The challenge
The Personal Data Protection Law (PDPL) and its SDAIA regulations require personal data to be protected, restrict transfers outside the Kingdom and mandate breach notification. The NCA Data Cybersecurity Controls (DCC) and National Data Management Office (NDMO) policies require data to be classified and protected according to its level.
You cannot protect what you cannot locate. Personal data, contracts and designs are spread across file shares, email, collaboration platforms and personal devices, and usually leave by the simplest route: an attachment, a USB stick or an upload to a public cloud service.
We build an integrated data security programme: discovery and classification, then loss prevention, encryption and rights management policies, with reporting that shows management and the data protection officer the real picture.
How we work
- 1
Discover and classify
We set a classification policy aligned with NDMO and PDPL, and run discovery across file shares, email, cloud and databases to map sensitive data.
- 2
Protect in phases
We enable labelling, then DLP policies in monitor mode, then gradual blocking, with encryption and rights management for the most sensitive categories.
- 3
Operate and report
We tune policies to reduce false positives, connect incidents to the SOC, and issue periodic reports to the data protection officer and management.
What is included
Data discovery and classification (DC)
Scanning of data at rest and in motion, with automatic and manual labelling by national classification levels and PDPL requirements.
Data loss prevention (DLP)
Endpoint, email, web and cloud policies to detect and block classified data leaving, with an exception workflow.
Encryption and key management
Disk, database, file and email encryption with centralised in-Kingdom key management.
Digital rights management (DRM)
Protection that travels with the file: who opens it, prints it or forwards it, with the ability to revoke access.
Mobile security (MDM, MTD)
Mobile device management and mobile threat defence, separating work data from personal data on staff devices.
Watermarking and tracking
Dynamic watermarks on documents and screens to deter capture and trace the source of any leak.
Database security
Database activity monitoring, data masking in test environments and control of administrator access.
PDPL alignment
Linking technical controls to records of processing, impact assessments and cross-border transfer requirements, in coordination with our GRC services.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- PDPL
- NCA DCC
- NCA ECC
- SAMA CSF
- ISO 27001
Frequently asked questions
Must all data be classified before DLP is enabled?
No. We start with the highest-risk categories, such as personal and financial data, and expand gradually. DLP policies can rely on content patterns as well as labels.
Do the solutions work with Microsoft 365 and Google Workspace?
Yes. We use the capabilities built into those platforms and complement them with specialist tools where needed, depending on your licensing.
How do you handle staff resistance to the controls?
Gradually and with communication: monitor first, then explanatory user prompts, then blocking, integrated with the awareness programme.
Are encryption keys stored outside the Kingdom?
We design key management to stay in-Kingdom or under your control, meeting PDPL and sector regulator requirements.
Which Saudi regulations does data security help with?
PDPL requires adequate technical and organisational measures to protect personal data in storage and in transit. For government entities and organisations that own, operate or host critical national infrastructure, the NCA Data Cybersecurity Controls (DCC-1:2022) extend the ECC with requirements across the data lifecycle that vary by classification level: Public, Restricted, Secret and Top Secret. We map classification, DLP and encryption controls to whichever of these apply to you, alongside SAMA CSF for SAMA-regulated organisations.
What affects the effort of a data security programme?
The number of users and endpoints, how many data repositories and channels (endpoint, email, web, cloud) are in scope, and how many classification levels and policies you need. Your existing licences matter too, because built-in platform capabilities can reduce the need for additional tools. The number of departments onboarded and how far you move from monitoring to blocking also shape the effort.
How is this different from identity and access management?
Identity and access management, a separate DataSec service, controls who can reach a system and with what rights. Data security protects the information itself once someone has access: labels tell users and tools how sensitive it is, DLP stops it leaving through unapproved channels, and encryption and rights management keep it protected wherever the file goes. The two complement each other and are usually planned together.
Related services
Solutions & infrastructure
Identity & access
Unified identity, managed privileged access and MFA with a zero-trust approach.
Govern & comply
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Govern & comply
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Assess & test
Cloud security assessment
Review of cloud configuration, identity and data against recommended practice.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

