Skip to main content

Where the data is, who accesses it, how it moves

Classification, sensitive-data discovery and masking, access audit and cross-border compliance

PIPL, the Data Security Law and GDPR come down to three questions: where the data is, who can access it, how it moves. We classify data against national standards and DSMM, discover sensitive data and design masking and encryption, enforce least privilege and access audit, and assess cross-border transfer compliance.

Our approach

One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.

01

Classification rests on automated discovery

Manually reported inventories are incomplete. Discovery tools scan databases, files and logs; owners confirm the results into a classification register.

02

Controls are set per level

Each level carries its own encryption, masking, access and audit requirements. Applying the strictest controls to all data costs more and meets more resistance than necessary.

03

Assessment produces actionable remediation

Every gap maps to a specific technical or process measure with an owner; clause-by-clause comparison is only the starting point.

Deliverables

01

Classification register

Classification standard, sensitive-data inventory, owners and protection requirements.

02

Data security policy and configuration

Masking, encryption, least privilege and access audit rules with platform configuration.

03

Compliance assessment report

PIPL / Data Security Law / GDPR gaps, cross-border assessment and remediation plan.

How we deliver

Four stages, each with defined inputs, outputs and a client sign-off.

01Weeks 1–3

Discovery

Sensitive-data scanning, data flow mapping, existing controls.

02Weeks 4–6

Classification and policy

Register, protection policy, compliance gap assessment.

032–3 months

Policy rollout

Masking and encryption live, privilege reduction, audit integration.

041 month after go-live

Reassessment

Policy effectiveness check and compliance reassessment.

Frequently asked questions

Notes on scope, execution and delivery standards. Contact us for anything not covered here.

The Data Security Law and GB/T 43697 (Rules for Data Classification and Grading), combined with sector rules (finance, industry, healthcare) and the DSMM maturity model. The standard is refined for the client's sector.

Start from where you stand

Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.