Know which columns are personal, restrict who can read them, and be able to delete one person from a lake that was designed to be immutable.
Knowing which drawers hold personal files, keeping them locked, and being able to pull one person's file out of a filing system designed never to remove anything.
Erasure in an append-only lake is genuinely hard, and 'we could probably do it' is not an answer an audit accepts.
Governance is three practical capabilities, not a policy document. Classification: you know which columns contain personal data, and the knowledge lives in metadata rather than in someone's head. Access control: who can read those columns is enforced by the platform — column masking, row-level policies, separate schemas — rather than by convention. And erasure: when a person exercises their right to deletion, you can actually find and remove their data, which is genuinely hard in an append-only lake full of Parquet files that were designed never to change.
Governance means classifying PII columns in metadata, enforcing access with column masking and row-level policies rather than convention, and being able to delete an individual on request. Erasure is the hard one in an immutable lake: the workable patterns are lakehouse-format deletes, or crypto-shredding — encrypt per subject and destroy the key.
How to Anonymization and Data Masking for PostgreSQL in Ubuntu 22.04 LTS Server — The Lazy SysAdmin, 8:02