide for explanations and industry context, or use the Decision Tool to find the practical route for work already underway.

The Data Governance Foundations

The common operating system for governing information assets across a large, regulated, data-rich retail Group.

Where Data Governance Sits in the Stack

Governance is the foundation everything else runs on. Without it, every layer above it inherits the same uncertainty, inconsistency and risk.

AI Data Science Analytics Reporting Data Engineering Data Management Data Governance
AI
A simulation of human intelligence in machines that perceive, reason and act. At the Group this includes Pixie, demand forecasting, fraud detection and the Xtra Savings personalisation engine.
Data Science
Combines domain expertise, programming and statistical methods to build models and extract insight that cannot be produced by standard reporting.
Analytics
Discovering and communicating meaningful patterns in data, from basket analysis and store performance to supply chain optimisation and customer segmentation.
Reporting
Collecting and translating structured information into formats that support ongoing business performance decisions including daily sales, stock positions, financial close.
Data Engineering
Designing and operating the systems and pipelines that collect, store, integrate, transform and deliver data at the Group's scale across SAP, Snowflake, MicroStrategy, Power BI and 698+ enterprise systems.
Data Management
The disciplines that keep data useful: quality management, metadata, architecture, security, records management, master and reference data , the practice the Data Governance framework governs.
Data Governance
The accountability structures, standards, policies and controls that determine how data is used, protected and valued across the Group. This is the layer this page defines. Everything above it inherits its integrity from this foundation.

Governance in Action

Good governance is not paperwork around data. It is the operating system that keeps trusted information moving safely across a complex retail Group. Tap or click any tile.

Govern Data Across the Full Lifecycle

Moving data does not reset ownership, classification, privacy, retention or accountability. Governance remains in force from design through secure disposal.

01

Design

Define purpose, ownership, classification, quality, retention, privacy, security and architecture before build.

02

Collect

Collect only what is required. Capture source, event dates, lawful basis and validation requirements.

03

Use & Share

Apply approved purpose, lawful processing, least privilege, sharing requirements and contractual controls.

04

Store & Protect

Maintain storage, access controls, quality monitoring, lineage, resilience, audit logs and backup alignment.

05

Retain & Archive

Retain according to legal and approved business requirements. Archive securely when online retention ends.

06

Dispose & Prove

Respect legal holds, securely delete or destroy at end of life and retain appropriate disposal evidence.

AI-First. Human-Accountable. Compliance by Design.

AI creates opportunity across customer experience, operations, supply chain, financial services, fraud prevention, analytics and productivity. It must be deployed responsibly.

Responsible AI at Shoprite

We do not govern AI to slow innovation. We govern it so innovation can scale safely.

AI systems must support legitimate business objectives, respect customer and employee rights, use approved tools and platforms, protect confidential information and comply with applicable law.

Named AI System Owner Risk classification Approved purpose Data provenance Human oversight Bias & fairness testing Secure GenAI use Monitoring & retirement

AI Assurance Gates

Material AI use cases require proportionate review, approval, control evidence and monitoring.

1

Use Case, Owner & Risk Classification

Define purpose, expected value, affected people, decision impact and risk tier before development or deployment.

2

Data Readiness, POPIA & Security

Assess quality, minimisation, lawful processing, retention, representativeness, lineage, access and provider controls.

3

Validation, Fairness & Human Control

Test performance, bias, explainability appropriate to risk, failure modes and meaningful human intervention.

4

Production Monitoring & Incident Response

Monitor performance, drift, fairness, security, usage, incidents and whether the original purpose remains valid.

Generative AI rule: Do not input customer data, personal information, confidential information, unpublished financial information or third-party confidential information into unapproved AI tools.

The Data Nobody Governs

Most governance effort covers databases. Most actual exposure now lives in SharePoint sites, mailboxes, Teams channels and scanned documents , and a GenAI assistant can read all of it on a user's behalf, instantly, at the breadth no human search would reach.
Why it matters: unstructured content holds contracts, board papers, HR records and personal information. If permissions are wrong, an assistant inherits every error at machine speed. Read this before enabling any Microsoft Copilot or AI assistant on Group content.

Unstructured content and collaboration

SharePoint, Teams, OneDrive, email and scanned documents hold official records, personal information and commercially sensitive material.

  • Permissions are the control. Broad "everyone" and "anyone with the link" sharing is the single largest cause of accidental exposure.
  • Sensitivity labelling. Classification must be applied to documents, not only to database tables, so that protection travels with the file.
  • Records live here too. Contracts, approvals, board packs and evidence in Teams and email carry the same retention and legal-hold obligations as structured records.
  • Site ownership. Every site and shared library needs a named owner and a periodic access review, not an inherited orphan.
  • Copies are the risk. Extracts, downloads and personal drives are where retention and classification quietly fail.

Copilots, assistants and retrieval

A GenAI assistant that answers from Group content inherits every permission error already present in that content.

  • Fix permissions before enabling retrieval. An assistant surfaces what a user could technically already reach, at a speed no human search would achieve.
  • Ground on approved sources. Retrieval scope must be defined, reviewed and restricted for sensitive domains.
  • Log prompts and outputs proportionately. Where an assistant informs a decision affecting a person, the interaction is evidence.
  • Do not let assistants create shadow records. Generated summaries used for decisions must be stored in the approved repository, classified and retained.
  • Approved tools only. Confidential and personal information must never be entered into unapproved AI services.

From Datasets to Data Products

A dataset is data that someone saved somewhere. A data product is data with a named owner, a quality promise, documented lineage and a published audience , data that another team can consume without having to investigate whether it is trustworthy.
Why it matters: at Shoprite's scale, unowned datasets multiply faster than anyone can track them. Every team that cannot find a certified source builds their own copy. Read this if your team publishes data that others depend on, or if you are tired of reconciling numbers that should be the same.

What makes something a data product

A certified data product is a governed, reusable asset with a named owner and a published promise about quality and meaning.

  • Named Data Sponsor and Data SME, published in the catalogue and reachable by consumers.
  • Defined purpose and audience, with permitted use and any personal-information constraints stated up front.
  • Documented quality expectations covering the dimensions that matter for that use, with monitoring and a visible current position.
  • Lineage to source, refresh frequency, known limitations and a change and deprecation route.
  • Retention and classification inherited from source, applied to the product, its copies and its backups.

Data contracts and machine-enforceable rules

Governance holds when the rule is executed by the platform rather than remembered by a person.

  • Contract at the interface. Producer and consumer agree schema, semantics, quality thresholds, availability and change notice.
  • Break the build, not the report. Contract violations should fail in the pipeline before they reach a dashboard or a model.
  • Metadata as the control plane. Classification, ownership, personal-information flags and retention tags must be machine-readable and carried downstream.
  • Agent-ready by design. Automated and agentic consumers cannot infer intent. Ambiguous definitions become incorrect actions at machine speed.
  • Deprecation is governance. Retiring an asset needs the same discipline as launching one.

Personalisation Is a Governance Decision

Every time the Xtra Savings engine surfaces a personalised offer, it makes a data decision , about what we know, what we inferred and whether we have the right to use it that way. The commercial opportunity and the POPIA exposure are not separate conversations: they are the same conversation.
Why it matters: the Information Regulator named direct marketing as a priority enforcement area in 2026. A personalisation model is both a revenue engine and a processing activity that must be justified. Read this if you work on loyalty, offer management, customer analytics, Sixty60, or any AI that touches customer behaviour data.

Direct marketing and electronic communication

Section 69 of POPIA restricts unsolicited electronic direct marketing, and the Information Regulator has named direct marketing and breach management as priority enforcement areas.

  • Know which basis applies. Existing customers and non-customers are treated differently. Record which basis was relied on for each contact, not just the outcome.
  • Consent must be evidenced. The record of when, how and for what a person agreed is the control. A statement that consent was obtained is not.
  • Opt-out must actually work. Objections must propagate across every channel and every downstream copy of the marketing audience, including partner and agency lists.
  • Segment definitions are governed data. An audience built on an incorrect or stale attribute reaches the wrong person with the wrong message.
  • Children and special categories. Higher-sensitivity attributes require stronger justification and tighter access, not just a flag in a table.

Fairness in what the customer experiences

A personalisation model makes thousands of small decisions about people every minute. Governance asks whether we would be comfortable explaining any one of them.

  • Be able to explain the offer. Where a customer asks why they received a price, a promotion or a recommendation, someone must be able to answer without reverse engineering a model.
  • Watch for proxy discrimination. Location, store, basket composition and payment method can stand in for protected characteristics without anyone intending it.
  • Set the boundary before the pilot. Agree what the Group will not do with customer data while the commercial pressure is still low.
  • Separate inference from fact. A predicted attribute is not a verified one. Downstream systems must be able to tell the difference.
  • Health and pharmacy data is different. Health information regulations took effect on 6 March 2026 with no grace period. Pharmacy data must not flow into general marketing or analytics populations.

Know Where We Are and What Improves

Governance that cannot be measured cannot be defended. Maturity and adherence are reported through the Group governance structures.

LEVEL 1
Ad hoc Ownership unclear, definitions inconsistent, issues found by accident.
LEVEL 2 → 3
Defined → Operating Policies and standards published. Catalogue and quality monitoring now active. Formal issue management in progress. Standards being embedded in delivery.
LEVEL 3
Operating Standards applied in delivery, catalogue and quality monitoring in use, issues managed formally.
LEVEL 4
Measured Adherence reported, controls tested, remediation tracked to closure with evidence.
LEVEL 5
Embedded Rules enforced in platform, governance is automatic rather than requested.

Data Governance Action Centre

Report concerns early. Use the correct route so issues can be assessed, prioritised, contained and resolved through the right accountable teams.

I have a Data Quality or Governance issue

Wrong or missing data, unclear definition, duplicates, missing ownership, weak metadata, retention concern or control weakness?

Raise a Data Issue →

I suspect a privacy or security incident

Suspected unauthorised access, disclosure, loss, acquisition or exposure of personal or confidential information must be reported immediately.

Report urgently →

I am building, changing or sharing data

Request early review for architecture, quality, classification, retention, metadata, privacy, third-party sharing, data ecosystems or AI requirements.

Request a Design Review →

I need to know the rule

Start with the applicable Group framework, policy, standard or guideline. Contact Data Governance where published guidance does not resolve the question.

Detail

Title

✦

Shoprite Governance Guide

Move by header • Resize from bottom-right • Site remains active behind the window

Keep it safe: Do not enter customer data, employee data, personal information, credentials, confidential commercial information, source code, contract details or incident facts.
Suggested questions
Hello. I am the Shoprite Governance Guide.

I can explain foundational Data Governance, Responsible AI, Data Quality, metadata, records, lineage and data sharing.

I can also assist with urgent lost-device and password-reset routing.
⌘

Data Governance Decision Tool

Move by header • Resize from bottom-right • Links behind this window still work

Choose the scenario closest to your work. This tool provides foundational guidance and routes you to the correct accountable owner or team.

Recommended route