TERMS OF REFERENCE OF THE INFORMATION AND DATA GOVERNANCE
COMMITTEE
Version 1.0
1. MEMBERSHIP
The permanent members of the committee are listed below:
I. Chief Information Officer (Chairperson)
II. Data Governance Officer
III. Director: ITSS
IV. Deputy Registrar
V. Director: MI
VI. Director: Institutional Planning
VII. Chief Risk Officer.
Other stakeholders or chairpersons of sub-committees may be co-opted as required.
2. PREAMBLE
The Information and Data Governance Committee plays a strategic oversight role in Information
Governance and Privacy Protection and in the development and implementation of the relevant
policies.
3. ROLES AND RESPOSIBILITIES
The Committee shall:
1) Set the vision and direction for the future of the institution as it pertains to information and
data governance.
2) Champion and align the Information and Data Governance Strategy to the University strategy.
3) Ensure compliance with the regulatory framework and legislation.
4) Provide oversight in terms of the development and implementation of relevant policies.
5) Report to the Executive Management Committee.
4. SECRETARY
The Data Governance Officer or duly appointed representative is the Secretary to the Committee.
5. MEETINGS
(1) The Secretary to the committee must issue a written notice to each member of the
committee
at least seven days before each ordinary meeting of the committee setting out the place,
date and time of the meeting, and the agenda for the meeting.
(2) At each meeting the committee must:
(a) confirm the minutes of the last ordinary meeting, and the minutes of any special meeting
held since then, with or without amendments, the minutes to be taken as read if copies
have
been sent to members prior to the meeting; and
(b) deal with the business of which notice has been given and any other urgent matter agreed
to.
(3) A quorum for the Information and Data Governance Committee is considered when, at a
minimum of 50%+ of its permanent members is present.
6. FREQUENCY OF MEETINGS
Quarterly Meetings will be scheduled at least one month in advance.
7. CO-OPTION OF MEMBERS
A committee may co-opt experts onto the committee to advise the committee on the matters
before it.
8. SUB-COMMITTEES
Sub-committees will be established or eliminated based on projects and requirements.
Membership shall be determined by the projects and requirements.
RELATED DOCUMENTS AND POLICIES
• DUT Data Governance Charter
• POPIA Industry Code of Conduct: Public Universities
• King IV
• Information Governance Policy: Sets out the principles of good information governance.
Requires institutional information to be classified as confidential, personal, private or public.
• Protection of Personal Information (Privacy) Policy: Ensures compliance with all information and
data protection regulations (i.e. POPIA, EU GDPR) and the public universities' POPIA Code of
Conduct. Also Sets out privacy protection principles and ensures that privacy impacts are
assessed proactively.
• Security Management Policy: Protects confidential and personal information against breaches of
confidentiality, failures of integrity and interruptions to availability. Sets out information security
principles and ensures that information security impacts are assessed proactively. Ensures that
confidential and personal information is not shared with third parties without the appropriate
contracts. Assigns responsibility for managing information incidents.
• Records Management Policy: Ensures the efficient and systematic control of the creation,
receipt, maintenance, use and disposition of records, including processes for capturing and
maintaining the evidence of and information about DUT’s activities.
• Post-School Education and Training Information Policy (PSETIP): It is intended to ensure that all
organisation in the PSET system adhere to agreed-upon standards, procedures and guidelines
for the generation, collection, collation, integration, processing, coordination, dissemination and
quality assurance of data.