Data is how we lead.Governance supports that trust.
Shoprite Group manages information assets across retail operations, digital commerce,
financial services, pharmacy, distribution, loyalty, property, supplier ecosystems,
analytics and AI-driven platforms. Data Governance establishes the authority,
accountability, standards and controls that enable responsible, secure, ethical and
high-value use of information assets across the Group.
Data Governance is a Board-level mandate, not a departmental preference
The governing body is accountable for how the Group creates, uses, shares, protects
and disposes of data, information and technology. Management must be able to
demonstrate that accountability with evidence, not assertion.
King V applies to financial years beginning on or after 1 January 2026 and elevates
data, information and technology to a standalone principle that expressly covers
artificial intelligence, human oversight and technology literacy at Board level.
Our Data Governance Promise
Data Governance is not a compliance function that says no. It is the Group capability
that helps teams move faster with trusted data, manage risk proportionately, protect
people, improve decisions and create sustainable value from information assets.
Start Here
Governance obligations differ by role. Choose the description closest to your work to
see what is expected of you, what to check first and where to go next.
Make Governance Easier
Use the Governance Guide for explanations and industry context, or use the Decision Tool
to find the practical route for work already underway.
The Data Governance Foundations
The common operating system for governing information assets across a large,
regulated, data-rich retail Group.
Where Data Governance Sits in the Stack
Governance is the foundation everything else runs on. Without it, every layer above it
inherits the same uncertainty, inconsistency and risk.
AI
A simulation of human intelligence in machines that perceive, reason and act. At the Group this includes Pixie, demand forecasting, fraud detection and the Xtra Savings personalisation engine.
Data Science
Combines domain expertise, programming and statistical methods to build models and extract insight that cannot be produced by standard reporting.
Analytics
Discovering and communicating meaningful patterns in data, from basket analysis and store performance to supply chain optimisation and customer segmentation.
Reporting
Collecting and translating structured information into formats that support ongoing business performance decisions including daily sales, stock positions, financial close.
Data Engineering
Designing and operating the systems and pipelines that collect, store, integrate, transform and deliver data at the Group's scale across SAP, Snowflake, MicroStrategy, Power BI and 698+ enterprise systems.
Data Management
The disciplines that keep data useful: quality management, metadata, architecture, security, records management, master and reference data , the practice the Data Governance framework governs.
Data Governance
The accountability structures, standards, policies and controls that determine how data is used, protected and valued across the Group. This is the layer this page defines. Everything above it inherits its integrity from this foundation.
Governance in Action
Good governance is not paperwork around data. It is the operating system that keeps
trusted information moving safely across a complex retail Group. Tap or click any tile.
Govern Data Across the Full Lifecycle
Moving data does not reset ownership, classification, privacy, retention or accountability.
Governance remains in force from design through secure disposal.
01
Design
Define purpose, ownership, classification, quality, retention, privacy, security and architecture before build.
02
Collect
Collect only what is required. Capture source, event dates, lawful basis and validation requirements.
03
Use & Share
Apply approved purpose, lawful processing, least privilege, sharing requirements and contractual controls.
Retain according to legal and approved business requirements. Archive securely when online retention ends.
06
Dispose & Prove
Respect legal holds, securely delete or destroy at end of life and retain appropriate disposal evidence.
AI-First. Human-Accountable. Compliance by Design.
AI creates opportunity across customer experience, operations, supply chain, financial
services, fraud prevention, analytics and productivity. It must be deployed responsibly.
Responsible AI at Shoprite
We do not govern AI to slow innovation. We govern it so innovation can scale safely.
AI systems must support legitimate business objectives, respect customer and employee
rights, use approved tools and platforms, protect confidential information and comply
with applicable law.
Named AI System OwnerRisk classificationApproved purposeData provenanceHuman oversightBias & fairness testingSecure GenAI useMonitoring & retirement
AI Assurance Gates
Material AI use cases require proportionate review, approval, control evidence and monitoring.
1
Use Case, Owner & Risk Classification
Define purpose, expected value, affected people, decision impact and risk tier before development or deployment.
Test performance, bias, explainability appropriate to risk, failure modes and meaningful human intervention.
4
Production Monitoring & Incident Response
Monitor performance, drift, fairness, security, usage, incidents and whether the original purpose remains valid.
Generative AI rule: Do not input customer data, personal information,
confidential information, unpublished financial information or third-party confidential
information into unapproved AI tools.
The Data Nobody Governs
Most governance effort covers databases. Most actual exposure now lives in SharePoint sites,
mailboxes, Teams channels and scanned documents , and a GenAI assistant can read all of it
on a user's behalf, instantly, at the breadth no human search would reach. Why it matters: unstructured content holds contracts, board papers, HR records
and personal information. If permissions are wrong, an assistant inherits every error at machine
speed. Read this before enabling any Microsoft Copilot or AI assistant on Group content.
Unstructured content and collaboration
SharePoint, Teams, OneDrive, email and scanned documents hold official records, personal information and commercially sensitive material.
Permissions are the control. Broad "everyone" and "anyone with the link" sharing is the single largest cause of accidental exposure.
Sensitivity labelling. Classification must be applied to documents, not only to database tables, so that protection travels with the file.
Records live here too. Contracts, approvals, board packs and evidence in Teams and email carry the same retention and legal-hold obligations as structured records.
Site ownership. Every site and shared library needs a named owner and a periodic access review, not an inherited orphan.
Copies are the risk. Extracts, downloads and personal drives are where retention and classification quietly fail.
Copilots, assistants and retrieval
A GenAI assistant that answers from Group content inherits every permission error already present in that content.
Fix permissions before enabling retrieval. An assistant surfaces what a user could technically already reach, at a speed no human search would achieve.
Ground on approved sources. Retrieval scope must be defined, reviewed and restricted for sensitive domains.
Log prompts and outputs proportionately. Where an assistant informs a decision affecting a person, the interaction is evidence.
Do not let assistants create shadow records. Generated summaries used for decisions must be stored in the approved repository, classified and retained.
Approved tools only. Confidential and personal information must never be entered into unapproved AI services.
From Datasets to Data Products
A dataset is data that someone saved somewhere. A data product is data with a named owner,
a quality promise, documented lineage and a published audience , data that another team can
consume without having to investigate whether it is trustworthy. Why it matters: at Shoprite's scale, unowned datasets multiply faster than anyone
can track them. Every team that cannot find a certified source builds their own copy.
Read this if your team publishes data that others depend on, or if you are tired of
reconciling numbers that should be the same.
What makes something a data product
A certified data product is a governed, reusable asset with a named owner and a published promise about quality and meaning.
Named Data Sponsor and Data SME, published in the catalogue and reachable by consumers.
Defined purpose and audience, with permitted use and any personal-information constraints stated up front.
Documented quality expectations covering the dimensions that matter for that use, with monitoring and a visible current position.
Lineage to source, refresh frequency, known limitations and a change and deprecation route.
Retention and classification inherited from source, applied to the product, its copies and its backups.
Data contracts and machine-enforceable rules
Governance holds when the rule is executed by the platform rather than remembered by a person.
Contract at the interface. Producer and consumer agree schema, semantics, quality thresholds, availability and change notice.
Break the build, not the report. Contract violations should fail in the pipeline before they reach a dashboard or a model.
Metadata as the control plane. Classification, ownership, personal-information flags and retention tags must be machine-readable and carried downstream.
Agent-ready by design. Automated and agentic consumers cannot infer intent. Ambiguous definitions become incorrect actions at machine speed.
Deprecation is governance. Retiring an asset needs the same discipline as launching one.
Personalisation Is a Governance Decision
Every time the Xtra Savings engine surfaces a personalised offer, it makes a data
decision , about what we know, what we inferred and whether we have the right to use it
that way. The commercial opportunity and the POPIA exposure are not separate conversations:
they are the same conversation. Why it matters: the Information Regulator named direct marketing as a
priority enforcement area in 2026. A personalisation model is both a revenue engine and
a processing activity that must be justified. Read this if you work on
loyalty, offer management, customer analytics, Sixty60, or any AI that touches customer
behaviour data.
Direct marketing and electronic communication
Section 69 of POPIA restricts unsolicited electronic direct marketing, and the Information Regulator has named direct marketing and breach management as priority enforcement areas.
Know which basis applies. Existing customers and non-customers are treated differently. Record which basis was relied on for each contact, not just the outcome.
Consent must be evidenced. The record of when, how and for what a person agreed is the control. A statement that consent was obtained is not.
Opt-out must actually work. Objections must propagate across every channel and every downstream copy of the marketing audience, including partner and agency lists.
Segment definitions are governed data. An audience built on an incorrect or stale attribute reaches the wrong person with the wrong message.
Children and special categories. Higher-sensitivity attributes require stronger justification and tighter access, not just a flag in a table.
Fairness in what the customer experiences
A personalisation model makes thousands of small decisions about people every minute. Governance asks whether we would be comfortable explaining any one of them.
Be able to explain the offer. Where a customer asks why they received a price, a promotion or a recommendation, someone must be able to answer without reverse engineering a model.
Watch for proxy discrimination. Location, store, basket composition and payment method can stand in for protected characteristics without anyone intending it.
Set the boundary before the pilot. Agree what the Group will not do with customer data while the commercial pressure is still low.
Separate inference from fact. A predicted attribute is not a verified one. Downstream systems must be able to tell the difference.
Health and pharmacy data is different. Health information regulations took effect on 6 March 2026 with no grace period. Pharmacy data must not flow into general marketing or analytics populations.
Know Where We Are and What Improves
Governance that cannot be measured cannot be defended. Maturity and adherence are
reported through the Group governance structures.
LEVEL 1
Ad hocOwnership unclear, definitions inconsistent, issues found by accident.
LEVEL 2 → 3
Defined → OperatingPolicies and standards published. Catalogue and quality monitoring now active. Formal issue management in progress. Standards being embedded in delivery.
LEVEL 3
OperatingStandards applied in delivery, catalogue and quality monitoring in use, issues managed formally.
LEVEL 4
MeasuredAdherence reported, controls tested, remediation tracked to closure with evidence.
LEVEL 5
EmbeddedRules enforced in platform, governance is automatic rather than requested.
Data Governance Action Centre
Report concerns early. Use the correct route so issues can be assessed, prioritised,
contained and resolved through the right accountable teams.
I have a Data Quality or Governance issue
Wrong or missing data, unclear definition, duplicates, missing ownership, weak metadata,
retention concern or control weakness?
Start with the applicable Group framework, policy, standard or guideline. Contact
Data Governance where published guidance does not resolve the question.
Ownership, Stewardship & Decision Rights
Data is a Group asset. It is entrusted to Data Sponsors who are accountable for its value, quality and governance.
Executive Sponsor. Champions the Group Data Governance programme at executive level, removes blockers and clarifies strategic priority.
Data Sponsor. An accountable business executive for a Data Domain, owns value, meaning, quality expectations, access decisions and remediation priority. This role cannot be delegated indefinitely.
Data SME. Maintains business definitions, quality rules, glossary content, catalogue records and day-to-day governance discipline within the domain.
Data Custodian. Implements storage, integration, security, access permissions, metadata, quality monitoring, backup and lifecycle controls. Technical accountable owner.
Data Governance Office. Enables standards, monitors adherence, aligns related functions, provides advice and escalates material risk. The DGO does not own the data, the business does.
Forums. The Data Governance Steering Committee, Data Councils and Data Focus Areas prioritise, challenge, resolve and escalate risk across the Group. Attendance is governance, not optional.
Personal-information decisions. The Group is the responsible party under POPIA. Accountability for a processing or sharing decision sits with the business Data Sponsor, advised by Legal, Compliance and Privacy.
Records, Retention & Defensible Disposal
Every record has a retention floor and a disposal trigger. Both must be documented and enforced.
Retention is mandatory, not optional. The Group Retention Schedule identifies the retention floor for each record category. Business need may extend it; convenience may not shorten it.
Trigger events matter. The retention clock starts from a defined trigger, contract end, last transaction, employee exit, financial year close, date of birth. Identify the trigger before deciding the period.
Legal holds override everything. When litigation, investigation, regulatory inquiry or a preservation notice applies, routine disposal must stop immediately across every copy, including backups and collaboration sites.
Defensible disposal requires evidence. Record what was destroyed, under which rule, when, by whom and with what approval. Disposal without documentation is not defensible in a dispute.
Copies and extracts are in scope. Analytics extracts, dashboard screenshots, email forwards, SharePoint copies and backup tapes carry the same retention obligation as the source. They are not exempt.
SAP data has long floors. Financial and tax-relevant records sit at seven years minimum under the Companies Act. Some employee records extend to ten. Check the schedule before any migration, archive or decommission.
The Retention Standards application contains the full Group Legal Retention Schedule and a system-level tool for applying rulings. Open the Retention Standards →
Lifecycle, Architecture & Custodianship
Moving data does not reset its classification, ownership, privacy, retention or accountability.
Govern from design. Bring Data Governance into architecture and design before code is written, not after go-live. Retrofitting governance into a live platform costs ten times more than designing it in.
Classification travels. A dataset classified as Confidential in SAP does not become Internal simply by landing in Snowflake. Classification inherits downstream.
Lineage is the audit trail. Every transformation, load and movement must be traceable to source. No lineage means no governance, no debugging and no regulator comfort.
Decommission is a governance event. Switching off a system that holds regulated records, live personal information or unresolved legal holds requires a formal plan, not an IT ticket.
Custodianship follows the data. Every platform, SAP, Snowflake, SharePoint, Power BI, SaaS, cloud, must have a named technical owner accountable for controls in that environment.
Data Design Review Board. Material data architecture decisions, new integrations, analytics platforms, AI pipelines, shared datasets, major migrations, require a design review before build.
AI, Analytics & Responsible Innovation
AI requires accountable ownership, risk classification, lawful data, human oversight, monitoring and a retirement plan.
Register before you build. Every material AI use case must be registered with a named AI System Owner and an agreed risk tier before development begins, not before launch.
Lawful, quality, permitted data only. Training data, feature data and retrieval content must have documented provenance, an approved purpose and the necessary permissions. Personal information in AI requires a lawful basis for that specific use.
Risk tiers determine assurance depth. A recommendation engine used for promotional targeting carries different risk to a demand forecast. Assurance requirements scale with impact on people and the business.
Human oversight must be meaningful. Meaningful means a person can review, override or stop an automated decision in time for it to matter. A dashboard that nobody reads is not oversight.
Monitor after go-live. Model drift, data drift and emergent behaviour require continuous monitoring. Governance does not end at deployment.
Retire responsibly. Agree the retirement condition when you make the deployment decision. Training data, outputs and logs have retention and disposal obligations. Delete in order.
Approved tools only. Confidential information and personal information must not be entered into unapproved AI tools, assistants or external services, including free consumer tools.
Detail
Title
Governance in Action
Governance detail
Contact the Data Governance Office
Select the most appropriate contact for your question. For urgent privacy or
security incidents, use the urgent incident route instead.
Move by header • Resize from bottom-right • Site remains active behind the window
Keep it safe: Do not enter customer data, employee data, personal information,
credentials, confidential commercial information, source code, contract details or incident facts.
Suggested questions
Hello. I am the Shoprite Governance Guide.
I can explain foundational Data Governance, Responsible AI, Data Quality, metadata,
records, lineage and data sharing.
I can also assist with urgent lost-device and password-reset routing.
⌘
Data Governance Decision Tool
Move by header • Resize from bottom-right • Links behind this window still work
Choose the scenario closest to your work. This tool provides foundational guidance and
routes you to the correct accountable owner or team.
Recommended route
Shoprite Data Governance Principles
Grounded in the Group Data Governance Framework and responsible use of I&T assets.
The Board is responsible for Data Governance. Management must establish effective systems and frameworks for responsible use of information assets.
Executive sponsorship drives Data Governance. Governance needs leadership, prioritisation, resourcing and removal of blockers.
Data is a corporate asset. It must be actively managed throughout its lifecycle.
Data is entrusted to Data Sponsors. Data Sponsors, Data SMEs and Data Custodians must have clear responsibilities and decision rights.
Data is classified and protected proportionately to risk. Classification, privacy, security and access must reflect sensitivity and potential harm.
Data Quality is fit-for-purpose. Requirements reflect business use, decision impact, cost and risk.
Data is shared fairly and legally. Sharing needs legitimate purpose, controls and appropriate agreements.
AI requires ethical use of data. AI needs ownership, lawful and quality data, risk assessment, human oversight and monitoring.
Data Governance Standards Library
Foundation documents establish common language. Standards and procedures provide detailed requirements.
Data Governance Framework. governance drivers, principles, operating model, roles and practices.
Data Retention Policy and Retention Schedule – Legal Standards. retention, archival, backup alignment and defensible disposal. Open →
Data Protection and Privacy Policy. POPIA-aligned collection, storage, sharing, DPIAs and incident reporting.
Data Quality Policy. Critical Data Elements, dimensions, monitoring, issues and remediation.
Information Classification, Handling and Sharing Process. Secret, Confidential, Private and Public classifications.
AI Policy. risk classification, acceptable use, GenAI controls, ownership, third-party AI and monitoring.
PAIA Manual. access-to-information processes and POPIA-related request forms.
Classification, Privacy & Protection
Information must be classified, processed lawfully and protected throughout its lifecycle.
Classify information. Group classification includes Secret, Confidential, Private and Public. Regulated information including personal information is Confidential.
Process personal information lawfully and reasonably. Define purpose, collect only what is needed and apply security safeguards.
Apply least privilege. Access to personal and confidential information is need-to-know based.
Assess privacy early. Projects processing personal information require assessment and a DPIA where applicable.
Share with control. External sharing requires purpose, agreements, security, confidentiality, due diligence and return/destruction provisions.
Justify every cross-border transfer. Section 72 requires a recorded basis. There is no adequacy list to rely on, and remote access from another country is a transfer.
Apply the health information regulations. Regulations on the processing of health information took effect on 6 March 2026 with no grace period. confirm applicability to Group entities
Report a security compromise promptly. Section 22 requires notification to the Information Regulator and affected data subjects as soon as reasonably possible after discovery, through the approved Group route.
Data Quality, Master & Reference Data
Data Quality is a business outcome managed through accountable ownership and measurable controls.
Quality must be fit-for-purpose. The threshold depends on data use and consequence of error.
Use recognised dimensions. Accuracy, completeness, consistency, timeliness, validity, uniqueness and integrity.
Prioritise Critical Data Elements. Define rules, targets, monitoring and remediation for high-impact data.
Fix data close to source. Root-cause remediation and upstream validation are preferable to repeated downstream correction.
Maintain authoritative shared data. Master and reference data requires ownership, quality expectations and controlled change.
Metadata, Catalogue & Lineage
Metadata provides the context needed to find, understand, trust and govern information assets.
Business metadata includes definitions, Data Sponsor, Data SME, business purpose, classification, quality expectations and retention requirements.
Technical metadata includes systems, tables, fields, structures, integration flows, technical owners and profiling rules.
Lineage tracks data from source through transformation to reports, dashboards, analytics, data products and AI systems.
Metadata is active. It must be maintained through change and monitored for inaccuracy, inconsistency and gaps.
Cataloguing enables reuse. Trusted catalogues and business glossaries reduce duplicate extracts, conflicting definitions and reinvention.
Access, Sharing & Data Ecosystems
Data sharing can create value, but it must be transparent, controlled, fair and lawful.
Start with purpose. Sharing needs a legitimate documented purpose and legal, regulatory and contractual compliance.
Apply appropriate access controls. Use least privilege and configure access at the right level.
Use formal agreements. Data Sharing Agreements and data contracts establish permitted use, protection, retention, accountability and auditability.
Know the ecosystem. Third parties, processors, cloud providers, APIs and data-product consumers require due diligence and monitoring.
Maintain traceability. Data must remain traceable from source through consumption.
Risk, Issues, Assurance & Evidence
Good governance creates evidence as work happens instead of reconstructing it only when asked.
Monitor adherence. The Data Governance Office monitors alignment to Framework and policies with risk, security, privacy, technology and business teams.
Manage issues formally. Quality, access, records, privacy, security, metadata and control issues must be logged, prioritised, assigned and remediated.
Escalate material risk. The Framework describes reporting through management risk structures, the Audit and Risk Committee and Governance Steering Committee.
Retain evidence. Keep evidence of policies, approvals, access decisions, quality monitoring, exceptions, legal holds, disposal, assessments and remediation.
Learn and improve. Findings, incidents, audits and control testing should improve processes, systems, training and standards over time.
Data Governance Glossary
Common language is the first control. If two teams define a term differently, every number built on it is disputed.