PDPL is fully enforced. Know where personal data lives.
The Personal Data Protection Law has been in full force since September 2024, and SDAIA is actively supervising compliance. The first question every Data Management Office must be able to answer: where does personal data live, who owns it, and where does it flow? Goava gives you a living, classified inventory of personal data across databases, dashboards, pipelines — and the APIs that expose it.
Discover & classify
Find personal data everywhere it hides
You cannot protect data you cannot find. Goava connects to roughly 80 sources and builds a unified, searchable catalog of tables, dashboards, pipelines, topics, and APIs — then lets you classify personal data once and let inheritance do the rest.
- Connect ~80 native sources — Snowflake, Oracle, SQL Server, PostgreSQL, MongoDB, Power BI, and more — into one searchable catalog.
- Apply PII classifications and tags that inherit automatically from databases to schemas, tables, and columns.
- Assign ownership and stewardship so every personal-data asset has an accountable owner.
- Organize personal data with domains and a business glossary aligned with your PDPL records of processing.
The API blind spot
Which public endpoints expose personal data?
Most governance programs stop at databases and dashboards — but personal data also leaves your organization through APIs. Goava discovers your API estate from the gateways you already run and connects every endpoint to the data behind it.
- Automatic API discovery from Kong, AWS API Gateway, Azure API Management, Google Cloud API Gateway, and Nginx.
- Automatic endpoint detection from OpenAPI specs, with API-to-data lineage showing which tables power which endpoints.
- PII tag inheritance between data and APIs — classify the table, and the endpoints serving it are flagged automatically.
- API Exposure dashboard with risk scoring that highlights public APIs exposing personal or financial data.
Evidence for the regulator
Show your work — coverage, ownership, and lineage
When the questions come, assertions are not enough. Goava turns day-to-day governance into reviewable evidence: who owns each personal-data asset, how it is classified, and exactly where it flows.
- KPI dashboards for classification coverage, ownership coverage, and description coverage across your estate.
- End-to-end, column-level lineage of personal data flows — from source systems to dashboards and APIs.
- Data quality profiling, tests, and SLAs, with incident management when personal data goes stale or breaks.
- Audit-friendly foundations: RBAC, SSO (OIDC / SAML 2.0 / LDAP), and activity feeds on every change.
Four capabilities at the core of PDPL readiness
From discovery to evidence — one platform, natively bilingual, deployed on-premises or in cloud inside Saudi Arabia.
PII classification
Classifications and tags with inheritance: classify once at the database or schema level and propagate to every table and column beneath it.
Lineage of personal data
End-to-end, column-level lineage with a visual editor and ML-based suggestions — see every hop personal data takes through your systems.
API exposure
An API Exposure dashboard with risk scoring that surfaces public endpoints exposing personal or financial data.
Coverage KPIs
Adoption dashboards tracking ownership, description, and classification coverage — measure progress, not intentions.
PDPL readiness — common questions
Does Goava itself store personal data?
Goava manages metadata, not the data itself: asset names, schemas, classifications, ownership, lineage, and quality metrics. It does not copy your customers' records into the platform. It also deploys self-hosted on-premises or in cloud inside Saudi Arabia, so even your metadata remains under your control.
How does PII classification propagate across assets?
Through tag inheritance. Classify a database or schema as containing personal data and the classification flows down to its tables and columns. Tags also inherit between data and APIs: when a table is classified as PII, the endpoints it powers carry that classification too — which is what lets the API Exposure dashboard score the risk of each public endpoint.
Can Goava evidence our PDPL compliance?
Goava is not a certification, and no tool alone makes you compliant. What it does is make compliance demonstrable: coverage KPIs show how much of your estate is classified and owned, lineage shows exactly where personal data flows, and RBAC, SSO, and activity feeds keep the record audit-friendly. Your Data Management Office sets the policy; Goava supports the evidence.
See your personal-data landscape in one place
Book a demo and watch Goava map personal data across your databases, dashboards, pipelines, and APIs — in Arabic and English.