Data governance for PE portfolio companies: a minimum viable set of four controls

Data governance for a private equity portfolio company can start with four controls rather than a data office: a named owner for every system, a written retention schedule, quarterly admin access reviews and a rights register showing who created the records and what contracts allow. The same four documents are the base of a defensible data license.

The minimum viable set

A portfolio company with a few hundred employees needs four governance controls, each about a page long and each owned by a named executive: a system register with an owner per system, a retention schedule, a quarterly access review and a rights register. Hand the pack to the CFO or COO, review it every quarter, and show it to the board once a year. Each control answers a question that a lender, acquirer, auditor or data licensee will eventually ask, so the work pays off even if the company never licenses anything.

Why lean beats a framework project in the mid-market

Enterprise governance frameworks assume a chief data officer, data stewards in each function and a standing council. A 50-500 employee company has a controller, an IT manager or managed service provider, and a stack of SaaS tools bought by different departments. A framework rollout stalls in that setting; four short documents get finished.

Long holds strengthen the case. PitchBook reported that the median holding period of US PE-backed companies still in portfolios reached 3.4 years at the end of 2024, the longest in more than nine years, with more than 30% held at least five years. Over a hold that long, the CFO, the IT lead and half the tool stack can change. Governance written down survives those changes; governance in one person's head does not.

Prerequisites

  • A sponsor-level decision that the pack is a 100-day or annual-plan deliverable, not an optional project
  • Card and accounts payable data for the last two years, to find tools IT does not manage
  • Copies of the current privacy notice, employee handbook, standard customer terms and contractor agreement templates
  • Access to outside counsel for a few hours of review

Step 1: name an owner for every system

List every system with a login, including tools bought on a corporate card. Well-run companies in this size range often run 10-15 or more. For each one, record:

FieldWhat to recordWhy it matters
OwnerA named executive accountable for the systemSomeone decides retention, access and exports
AdminsEvery account with admin or super-admin rightsA resignation does not strand the company
HistoryFirst year of records and approximate volumeShows depth for diligence and licensing
Retention settingAuto-delete rules, archive settings, plan limitsSilent deletion is the easiest loss to miss
Personal dataWhether it holds consumer, employee or health dataSets privacy handling and redaction needs
Renewal dateContract end and cancellation notice periodStops a lapse from deleting history

Step 2: write a retention schedule people can follow

Write the schedule by record category, not by system: finance and tax records, HR files, customer correspondence, support tickets, engineering history, chat and meeting records. Counsel and the tax adviser set the minimums for each category. Then add one house rule that matters most: no category is deleted, and no auto-delete setting changed, without the system owner's sign-off logged in the register. Add a line for how litigation holds override the schedule.

Step 3: review access every quarter

The quarterly review is short: remove departed users, cut super-admins to two named people per system, retire shared logins and list every vendor or MSP account with access. For some portfolio companies this is a legal requirement rather than hygiene. The FTC's Safeguards Rule guide explains that its definition of a financial institution reaches many non-bank businesses, such as mortgage brokers, finance companies, collection agencies and tax preparation firms, which must maintain a written information security program.

Step 4: keep a rights register

For each major dataset, record who created it, under what agreement, what customer contracts say about it, what the company promised in its notices, and whether any license already covers it.

  • Employees. The Copyright Office's circular on works made for hire explains that the employer is the author and owner of work an employee prepares within the scope of employment.
  • Contractors. Commissioned work counts as made for hire only in limited categories and with a signed agreement, so freelance and agency output generally needs a written assignment.
  • Promises. FTC staff have stated that promises not to use customer data for undisclosed purposes, such as training models, are enforceable whether made in privacy policies, terms of service or marketing materials. Log what the company has promised and where.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

A 90-day rollout

WeeksWorkOwnerOutput
1-2Pull the tool list from card, accounts payable and IT recordsController, IT leadDraft system register
3-4Name owners, record admins and retention settings, freeze deletionsCFOCompleted register
5-8Draft the retention schedule and have counsel review itCFO, counselApproved schedule
9-10Run the first access review and cut excess super-adminsIT lead or MSPAccess log
11-13Build the rights register for the five largest datasets; present the pack to the boardCFO, counselRights register and board minute

The schedule fits inside the portfolio company CFO's first 90 days when a new CFO arrives with the deal. To launch it across a fund, a 30-minute session at the portfolio CEO summit works well. Roll-ups face the same work multiplied by every add-on; the HVAC and plumbing roll-up screen shows how it applies when each acquired business brings its own field-service software.

Common mistakes

MistakeConsequenceBetter approach
Starting with a policy manualNobody reads it, and no inventory existsStart with the system register
Counting only IT-managed toolsDepartment-bought tools often hold the deepest historyPull card and accounts payable data
One super-admin per systemOne resignation locks the company outTwo named admins, recorded
Leaving retention at vendor defaultsDefaults may delete too early or neverSet and document each setting
Leaving rights to exit diligenceGaps surface under deal pressureKeep the rights register current

Illustrative example: a distributor's first pass

Illustrative only; the company is fictional. Cedar Line Supply, a fictional 220-person industrial distributor four years into a lower-middle-market hold, runs an ERP, a CRM, a customer service desk, a warehouse management system, email and chat. Its new CFO builds the register in two weeks and finds three problems: the service desk deletes closed tickets after three years, the CRM's only super-admin left last spring, and product descriptions were written by freelancers with no assignment clause. The fixes take one quarter. Retention is changed and logged, two admins are named, assignments are signed for current freelancers, and older freelance content is flagged in the rights register.

How the four controls support a data license

ControlLicensing question it answers
System registerWhat records exist, how far back, and can they be exported?
Retention scheduleIs the history intact, or were years deleted?
Access reviewWho can run exports under supervision when the time comes?
Rights registerDoes the company have the right to license, and what must be excluded or redacted?

With the pack in place, a company that reached 50+ full-time employees at peak (contractors excluded), has several years of documented operations and an executive willing to sponsor an application can move straight to a data inventory. The data inventory builder helps list systems and records, and the guide on how PE teams assess portfolio company data opportunities covers the screen. The same documents also feed the exit data book.

Operating partners who introduce a qualifying company never touch its records. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee; no reward is guaranteed. The operating partner hub explains the role.

Next step

Ask each portfolio CFO for a draft system register by the next board meeting. When one shows deep, rights-clean history, register as a partner and make the introduction, or have the CEO apply at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Who should own data governance in a portfolio company without a CIO?

Give the pack to one executive, often the CFO or COO, and make each system the responsibility of the leader who uses it most. The IT lead or managed service provider runs the access review, and counsel reviews the retention schedule and rights register. Ownership matters more than title: someone must answer for each system when asked.

How is this different from the company's cybersecurity program?

Security protects systems from unauthorized access and attack. These four controls cover what the company keeps, who is accountable for it and what the company has the right to do with its records. They overlap at the access review, so share that work with the security lead, but a strong security program can still leave a company unable to say who owns its data.

Does the rights register need a lawyer to build it?

An operator can assemble most of it: which teams and contractors created which records, which contracts mention data use, and what the privacy notice said over time. Counsel should review the conclusions, especially contractor ownership, customer confidentiality terms and anything involving consumer, financial or health data. Keeping facts and legal judgments in separate columns helps both.

How often should the system register be updated?

Review it quarterly alongside the access review, and update it whenever a tool is bought, cancelled or migrated. Acquisitions, ERP or CRM projects and leadership changes are when it goes stale fastest, so add a register update to the checklist for each of those events and to every add-on integration plan.

Should a sponsor standardize governance across the whole portfolio?

Standardize the templates and the cadence, not the systems. A common register format, retention template and quarterly review rhythm let the operating team compare companies and spot licensing candidates quickly. Each company still fills in its own systems and rights, because contracts, customers and record histories differ from one business to the next.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment