Skip to main content
PDPL Readiness

PDPL is fully enforced. Know where personal data lives.

The Personal Data Protection Law has been in full force since September 2024, and SDAIA is actively supervising compliance. The first question every Data Management Office must be able to answer: where does personal data live, who owns it, and where does it flow? Goava gives you a living, classified inventory of personal data across databases, dashboards, pipelines — and the APIs that expose it.

Discover & classify

Find personal data everywhere it hides

You cannot protect data you cannot find. Goava connects to roughly 80 sources and builds a unified, searchable catalog of tables, dashboards, pipelines, topics, and APIs — then lets you classify personal data once and let inheritance do the rest.

  • Connect ~80 native sources — Snowflake, Oracle, SQL Server, PostgreSQL, MongoDB, Power BI, and more — into one searchable catalog.
  • Apply PII classifications and tags that inherit automatically from databases to schemas, tables, and columns.
  • Assign ownership and stewardship so every personal-data asset has an accountable owner.
  • Organize personal data with domains and a business glossary aligned with your PDPL records of processing.
Explore the data catalog
orders · data-team · PII
customers · analytics · Certified
revenue_daily · finance

The API blind spot

Which public endpoints expose personal data?

Most governance programs stop at databases and dashboards — but personal data also leaves your organization through APIs. Goava discovers your API estate from the gateways you already run and connects every endpoint to the data behind it.

  • Automatic API discovery from Kong, AWS API Gateway, Azure API Management, Google Cloud API Gateway, and Nginx.
  • Automatic endpoint detection from OpenAPI specs, with API-to-data lineage showing which tables power which endpoints.
  • PII tag inheritance between data and APIs — classify the table, and the endpoints serving it are flagged automatically.
  • API Exposure dashboard with risk scoring that highlights public APIs exposing personal or financial data.
Explore API governance
/v1/customers · PUBLIC · PII ⚠
/v1/orders · partner · Financial
/v1/health · public · safe

Evidence for the regulator

Show your work — coverage, ownership, and lineage

When the questions come, assertions are not enough. Goava turns day-to-day governance into reviewable evidence: who owns each personal-data asset, how it is classified, and exactly where it flows.

  • KPI dashboards for classification coverage, ownership coverage, and description coverage across your estate.
  • End-to-end, column-level lineage of personal data flows — from source systems to dashboards and APIs.
  • Data quality profiling, tests, and SLAs, with incident management when personal data goes stale or breaks.
  • Audit-friendly foundations: RBAC, SSO (OIDC / SAML 2.0 / LDAP), and activity feeds on every change.
Explore governance features
null_check · passed · 99.2%
freshness · passed · 14 min
row_count · failed · -12%

Four capabilities at the core of PDPL readiness

From discovery to evidence — one platform, natively bilingual, deployed on-premises or in cloud inside Saudi Arabia.

PII classification

Classifications and tags with inheritance: classify once at the database or schema level and propagate to every table and column beneath it.

Lineage of personal data

End-to-end, column-level lineage with a visual editor and ML-based suggestions — see every hop personal data takes through your systems.

API exposure

An API Exposure dashboard with risk scoring that surfaces public endpoints exposing personal or financial data.

Coverage KPIs

Adoption dashboards tracking ownership, description, and classification coverage — measure progress, not intentions.

PDPL readiness — common questions

Does Goava itself store personal data?

Goava manages metadata, not the data itself: asset names, schemas, classifications, ownership, lineage, and quality metrics. It does not copy your customers' records into the platform. It also deploys self-hosted on-premises or in cloud inside Saudi Arabia, so even your metadata remains under your control.

How does PII classification propagate across assets?

Through tag inheritance. Classify a database or schema as containing personal data and the classification flows down to its tables and columns. Tags also inherit between data and APIs: when a table is classified as PII, the endpoints it powers carry that classification too — which is what lets the API Exposure dashboard score the risk of each public endpoint.

Can Goava evidence our PDPL compliance?

Goava is not a certification, and no tool alone makes you compliant. What it does is make compliance demonstrable: coverage KPIs show how much of your estate is classified and owned, lineage shows exactly where personal data flows, and RBAC, SSO, and activity feeds keep the record audit-friendly. Your Data Management Office sets the policy; Goava supports the evidence.

See your personal-data landscape in one place

Book a demo and watch Goava map personal data across your databases, dashboards, pipelines, and APIs — in Arabic and English.