DAT / DAT-01
Sensitive-data discovery and classification
Identify information requiring protection, where it resides, who owns it and how sensitive it is. Classification provides a practical basis for access, sharing, retention and protection decisions.

WHEN IT HELPS
A focused response
to a defined need.
Data scattered across servers, SaaS and endpoints; a DLP or AI project blocked by poor visibility; business teams unable to distinguish public, internal and confidential documents.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Business workshops
- repository inventory
- authorised sampling or automated discovery
- simple categories
- ownership
- labelling rules
- controls using test data
Deliverables
- Repository map
- classification model
- sensitive-data dictionary
- labelling rules
- gap register
- rollout plan and responsibilities
Acceptance evidence
Categories are understood and approved by business teams; samples are correctly classified; false positives are reviewed; excluded repositories and missing owners are identified.
DELIVERY
How the work is structured.
Approach
Identify data and owners; define policies; pilot on sensitive scope; measure errors; roll out and organise exceptions.
Prerequisites & responsibilities
Customer: business data owners, DPO/legal/HR as relevant, administrators and retention rules. Provider: technical design and verification within agreed permissions.
Scope factors
Repositories, volumes, categories, channels, populations, formats and permission quality. DLP/classification licensing and event handling are separate from deployment.
Questions to clarify
Which data would cause harm if leaked? Who decides access? Where are copies, exports and archives?
IMPORTANT BOUNDARIES
Discovery can expose personal or confidential data. Minimum access, result storage and retention must be scoped; automated classification still requires validation.
Minimisation, proportionality and investigation confidentiality must be scoped. No guarantee of zero leakage or comprehensive legal opinion.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
An engineering firm prepares for DLP. Project: distinguish public plans, customer files and design secrets. Target outcome: protection rules based on actual use rather than a generic keyword list.
Scenario 02
A company wants an AI assistant to access its documents. Project: map repositories and appoint owners. Target outcome: a defined eligible corpus; archives without reliable permissions remain excluded until cleaned up.
Technology and reference context
Examples: Microsoft Purview discovery and labelling capabilities or tools suited to selected repositories; confirm compatibility and licenses.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
