LabHub

Blog

Data Governance, Lineage and PII Complete Guide: OpenLineage, Collibra, Atlan, DataHub, Unity, Polaris, GDPR, Korean PIPA (2025)

한국어English日本語中文

Season 5 Ep 7 — Through Ep 1–6, data kept growing and getting more complex. Ep 7 is the opposite axis — "how do we govern it". If you do not manage your data, your data will rule your company.

Prologue — "How many places in our company hold a customer email?"

The hardest questions for a CTO to answer in 2025:

If the answer to all four is "I do not know", that company carries regulatory risk and product quality risk at the same time. This post lays out the tools and processes that make those four questions answerable.


Chapter 1 · Defining Data Governance

1.1 The Four Axes of Governance

1.2 Why It Matters Now

1.3 The Governance Spectrum


Chapter 2 · OpenLineage — The Standard for Lineage

2.1 Identity

2.2 Structure

2.3 Integrations

2.4 Example Event

{
  "eventType": "COMPLETE",
  "job": {"name": "dbt.fact_orders"},
  "run": {"runId": "..."},
  "inputs": [{"name": "raw.orders"}, {"name": "raw.customers"}],
  "outputs": [{"name": "analytics.fact_orders"}]
}

2.5 Value


Chapter 3 · The Four Major Data Catalogs

3.1 Collibra

3.2 Atlan

3.3 DataHub

3.4 Alation

3.5 Others

3.6 Comparison

ToolStrengthCustomersModel
CollibraRegulation, enterpriseFinance, public sectorSaaS/self
AtlanModern stack, UXSaaS, startups, mid-sizeSaaS
DataHubOpen, flexibleEngineering teamsOSS + Acryl
AlationCollaboration, business usersMid-size, enterpriseSaaS
OpenMetadataOpen, lightweightSelf-hostedOSS

Chapter 4 · Technical Catalogs — Unity/Polaris/Glue

4.1 Unity Catalog

4.2 Polaris

4.3 AWS Glue Data Catalog

4.4 Nessie / Gravitino

4.5 Business vs Technical Catalog


Chapter 5 · PII — Definition and Detection

5.1 Defining PII

5.2 Automatic Detection Tools

5.3 Detection Methods

5.4 Classification Grades


Chapter 6 · Protecting PII — Masking, Tokenization, Encryption

6.1 Masking

6.2 Tokenization

6.3 Hashing and Anonymization

6.4 Encryption

6.5 Dynamic Masking Example (Snowflake)

CREATE MASKING POLICY mask_email AS (val STRING)
RETURNS STRING ->
  CASE WHEN CURRENT_ROLE() IN ('ADMIN') THEN val
       ELSE REGEXP_REPLACE(val, '.+@', '***@')
  END;

ALTER TABLE customers MODIFY COLUMN email
  SET MASKING POLICY mask_email;

Chapter 7 · Regulation — GDPR, Korean PIPA, AI Act

7.1 GDPR (EU, 2018–)

7.2 The Korean Personal Information Protection Act (PIPA)

7.3 The Korean AI Framework Act (2024–)

7.4 Other Regulations

7.5 Common Principles


Chapter 8 · Data Subject Request (DSR)

8.1 Request Types

8.2 Implementation Difficulty

8.3 Practical Patterns

8.4 AI and Training Data


Chapter 9 · Extending Governance into the AI Era

9.1 Model Catalog

9.2 Prompt and Agent Catalog

9.3 Tracking the Provenance of Training Data

9.4 Auditing AI Output


Chapter 10 · Practical Architecture — Governance Integration

10.1 Layers

10.2 Policy Example

10.3 Auditing

10.4 Automation


Chapter 11 · The Reality of Governance at Korean Companies

11.1 Current State

11.2 Regulatory Response

11.3 Challenges

11.4 Reference Cases


Chapter 12 · Eight Failure Stories

12.1 PII Exposed on a BI Dashboard

Real names shown without dynamic masking, flagged in an audit.

12.2 Incident Response Without Lineage

Spent half a day hunting for "why this metric is wrong".

12.3 A Deletion Request That Took a Month

Manual work, and simultaneous deletion across several systems failed.

12.4 Thousands of Tables With No Known Owner

Nobody knows who to ask.

12.5 A Catalog That Exists but Is Empty

Built once and never maintained, so it drifted away from reality.

12.6 Fragmented Access Permissions

RBAC configured separately in ten databases, central management failed.

12.7 Contractors With Access to All PII

An audit violation.

12.8 Unknown Provenance for AI Training Data

Helpless in a copyright dispute or a regulatory investigation.


Chapter 13 · Ten Anti-patterns

13.1 "Governance Later"

The larger you grow, the harder it is to tear up and redo. Lay the foundations from the start.

13.2 A Catalog With No Owners

There is documentation, but no accountability.

13.3 A Few Lines of Regex for PII Detection

You need ML classifiers and sampling alongside it.

13.4 Indifference to Regulation for Backups

The "the destruction deadline passed but it is still in the backup" incident.

13.5 Lineage as a Hand-written Document

Adopt automatic collection (OpenLineage).

13.6 Changing Upstream Freely Without a Data Contract

Every consumer breaks.

13.7 No Control Over External Sharing

Public S3 buckets, email attachments.

13.8 Short Retention for Audit Logs

Fails to meet regulatory requirements.

13.9 Running Several Catalog Tools in Parallel

Duplicated management with no consolidation.

13.10 Leaving AI and ML Outside Governance

In 2025 this is the biggest risk of all.


Chapter 14 · Checklist — Twelve Points for Data Governance


Chapter 15 · Next Up — Season 5 Ep 8: "Observability 2025 (Logs, Metrics, Traces + LLM)"

If governance is "how do we manage data", observability is "how are the systems and the data actually running".

"No observability, no operations" — the default of infrastructure in 2025.

See you in the next post.


Summary: Data governance in 2025 rests on four axes — catalog, lineage, quality, and PII and regulation. OpenLineage has become the standard for lineage, Collibra, Atlan, DataHub and Alation are the four catalog options, and Unity, Polaris and Glue handle the technical catalog. PII is managed in five stages of detection, classification, masking, tokenization and encryption, while GDPR, the Korean PIPA and the AI Act form the regulatory triangle. Governance in the AI era now extends to models, prompts and training data, and data subject requests (DSR) demand an automated workflow. For Korean companies, network separation, Korean-language metadata and legacy integration are the challenges, and securing dedicated governance staff is the next competitive edge. "If you do not manage it, it manages you" — the 2025 law of data governance.

Comments

No comments yet.

Sign in to leave a comment