Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when organisations try to meet GDPR…
Governance, Ownership & Risk

What happens when organisations try to meet GDPR or HIPAA requirements without centralised identity governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Compliance becomes inconsistent across teams, systems, and locations. Access policies are harder to enforce uniformly, reporting takes longer, and evidence for auditors becomes fragmented. In practice, this increases the chance of policy gaps, delayed remediation, and access decisions that do not match the organisation’s legal obligations in each jurisdiction.

Why centralised identity governance changes GDPR and HIPAA compliance

Without a central identity governance layer, GDPR and HIPAA obligations tend to be interpreted and enforced differently by each team, system owner, and regional operation. That creates uneven access approval standards, inconsistent review cycles, and weaker traceability. For regulated organisations, the issue is not only control design, but whether the control can be demonstrated consistently when auditors or regulators ask for evidence.

Centralisation matters because identity governance is where policy becomes repeatable practice: who gets access, who reviews it, when it expires, and how exceptions are recorded. When those decisions are fragmented, compliance becomes a patchwork of local habits rather than a single control model. For privacy and health data, that is especially risky because lawful access, minimum necessary access, and access review expectations depend on being able to prove consistent enforcement.

Identity governance also sits at the boundary between policy and operations, so gaps often appear first as process drift. A role may be granted in one environment but not another, or a revocation may be completed in one system while lingering in a connected application. The IAM and IGA Basics guide is useful here because it distinguishes provisioning, access review, entitlement management, and governance as separate control functions, not one vague admin task.

How fragmented access control shows up in practice

In practice, the absence of central governance produces familiar failure modes: duplicate identities, orphaned accounts, delayed deprovisioning, and inconsistent role definitions. Under GDPR, that can mean access decisions are not aligned to data minimisation or retention expectations. Under HIPAA, it can mean user access is not consistently tied to job function or reviewed often enough to support the security rule.

Fragmentation also slows remediation. If access data lives in many tools, a reviewer may not know whether a user still has access in a downstream app, a legacy platform, or a regional system. The result is delayed correction of excessive access, and an audit trail that is assembled after the fact rather than produced from a control system. The Access Reviews and Certification Guide and the Role Mining and Role Design Guide both address the practical side of this problem, especially where role drift and reviewer fatigue undermine uniform decisions.

Centralisation also reduces ambiguity around evidence. If each team keeps its own spreadsheets, tickets, and local logs, the organisation may technically have controls but not a coherent compliance record. That is why identity governance is often the control plane that makes reporting believable, not just possible.

What regulators and auditors usually care about most

For GDPR, the practical question is whether the organisation can show that access to personal data is purposeful, limited, and reviewable across the full environment. For HIPAA, the question is whether access to protected health information is appropriately assigned, monitored, and revoked. In both cases, evidence quality matters as much as policy language. A scattered control environment usually makes it harder to prove that one policy was applied everywhere.

That is why central governance should be measured by its ability to produce consistent attestation, timely revocation, and a complete view of access history. The EU General Data Protection Regulation (GDPR) and the Healthcare Identity Security Guide are both relevant reference points when you need to connect access control to privacy and health-data obligations rather than treating them as separate compliance workstreams.

Where organisations struggle most is not with writing the rule, but with keeping the rule intact across acquisitions, jurisdictions, contractors, and application sprawl. The more disconnected the estate, the more likely it is that access governance becomes reactive, and the harder it is to show that the same approval and review logic applied to every identity that could reach regulated data.

Risk and Threat Considerations

Fragmented identity governance increases the chance of excessive access, stale access, and undocumented exceptions persisting long enough to become a compliance breach or a security incident. It also raises the probability that an auditor will find a control gap that the business did not know existed because the evidence was never consolidated.

Failure mechanism: Different teams apply different approval rules, review cadences, and revocation practices, so access accumulates faster than it is recertified or removed. That weakens both preventative control and the audit trail needed to prove lawful access.

Impact: The organisation may fail to demonstrate consistent compliance, may retain access longer than policy allows, and may need to perform costly retrospective remediation when regulators or internal assurance teams request evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt.5 — Principles relating to processing of personal dataCentral governance is needed to apply minimisation and purpose limits consistently.
Art.25 — Data protection by design and by defaultCentral identity governance helps embed privacy rules into access design, not local discretion.
Art.32 — Security of processingUniform access governance supports consistent protection of personal data across systems.
Recommendation — Enforce common access rules so personal-data access stays limited and reviewable. Build access governance into default role and entitlement design. Standardise access controls and review evidence across all systems handling personal data.
NIST SP 800-53 Rev 5AC-2 — Account ManagementCentral governance is the mechanism for provisioning, reviewing and removing accounts consistently.
AC-6 — Least PrivilegeFragmented governance often produces excessive access that least privilege should prevent.
AU-6 — Audit Review, Analysis, and ReportingAuditors need a consolidated evidence trail when access decisions are spread across teams.
Recommendation — Centralise account lifecycle controls and recertification. Reduce permissions to the minimum required across all regulated systems. Aggregate access evidence into a single reviewable reporting path.
ISO/IEC 27001:2022A.5.15 — Access controlCentralised governance supports consistent access control policy enforcement.
A.5.16 — Identity managementIdentity governance depends on consistent identity lifecycle and ownership controls.
A.5.18 — Access rightsCentral governance is needed to grant, review and revoke rights consistently.
Recommendation — Apply one access-control policy across all in-scope systems and teams. Assign clear identity ownership and lifecycle controls for every account. Review and revoke access rights through a single governed process.
CIS Controls v8CIS-5 — Account ManagementCentral account management reduces orphaned, stale and inconsistent access.
Recommendation — Centralise account provisioning, review and removal.

Practitioner Guidance

What to prioritise: Start with the identities and applications that can touch regulated data, then standardise their ownership, review cadence, and revocation path before expanding to lower-risk systems. If the same access decision can be made in three different ways, the control is already too fragmented to trust.

What to verify: Confirm that one authoritative view exists for who approved access, when it was last reviewed, and when it was removed. A policy is not mature until you can produce consistent evidence without rebuilding the story from tickets and email.

Common mistake: Treating identity governance as an annual certification exercise only. In regulated environments, the real test is whether access changes, role changes, and offboarding events are controlled continuously enough to keep evidence current.

Practitioner takeaway: centralised identity governance is not just an efficiency choice, it is what turns privacy and health-data obligations into repeatable, auditable access decisions rather than local interpretations.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org