top of page
WHERE IS YOUR SENSITIVE DATA, WHO CAN REACH IT, AND IS THAT LAWFUL?
The problem

Most organisations cannot answer any of those three questions with confidence — and the third is the one that ends careers.

 

Data discovery projects produce inventories that are stale within a quarter. Classification schemes are defined in policy and ignored in practice. And the question of whether a given data flow is lawful is treated as a legal matter rather than an architectural one, which means it is discovered during an audit rather than designed for.

 

In the GCC this is materially harder than in single-jurisdiction environments. Saudi Arabia's PDPL requires that cross-border transfers meet permitted purposes, do not prejudice national security or the vital interests of the Kingdom, provide an adequate level of protection, and are limited to the minimum data necessary — with detailed mechanics set out in the SDAIA implementing and transfer regulations, the transfer framework having been updated with effect from September 2024. The UAE operates a federal PDPL alongside separate regimes in the DIFC and ADGM, which means a single organisation with a Dubai head office, a DIFC entity and a Riyadh branch is subject to at least four distinct regimes simultaneously.

 

Global DSPM platforms are good at discovery and classification. Very few of them know any of this.

OUR APPROACH

  1. Scope by risk, not by volume. Discovering everything is a project that never finishes. We scope to the data that carries regulatory, contractual or existential consequence.

  2. Design a classification schema people will actually use. Four labels, unambiguous definitions, and a default that fails safe. Schemas with nine levels are ignored.

  3. Map the flows, not just the stores. Where data rests matters less than where it moves, who moves it, and under what authority.

  4. Assess against every applicable regime. UAE PDPL, DIFC, ADGM, KSA PDPL and SDAIA transfer regulations, and the sectoral requirements that overlay them.

  5. Design residency-aware controls. Residency is not a storage location. It is an access-control and key-custody problem. Data physically located in-country and administratively accessible from outside it has not been localised in any meaningful sense.

  6. Define the operating model. Ownership, review cadence, exception handling. Posture management without an owner is a report, not a control.

ENGAGEMENTS

01. Data Security Posture Assessment

Typical duration: 12-20 days

Discovery scoping, classification schema, sensitive data mapping, control gap analysis

02. DSPM Platform Selection & Deployment Architecture

Typical duration: 10-15 days

Requirements, vendor evaluation, deployment topology, integration design

03. Data Sovereignty & Residency Assessment

Typical duration: 10-18 days

Cross-border transfer mapping against all applicable MEA regimes

04. Classification & Labelling Operating Model

Typical duration: 12-18 days

Schema, taxonomy, labelling policy, platform design, adoption plan

FRAMEWORKS APPLIED

UAE PDPL (Federal Decree-Law 45/2021) · DIFC Data Protection Law 2020 · ADGM Data Protection Regulations 2021 · KSA PDPL and SDAIA transfer regulations · NCA ECC-2:2024 · ISO/IEC 27001:2022 · CSA CCM v4.1 · POPIA · Kenya DPA 2019 · NDPR

Note on legal boundaries: PRAECEPTA provides security architecture and data governance design. Binding interpretation of data protection law is a matter for qualified legal counsel, and we will say so plainly where the line falls. We work alongside your counsel, not instead of them.

bottom of page