Skip to content

Home Expertise / Data protection

DAT / DAT-01

Sensitive-data discovery and classification

Identify information requiring protection, where it resides, who owns it and how sensitive it is. Classification provides a practical basis for access, sharing, retention and protection decisions.

WHEN IT HELPS

A focused response
to a defined need.

Data scattered across servers, SaaS and endpoints; a DLP or AI project blocked by poor visibility; business teams unable to distinguish public, internal and confidential documents.

AT A GLANCE

Family
Data protection

Engagement
Implementation and advisory

Reference
DAT-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Business workshops
  • repository inventory
  • authorised sampling or automated discovery
  • simple categories
  • ownership
  • labelling rules
  • controls using test data

Deliverables

  • Repository map
  • classification model
  • sensitive-data dictionary
  • labelling rules
  • gap register
  • rollout plan and responsibilities

Acceptance evidence

Categories are understood and approved by business teams; samples are correctly classified; false positives are reviewed; excluded repositories and missing owners are identified.

DELIVERY

How the work is structured.

Approach

Identify data and owners; define policies; pilot on sensitive scope; measure errors; roll out and organise exceptions.

Prerequisites & responsibilities

Customer: business data owners, DPO/legal/HR as relevant, administrators and retention rules. Provider: technical design and verification within agreed permissions.

Scope factors

Repositories, volumes, categories, channels, populations, formats and permission quality. DLP/classification licensing and event handling are separate from deployment.

Questions to clarify

Which data would cause harm if leaked? Who decides access? Where are copies, exports and archives?

IMPORTANT BOUNDARIES

Discovery can expose personal or confidential data. Minimum access, result storage and retention must be scoped; automated classification still requires validation.

Minimisation, proportionality and investigation confidentiality must be scoped. No guarantee of zero leakage or comprehensive legal opinion.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

An engineering firm prepares for DLP. Project: distinguish public plans, customer files and design secrets. Target outcome: protection rules based on actual use rather than a generic keyword list.

Scenario 02

A company wants an AI assistant to access its documents. Project: map repositories and appoint owners. Target outcome: a defined eligible corpus; archives without reliable permissions remain excluded until cleaned up.

Technology and reference context

Examples: Microsoft Purview discovery and labelling capabilities or tools suited to selected repositories; confirm compatibility and licenses.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.