Higher education institution
Sensitive data discovery and classification across academic and administrative systems at a Saudi higher education institution, establishing the inventory that PDPL compliance depends on.
- Industry
- Higher education
- Country
- Saudi Arabia
- Modules
- Sensitive data discovery · Data classification · PDPL readiness
Client not named — engagement details available under NDA.
Outcomes
Why this one is not named
Every other case study on this site names its client. This one does not, and that is the point rather than an omission. In public sector and institutional security work the existence of an engagement can itself be the sensitive fact — knowing that an organisation has recently gone looking for its own unprotected data is useful to the wrong reader.
So: sector and scope, no name. Detail beyond what appears here is available under NDA.
The situation
Institutions of this kind accumulate systems the way they accumulate buildings — by faculty, by decade, by whoever had budget at the time. Personal data ends up spread across academic and administrative systems that were never inventoried together, and often were never inventoried at all.
PDPL attaches obligations to personal data wherever it sits, including the database a department stood up years ago and never registered. Those obligations cannot be met against an unknown estate.
What we built
Discovery and classification across academic and administrative systems, producing an inventory of where personal data actually lives. Classification then attaches controls to record classes rather than to individual servers, so protection follows the data instead of the hardware it happened to land on.
That inventory is the precondition for everything that comes after it — monitoring, access governance, retention. You cannot protect data you have not found.
Let's talk about the work.
Tell us the entities, the modules and the deadline. We will tell you honestly whether we are the right team for it.