Data Governance

Data Classification &
Governance

You cannot protect data you don't know you have. We discover, classify, and govern your sensitive data across every system โ€” cloud, on-prem, SaaS โ€” and implement the controls that keep it where it belongs.

Discovery ScopeCloud ยท On-prem ยท SaaS
ClassificationAutomated + expert review
DLP PlatformsMicrosoft ยท Symantec ยท Forcepoint
CertificationsCDMP ยท CIPP/E
0Orgs with Unclassified Data
0Data Sources Integrated
0Avg Discovery Timeline

The Problem

Most organisations vastly underestimate the volume and sensitivity of data they hold. Personal data in marketing databases that should have been deleted 3 years ago. Payment card numbers in log files. Health information in unencrypted SharePoint folders. Intellectual property on personal Dropbox accounts. These are not edge cases โ€” they are findings from our last 50 data discovery engagements. You cannot protect what you cannot see.

Our Approach

01

Data Discovery & Scanning

Automated scanning across all connected repositories โ€” SharePoint, OneDrive, Google Drive, S3, databases, file servers, email โ€” identifying where sensitive data actually lives, not where you think it does.

02

Classification Framework Design

We design a classification framework appropriate for your industry, regulatory environment, and risk appetite โ€” typically 3โ€“5 levels from Public to Restricted โ€” with clear labelling rules and handling requirements for each level.

03

Classification Implementation

We implement classification labels in Microsoft Purview, Google Workspace, or other platforms โ€” with auto-classification for known sensitive data types and guided classification for human review of ambiguous content.

04

DLP Policy Implementation

Data Loss Prevention policies configured across email, web, endpoint, and cloud applications โ€” preventing sensitive data from leaving controlled environments. Tuned to minimise false positives without sacrificing protection.

05

Retention Schedule Implementation

We implement data retention schedules โ€” automated deletion of data that has exceeded its retention period, legal hold capabilities for regulatory requirements, and audit trails for compliance demonstration.

What You Receive

๐Ÿ—บ

Data Discovery Report

Complete map of sensitive data locations across all in-scope systems with volume, type, and risk analysis.

๐Ÿ“‹

Classification Framework

Documented classification scheme with handling requirements, labelling standards, and implementation guidelines.

๐Ÿท

Classification Implementation

Labels deployed in your environment with auto-classification rules and user training for manual classification.

๐Ÿ›ก

DLP Policies

Configured DLP policies across your email, endpoint, cloud, and web channels with incident management workflow.

๐Ÿ“…

Retention Schedule

Implemented retention policies with automated deletion, legal hold, and audit trail capabilities.

๐Ÿ“Š

Data Governance Dashboard

Ongoing view of classification coverage, DLP incidents, retention compliance, and data risk posture.

Security Maturity Model

Data governance maturity spans from complete opacity about what data you hold to comprehensive, automated governance that ensures data is used appropriately throughout its lifecycle.

Initial
Managed
Defined
Measured
Optimizing
Level 01InitialCMMI-1

Where you are

No data classification. Data stored wherever convenient. No retention policies. DLP absent. Data inventory non-existent. Sensitive data discovered reactively โ€” after a breach or regulator inquiry.

No classificationNo retentionNo DLP
Level 02ManagedCMMI-2

Where you are

Basic classification scheme defined but not implemented in tools. Manual labelling attempted but inconsistent. Some retention policies documented. DLP in basic email mode only. Data discovery limited to known systems.

Manual labellingBasic email DLPPartial retention
Level 03DefinedCMMI-3

Where you are

Classification implemented in productivity tools (Microsoft/Google). Auto-classification for structured data types. DLP across email and cloud storage. Retention schedule documented and partially automated. Data governance officer appointed.

Tool-based labellingMulti-channel DLPAutomated retention
Level 04MeasuredCMMI-4

Where you are

Comprehensive data discovery across all systems including shadow IT. Classification coverage >80% of data estate. DLP incidents tracked and trended. Retention compliance measured quarterly. Data risk quantified in financial terms.

80%+ coverageDLP trend trackingFinancial quantification
Level 05OptimizingCMMI-5

Where you are

Data governance fully automated. Real-time sensitive data detection and remediation. Classification drives access control decisions automatically. Data minimisation principles embedded in product development. Data governance feeds privacy and compliance programmes seamlessly.

Real-time detectionAuto-remediationGovernance-driven access

ACE MATES assessment โ†’ Not sure where you sit? Our free 90-minute threat briefing includes a maturity assessment across all security domains.

How We've Helped

โ—‰ Case Study โ€” Anonymised
Nordic Healthcare Provider โ€” 8 hospitals, 12,000 staff

An internal audit found that patient records were being stored in personal OneDrive accounts and shared via personal email. The client needed to discover the full extent of the problem and implement controls within 60 days before a scheduled regulatory inspection.

ACE MATES deployed Microsoft Purview across the entire M365 tenant and connected on-premises file servers. Discovery found 2.3 million files containing patient data โ€” 47,000 in unapproved personal storage. We implemented classification labels, DLP policies blocking transfer of patient data to personal accounts, and mandatory retention policies. The regulatory inspection found zero findings on data governance.

0Files Discovered & Classified
0Files Remediated from Uncontrolled Storage
0Regulatory Findings

Transparent Pricing

We publish indicative pricing because you deserve to know the ballpark before a single call.

Data Discovery Assessment
โ‚ฌ8,000 โ€“ โ‚ฌ16,000
One-time ยท 3โ€“5 weeks
  • Automated discovery across in-scope systems
  • Sensitive data type identification
  • Risk-based findings report
  • Classification framework recommendation
  • DLP gap assessment
  • Remediation roadmap
Data Governance Retainer
โ‚ฌ2,500 / month
Ongoing ยท 12-month minimum
  • Continuous discovery & classification
  • DLP incident management
  • Monthly governance report
  • Policy tuning & updates
  • Quarterly data risk review
  • New system onboarding
  • Regulatory change monitoring
All prices excl. VAT. Microsoft Purview or Google Workspace licences required โ€” we advise on the right tier. On-premises scanning requires agent deployment โ€” included in programme pricing. Healthcare and financial services pricing available at specialised rates.

Why ACE MATES

Discovery-First Philosophy

We start by finding your data where it actually is โ€” not where your documentation says it is. Discovery often reveals 3โ€“5x more sensitive data than organisations expect, changing the entire risk picture.

Platform-Agnostic Expertise

We implement governance in Microsoft Purview, Google Workspace DLP, Symantec DLP, Forcepoint, and Varonis. We recommend the right platform for your environment, not the one we are partnered with.

Regulatory Context

Our data governance programmes are designed to satisfy GDPR Article 5 (data minimisation, storage limitation), NIS2 data handling requirements, and industry-specific regulations (HIPAA, PCI DSS) simultaneously.

Business-Friendly Implementation

DLP that blocks too much destroys productivity and gets disabled. We tune policies collaboratively with business units to find controls that protect without creating frustration โ€” and that actually stay enabled.

Frequently Asked Questions

What is data discovery and how does it work?
Data discovery is the automated scanning of your IT environment to find where sensitive data lives. We use classification engines that recognise personal data (names, emails, national IDs), financial data (credit card numbers, bank accounts), health data, and intellectual property โ€” across structured databases, unstructured files, email, and cloud storage.
What is Microsoft Purview and do we need it?
Microsoft Purview (formerly Microsoft Information Protection) is Microsoft's data governance platform. If you are an M365 organisation, you likely already have access to Purview but may not be using it. We configure Purview to its full capability โ€” discovery, classification, DLP, and retention โ€” at a fraction of the cost of third-party alternatives.
How do we handle data that should have been deleted years ago?
This is one of the most common findings. We implement a remediation process โ€” reviewing data before deletion, applying legal holds where required, and then automating deletion of data beyond its retention period. We handle the legal, operational, and technical aspects of data remediation.
Can you discover data in SaaS applications (Salesforce, HubSpot, etc.)?
Yes, via API connectors. We can discover sensitive data in Salesforce, HubSpot, Slack, Jira, Confluence, Zendesk, and other major SaaS platforms. Discovery scope and depth varies by platform โ€” we advise on what is achievable during scoping.
What happens when a DLP policy blocks a legitimate business need?
DLP policies are never perfectly tuned at launch. We implement an override and exception process โ€” business users can request overrides with justification, which are logged and reviewed. We tune policies based on override patterns to reduce false positives over time.

Know What Data You Hold

Start with a free data discovery scoping session. No commitment required.

Start Data Discovery โ†’โœ‰ Email Us