Data Centers play a leading role in today's society and tomorrow's. Even so, inside and outside their organizations they remain almost invisible, and they're rarely talked about beyond what they cost.
Data governance is a good example. It shows up in the news and in the boardrooms of large companies. It's almost always treated as something intangible. But you can touch it. At least, at its foundation.
Eleven cases of failure and no trace of the Data Center
If you review the cases from the last three years in which data governance has failed, a very simple question arises: does the Data Center appear in any of them?
None of the eleven case files mentions a technical failure. In none of them is the Data Center listed as the cause. And yet, there we are. Not on the front line, but in the foundation that supports that data.

The data's ID card
There are countless definitions of data governance. I'll go with one of the most widely accepted, from DAMA International: "the exercise of authority, control, and shared decision-making over the management of data assets."
In simple terms, deciding who's in charge of the data and how you check that what was agreed is being followed. Put that way, it sounds a little cold, so I prefer to compare it to an ID card, something we all know.
Just as we answer a few basic questions to identify ourselves, data should also be able to answer its own. Where is it? Who has accessed it? How long has it been there? What is it used for?

Let's take a very ordinary example: a customer record. Which server is it stored on? Who has opened it this month? How long have we had it? Do we use it for billing or for marketing campaigns? If a company can answer those four questions, that piece of data has its ID card in order.
This is starting to sound like a Data Center, isn't it?
Now, how many organizations can say that all their data has its ID card in order? Certifications like ISO 27001 (the international standard for information security) are a good starting point. At Bjumper we saw this firsthand when we obtained ENS High and ISO 27001. But getting certified doesn't mean having 100% of your data governed.
And data governance isn't something you achieve and file away, either. Every new system, supplier or regulation pushes it a little further out.
Why is governing data so hard for us?
The answer has to do with three things that are happening at the same time.
Regulation is tightening
It's the most boring one, but it's the one that has forced us to think about governance, or at least to give it a name and a framework. And the list of regulations keeps growing: the GDPR (personal data protection in Europe), the AI Act (the European artificial intelligence law), NIS2 (cybersecurity for essential services), DORA (digital resilience in the financial sector), the LGPD (Brazil's data protection law) and many more.
What sets them apart from the quality standards we were used to is how demanding they are. Having documented policies and processes is no longer enough. Now you have to prove they're being followed.
They used to ask for the manual. Now they ask for the log, that is, the record of what actually happened. And that shift in mindset explains, I think, why the goal sometimes seems to slip away from us.
It's like the difference between showing the recipe book and showing the kitchen footage. It's no longer enough to explain how the dish is made. You have to prove it was made that way, every single day.
The fortress no longer has walls
Just think of a company in the early 2000s: local management software, files on a shared server. You knew exactly where every piece of data was and who could access it.
It was a fortress. So much so that 25 years ago hardly anyone had heard of the CISO (the chief information security officer), and the security team, if there was one, barely got involved in your work. It was also the era of the big Enterprise Data Centers, and no bank would have dreamed of running a service outside its own infrastructure.
Today that same CISO (now with a name and a title) has to govern the ERP contracted as a service from an external provider, a hybrid Data Center, partly owned and partly rented in a CoLo, and cloud applications. The data has escaped the perimeter. The fortress walls have been erased, at least in part.
Data used to live at home. Now it lives at home, in a rented apartment and in a hotel, all at once. And good luck figuring out who has the keys to everything.
Our new friend, AI
And the most recent one: democratized AI (because AI existed before). It's practically uncontrollable, even in organizations with their own models. If someone runs out of quota on their corporate tool (the famous tokens) and they're in a hurry, and we're always in a hurry, they'll jump to another tool. And they'll end up pasting a contract or a customer list into a public chatbot, where that data should never be.
There's a great deal left to discuss here, and I don't feel ready to give answers. What I am clear about is that it's best not to get ahead of ourselves. As we explained in «ou don't need AI to operate your Data Center yet», processes and data come first.
How much control do we really have? Welcome to the gray zone
With regulation, invisibility and AI on the table, the question asks itself: how much control can we have over our data?
Total control? You'd need to have everything in an Enterprise Data Center, with local AI and no critical systems in SaaS. Honestly, few companies in the world could say yes. Perhaps none.
High risk, then, with zero visibility and zero control? I don't think so either.
Because there's no yes or no here, no ones or zeros. It's more like life itself, which is almost always gray. And grays are much harder to measure. That's where most of us are, with hybrid models.

The good news is that measuring grays isn't easy, but it can be done. There are data governance maturity models that tell you where you stand, how far you are from your own goals, and even how you compare with your industry.
A maturity model works like school report cards by subject. Besides telling you whether you pass, it shows you what you're doing well in and what you'd need to study to raise your grade.
One of the most comprehensive is the CMMI Data Management Maturity Model, from the CMMI Institute. It defines five maturity levels and covers six areas: strategy, quality, operations, platform, governance and processes. Note that last one. Processes will always be there.
Want to know what shade of gray your infrastructure is? That's why we designed our free data maturity report.
Business versus security, with the Data Center right in the middle
And why are we in the gray zone? Wouldn't it be easier to be in the green?
Because in every organization, public or private, there's a slight tension. At first glance it seems like a contradiction, but it's really a matter of objectives. On one side, what Legal, Security and Compliance want. On the other, what the business or the service we offer demands.
The market, whether banking, industry, telecommunications or utilities, is more competitive every day. It needs a speed and flexibility that the green of the past doesn't provide, at least at first glance.
And where are we, the Data Center? If you think about it, right in the middle of that tension. But we're rarely part of the conversation. Infrastructure is discussed implicitly, without involving the professionals who know it best.
And that's what we need to correct. We're a fundamental piece of this discussion. We can, and must, be part of the solution.
The base of the pyramid
NVIDIA calls AI Data Centers "iAI factories." And the name is very well chosen.
NVIDIA has also described AI as a five-layer model. Infrastructure is one of them, and without it there are no models or applications to control.

Without controlling that physical foundation, data governance is a policy floating in thin air.
And I come back to DAMA's definition, which spoke of governing "assets." Call me naive, but I like to think that, when they said assets, they were thinking of us.
Others already talk about us, but they rarely invite us into the conversation. It's time to claim our place. Not as mere hosts of infrastructure, but as architects.
The Data Center's ID card
If we agree that data governance goes through Data Center governance, the conclusion is straightforward. We need our own ID card too.
And how does the data's ID card translate into the Data Center's? Field by field. When the conversation reaches infrastructure, this is what they'll ask us, and this is what we can answer:

We're not inventing anything new. We're organizing what we already know how to do and putting it at the service of a conversation we should have been part of for a long time.
What we contribute from the infrastructure side is called traceability. That is, being able to track every piece of equipment, knowing where it is and who has touched it, like a package's tracking number. Exactly what governance asks of us. And, going further, it's the foundation of automation, which will be our best ally. I've already explained why nothing really works without integrations between systems..
This isn't about technology
It's about organizational discipline. Governing infrastructure means knowing why each asset exists and what business decision it supports. Also what it means within the company, not just within the system, and what happens if it fails, if it's in the wrong location, or if someone accesses it without permission.
The Data Center isn't IT's problem. It's the starting point of governance. And if we're not part of that conversation, someone will make those decisions without us.
Our part of the solution
We're not going to solve everything, I'll be honest. The heavy lifting falls on Systems, on IT, on the teams that manage data at the logical level. But we are part of the solution. And being part of the solution will give us the relevance we've been seeking for a long time.
Data Center governance comes to add to data governance, to complete it from the physical side.
Is what we do today enough?
Not quite.
Today our KPIs measure availability, performance, capacity and efficiency. We answer the question "how does it work?" very well. But data governance asks more of us.
Reliability is something we already work on. It's the foundation of everything we do and the argument on which we've built our reputation.
Visibility is where we're stretched thinner. Knowing whether a system is up or down is no longer enough. You need to know what workload is running, what data is being processed and what business decision that asset is supporting right now.
And then there's accountability, the most uncomfortable one. Who owns that asset within the organization? Who bears the consequences if something fails?
Operational excellence will lead us to governance if we make the leap. Moving from answering how it works to answering why it exists and what happens if something goes wrong. Because, as I've written before, design lays the foundations, but it's operations that sustain the Data Center.
The framework we're building at Bjumper
Precisely because it isn't easy, at Bjumper we're building a Data Center governance framework. It works on three pillars:
- Accountability, that is, who is in charge of what, with what criteria and with what consequences.
- Traceability, without which it won't be possible to automate or certify.
- Trust, which is tied to automation. The more automation, the more reliable the data, because we stop depending on manual updates in repetitive operations. It's the same path that leads ustoward autonomous Data Center operation.
We're building it right now. It's a draft, not a finished product. If you'd like to be part of this conversation, even if only to challenge the approach, we'd be delighted to present it to you and hear what you think.
Enterprise or CoLo: two realities with the same opportunity
Before wrapping up, an important nuance. Data Center governance applies to both major realities in the sector, although in different ways.
If you're in an Enterprise Data Center, your advantage is control. Your Data Center is yours and serves only your company, so you have full visibility of your infrastructure and can build on it with your own criteria.
If you're in a CoLo Data Center, your advantage is proximity. You rent space, power and connectivity to other companies, and you know firsthand the infrastructure where their data lives. That proximity, well managed and documented, can become a product argument that sets you apart from any cloud.
In both cases, governance will end up being the argument that gives the Data Center the role it deserves.
Final thoughts
No one has all the answers yet. What is clear is that the Data Center already has a good part of what data governance demands. What it lacks is a seat at the table where decisions are made.
We already take for granted that the Data Center works. Now it's time for people to understand why it exists.