Compliance And Legal Are Not Just Control Functions. They Are Data Providers.
18 March 2026 · Loïc Ribet · 3 min
To be honest, everything is already in the title.
Last week, I found an old issue of The Economist (from 2017) at home whose cover read: “The world’s most valuable resource is no longer oil, but data.” (I found a link to it). I have kept that magazine for nine years. I remember buying it, meaning to read it properly, then putting it aside. I saw it lying around from time to time, but until last week, I had never actually read it.
In 2026, there is nothing particularly new in that article, and it does not directly relate to the one you are reading now. Yet re-reading it made me reflect again on Compliance and Legal data as an asset.
And then something struck me. Much of the data generated within Legal and Compliance department usually remains inaccessible to the rest of their organisation. In truth, this is not unique to those two departments; most functions operate in their bubble. But Legal and Compliance are particularly interesting because they generate strategic and important data.
I believe that every department, including Legal and Compliance, should see itself as a provider of data. And I believe the guiding principle should be open by default, closed by exception.
This idea is inspired by the open data movement, where governments progressively shifted from hoarding public information to publishing it proactively, unless there was a legitimate reason not to.
The same logic should apply internally. This does not mean that all Legal and Compliance data should be visible to everyone without restriction as some of the data may be confidential. But it does mean that data should not be closed simply out of habit, territorial reflex, or lack of structure.
In practice, I see three levels:
- Open data: accessible to everyone within the company.
- Restricted-access data: accessible upon authorised request and governed approval.
- Closed data: accessible only within Legal and Compliance due to legitimate confidentiality constraints.
At the moment, in many organisations, almost everything falls into the third category. The goal is to shift to Open and Restricted-access data as much as possible and to keep data closed only when necessary.
The objective is not to predict how other departments might use the data. That is impossible. The objective is only to ensure that data is accurate, structured, documented, and accessible under governance. Once that discipline exists, the organisation as a whole becomes more intelligent.
There is another important benefit to open data by default: it forces you to improve the quality of your own data. In most organisations, once data is integrated into a central data lake or data warehouse, it must comply with enterprise data governance standards: defined schemas, consistent formats, unique identifiers, documented metadata (i.e., data dictionary), and clear data ownership.
The main difficulty is cultural: Legal and Compliance departments must stop seeing themselves solely as advisory and control functions and start recognising that they curate a strategic corporate asset on behalf of the organisation.
To conclude, reflect on the data you produce and manage each day: is it open, restricted, or simply locked within your department? Challenge the default position. Not all data needs to remain closed.
The real question is not whether others currently ask for it, but whether there is a legitimate reason to withhold it. If there is not, then you should begin thinking about how to share it within your organisation.