Perspectives · Data Governance

Data governance is becoming an investment issue

September 21, 2026 · Diana Andrade, LL.M., CIPP/E, CIPM

For many years, data protection has largely been treated as a compliance matter.

Companies asked whether they complied with applicable privacy laws, whether the necessary policies and agreements were in place, and whether regulatory exposure had been appropriately managed.

Investors, meanwhile, tended to encounter privacy primarily during due diligence, often as one item among a much broader list of legal and regulatory risks.

That distinction is becoming increasingly difficult to maintain.

For companies whose value depends materially on data—particularly in healthcare, life sciences, digital health and artificial intelligence—the question is no longer simply whether the company is compliant.

It is whether the company actually has the right to use the data on which its business model, technology and future growth depend.

From compliance risk to asset quality

Consider a biotechnology company building a valuable longitudinal dataset, a digital health business training algorithms using patient information, or a healthcare technology company planning to commercialise insights derived from large volumes of health data.

Two companies may appear to hold similarly valuable datasets, but those datasets are not necessarily equally valuable.

One company may have clear provenance, appropriate permissions and legal bases, documented data flows, robust contractual rights and governance structures that support future uses of the data.

The other may possess the same volume of information while facing restrictions on secondary use, uncertain rights obtained from partners, incomplete documentation or limitations affecting international transfers and commercialisation.

From an investment perspective, these are fundamentally different assets. The value is therefore not simply in the data itself, but in the company’s ability to legitimately access, use, combine, transfer and commercialise that data over time.

Investors are beginning to notice

This distinction is increasingly appearing in investment and transaction discussions.

For an investor evaluating a data-intensive healthcare or life-sciences company, weaknesses in data governance can affect much more than regulatory exposure. They can affect the scalability of the business model.

They can restrict entry into new markets, undermine assumptions about the development of an AI product, or complicate partnerships with hospitals, research institutions and pharmaceutical companies.

And, in some circumstances, they can call into question whether an asset presented as one of the company’s principal sources of value can actually be used in the way contemplated by the investment thesis.

This changes the role of privacy due diligence.

The relevant question is no longer only:

“Does this company comply with data protection law?”

It increasingly becomes:

“Can this company do what it says it intends to do with its data?”

That is a very different investment question.

Healthcare makes the issue particularly important

The distinction is especially relevant in healthcare and life sciences because some of the sector’s most valuable data is also among its most heavily regulated.

Clinical trial data, genomic information, electronic health records, real-world data and other health datasets can support research, product development, regulatory strategy and increasingly artificial intelligence.

But access to data does not automatically create unrestricted rights over it.

How information was originally collected, the legal basis relied upon, the information provided to individuals, contractual arrangements between the parties, restrictions on secondary use, international transfer requirements and the regulatory environment in each relevant jurisdiction can all influence what can subsequently be done with that information.

This becomes particularly significant when a company moves from research to commercialisation, enters new jurisdictions, changes its intended use of data or develops applications that were not contemplated when the information was originally obtained.

A weakness that appears relatively technical during an early financing round can therefore become commercially significant at a later stage.

Data governance belongs in the investment thesis

This suggests that sophisticated due diligence of data-intensive businesses should increasingly distinguish between two related questions.

The first is risk: what regulatory, contractual or litigation exposure exists because of the way the company handles data?

The second is value: to what extent can the company’s data assets actually support the growth assumptions on which its valuation depends?

The second question has historically received considerably less attention.

That is beginning to change.

For investors, understanding data governance earlier can identify both downside risk and hidden limitations in a company’s growth strategy.

For founders, the implication is equally important.

Building strong data governance should not be viewed simply as expenditure required to satisfy regulators. Done properly, it protects the usability of one of the company’s most important assets and can make the business easier to diligence, partner with, scale and ultimately transact.

A broader change in how we think about data

Perhaps the most interesting development is that this conversation is beginning to extend beyond privacy specialists.

European data protection authorities are now discussing questions around data valuation, accounting, mergers and acquisitions, and the relationship between data protection and value creation.

That matters because it reflects a broader evolution in the way data governance is understood.

Privacy will remain a regulatory obligation, but for data-intensive companies, particularly in healthcare and life sciences, it is increasingly also part of the infrastructure that determines whether data can generate economic value.

For investors and founders alike, that makes data governance much more than a compliance exercise.

It makes it part of the investment case.

Diana Andrade

LL.M., CIPP/E, CIPM
Co-Founder, ManaraMED
Data Protection Lawyer · Clinical Research & Healthcare Privacy

Back to Perspectives
ManaraMED

A strategic advisory firm focused on healthcare and life sciences in the GCC.

Offices

ManaraMED L.L.C-FZ
Meydan Grandstand, 6th Floor
Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates

ManaraMED LLC
16192 Coastal Hwy
Lewes, DE 19958
United States

Terms of UsePrivacy Notice© 2026 ManaraMED L.L.C-FZ. All rights reserved. Registered in Meydan Free Zone, Dubai, United Arab Emirates.