Data governance for PE portfolio companies: a minimum viable set of four controls
Data governance for a private equity portfolio company can start with four controls rather than a data office: a named owner for every system, a written retention schedule, quarterly admin access reviews and a rights register showing who created the records and what contracts allow. The same four documents are the base of a defensible data license.
The minimum viable set
A portfolio company with a few hundred employees needs four governance controls, each about a page long and each owned by a named executive: a system register with an owner per system, a retention schedule, a quarterly access review and a rights register. Hand the pack to the CFO or COO, review it every quarter, and show it to the board once a year. Each control answers a question that a lender, acquirer, auditor or data licensee will eventually ask, so the work pays off even if the company never licenses anything.
Why lean beats a framework project in the mid-market
Enterprise governance frameworks assume a chief data officer, data stewards in each function and a standing council. A 50-500 employee company has a controller, an IT manager or managed service provider, and a stack of SaaS tools bought by different departments. A framework rollout stalls in that setting; four short documents get finished.
Long holds strengthen the case. PitchBook reported that the median holding period of US PE-backed companies still in portfolios reached 3.4 years at the end of 2024, the longest in more than nine years, with more than 30% held at least five years. Over a hold that long, the CFO, the IT lead and half the tool stack can change. Governance written down survives those changes; governance in one person's head does not.
Prerequisites
- A sponsor-level decision that the pack is a 100-day or annual-plan deliverable, not an optional project
- Card and accounts payable data for the last two years, to find tools IT does not manage
- Copies of the current privacy notice, employee handbook, standard customer terms and contractor agreement templates
- Access to outside counsel for a few hours of review
Step 1: name an owner for every system
List every system with a login, including tools bought on a corporate card. Well-run companies in this size range often run 10-15 or more. For each one, record:
| Field | What to record | Why it matters |
|---|---|---|
| Owner | A named executive accountable for the system | Someone decides retention, access and exports |
| Admins | Every account with admin or super-admin rights | A resignation does not strand the company |
| History | First year of records and approximate volume | Shows depth for diligence and licensing |
| Retention setting | Auto-delete rules, archive settings, plan limits | Silent deletion is the easiest loss to miss |
| Personal data | Whether it holds consumer, employee or health data | Sets privacy handling and redaction needs |
| Renewal date | Contract end and cancellation notice period | Stops a lapse from deleting history |
Step 2: write a retention schedule people can follow
Write the schedule by record category, not by system: finance and tax records, HR files, customer correspondence, support tickets, engineering history, chat and meeting records. Counsel and the tax adviser set the minimums for each category. Then add one house rule that matters most: no category is deleted, and no auto-delete setting changed, without the system owner's sign-off logged in the register. Add a line for how litigation holds override the schedule.
Step 3: review access every quarter
The quarterly review is short: remove departed users, cut super-admins to two named people per system, retire shared logins and list every vendor or MSP account with access. For some portfolio companies this is a legal requirement rather than hygiene. The FTC's Safeguards Rule guide explains that its definition of a financial institution reaches many non-bank businesses, such as mortgage brokers, finance companies, collection agencies and tax preparation firms, which must maintain a written information security program.
Step 4: keep a rights register
For each major dataset, record who created it, under what agreement, what customer contracts say about it, what the company promised in its notices, and whether any license already covers it.
- Employees. The Copyright Office's circular on works made for hire explains that the employer is the author and owner of work an employee prepares within the scope of employment.
- Contractors. Commissioned work counts as made for hire only in limited categories and with a signed agreement, so freelance and agency output generally needs a written assignment.
- Promises. FTC staff have stated that promises not to use customer data for undisclosed purposes, such as training models, are enforceable whether made in privacy policies, terms of service or marketing materials. Log what the company has promised and where.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
A 90-day rollout
| Weeks | Work | Owner | Output |
|---|---|---|---|
| 1-2 | Pull the tool list from card, accounts payable and IT records | Controller, IT lead | Draft system register |
| 3-4 | Name owners, record admins and retention settings, freeze deletions | CFO | Completed register |
| 5-8 | Draft the retention schedule and have counsel review it | CFO, counsel | Approved schedule |
| 9-10 | Run the first access review and cut excess super-admins | IT lead or MSP | Access log |
| 11-13 | Build the rights register for the five largest datasets; present the pack to the board | CFO, counsel | Rights register and board minute |
The schedule fits inside the portfolio company CFO's first 90 days when a new CFO arrives with the deal. To launch it across a fund, a 30-minute session at the portfolio CEO summit works well. Roll-ups face the same work multiplied by every add-on; the HVAC and plumbing roll-up screen shows how it applies when each acquired business brings its own field-service software.
Common mistakes
| Mistake | Consequence | Better approach |
|---|---|---|
| Starting with a policy manual | Nobody reads it, and no inventory exists | Start with the system register |
| Counting only IT-managed tools | Department-bought tools often hold the deepest history | Pull card and accounts payable data |
| One super-admin per system | One resignation locks the company out | Two named admins, recorded |
| Leaving retention at vendor defaults | Defaults may delete too early or never | Set and document each setting |
| Leaving rights to exit diligence | Gaps surface under deal pressure | Keep the rights register current |
Illustrative example: a distributor's first pass
Illustrative only; the company is fictional. Cedar Line Supply, a fictional 220-person industrial distributor four years into a lower-middle-market hold, runs an ERP, a CRM, a customer service desk, a warehouse management system, email and chat. Its new CFO builds the register in two weeks and finds three problems: the service desk deletes closed tickets after three years, the CRM's only super-admin left last spring, and product descriptions were written by freelancers with no assignment clause. The fixes take one quarter. Retention is changed and logged, two admins are named, assignments are signed for current freelancers, and older freelance content is flagged in the rights register.
How the four controls support a data license
| Control | Licensing question it answers |
|---|---|
| System register | What records exist, how far back, and can they be exported? |
| Retention schedule | Is the history intact, or were years deleted? |
| Access review | Who can run exports under supervision when the time comes? |
| Rights register | Does the company have the right to license, and what must be excluded or redacted? |
With the pack in place, a company that reached 50+ full-time employees at peak (contractors excluded), has several years of documented operations and an executive willing to sponsor an application can move straight to a data inventory. The data inventory builder helps list systems and records, and the guide on how PE teams assess portfolio company data opportunities covers the screen. The same documents also feed the exit data book.
Operating partners who introduce a qualifying company never touch its records. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee; no reward is guaranteed. The operating partner hub explains the role.
Next step
Ask each portfolio CFO for a draft system register by the next board meeting. When one shows deep, rights-clean history, register as a partner and make the introduction, or have the CEO apply at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who should own data governance in a portfolio company without a CIO?
Give the pack to one executive, often the CFO or COO, and make each system the responsibility of the leader who uses it most. The IT lead or managed service provider runs the access review, and counsel reviews the retention schedule and rights register. Ownership matters more than title: someone must answer for each system when asked.
How is this different from the company's cybersecurity program?
Security protects systems from unauthorized access and attack. These four controls cover what the company keeps, who is accountable for it and what the company has the right to do with its records. They overlap at the access review, so share that work with the security lead, but a strong security program can still leave a company unable to say who owns its data.
Does the rights register need a lawyer to build it?
An operator can assemble most of it: which teams and contractors created which records, which contracts mention data use, and what the privacy notice said over time. Counsel should review the conclusions, especially contractor ownership, customer confidentiality terms and anything involving consumer, financial or health data. Keeping facts and legal judgments in separate columns helps both.
How often should the system register be updated?
Review it quarterly alongside the access review, and update it whenever a tool is bought, cancelled or migrated. Acquisitions, ERP or CRM projects and leadership changes are when it goes stale fastest, so add a register update to the checklist for each of those events and to every add-on integration plan.
Should a sponsor standardize governance across the whole portfolio?
Standardize the templates and the cadence, not the systems. A common register format, retention template and quarterly review rhythm let the operating team compare companies and spot licensing candidates quickly. Each company still fills in its own systems and rights, because contracts, customers and record histories differ from one business to the next.
Related pages
- The portfolio company CFO's first 90 days: cash, covenants, systems and records
- Portfolio company CEO summit agenda ideas, with a 30-minute data licensing session
- HVAC and plumbing roll-ups: a data licensing screen for private equity teams
- Build a metadata-only business data inventory
- How private equity teams can assess portfolio company data opportunities
- The exit data book: how KPI preparation also makes a company licensing-ready
Free resources
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment