Where the data is, who accesses it, how it moves
Classification, sensitive-data discovery and masking, access audit and cross-border compliance
PIPL, the Data Security Law and GDPR come down to three questions: where the data is, who can access it, how it moves. We classify data against national standards and DSMM, discover sensitive data and design masking and encryption, enforce least privilege and access audit, and assess cross-border transfer compliance.
Our approach
One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.
Classification rests on automated discovery
Manually reported inventories are incomplete. Discovery tools scan databases, files and logs; owners confirm the results into a classification register.
Controls are set per level
Each level carries its own encryption, masking, access and audit requirements. Applying the strictest controls to all data costs more and meets more resistance than necessary.
Assessment produces actionable remediation
Every gap maps to a specific technical or process measure with an owner; clause-by-clause comparison is only the starting point.
Deliverables
Classification register
Classification standard, sensitive-data inventory, owners and protection requirements.
Data security policy and configuration
Masking, encryption, least privilege and access audit rules with platform configuration.
Compliance assessment report
PIPL / Data Security Law / GDPR gaps, cross-border assessment and remediation plan.
How we deliver
Four stages, each with defined inputs, outputs and a client sign-off.
Discovery
Sensitive-data scanning, data flow mapping, existing controls.
Classification and policy
Register, protection policy, compliance gap assessment.
Policy rollout
Masking and encryption live, privilege reduction, audit integration.
Reassessment
Policy effectiveness check and compliance reassessment.
Frequently asked questions
Notes on scope, execution and delivery standards. Contact us for anything not covered here.
The Data Security Law and GB/T 43697 (Rules for Data Classification and Grading), combined with sector rules (finance, industry, healthcare) and the DSMM maturity model. The standard is refined for the client's sector.
Start from where you stand
Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.