Data Management Office (DMO)
Governance Glossary & Taxonomy
NDMO Standards & PDPL Mandates
Data Governance & PDPL Glossary
This comprehensive taxonomy outlines official definitions and governance terms adopted by Princess Nourah bint Abdulrahman University in alignment with regulatory standards set forth by the National Data Management Office (NDMO) and the Personal Data Protection Law (PDPL).
Foundational Concepts & Technical Access
6 Terms
Data
Core Concept
A collection of raw, unorganized facts, such as numbers, text, still images, video, audio recordings, or emojis.
Data Access
System Access
The ability to logically and physically access organizational data assets and technological resources for operational utilization.
Data Access Level
Entitlements
A permission-based tier restricting access to data and technical resources strictly to authorized personnel commensurate with assigned institutional duties.
Authentication
Identity Verification
The verification of the identity of any user, process, or device as an essential security prerequisite to granting technological resource access.
Authorization
Access Control
The formal specification and allocation of access rights and privileges to data assets for any user, application, or process.
Data Confidentiality
Cybersecurity
Preserving authorized restrictions on data access and disclosure, preventing improper dissemination to unauthorized parties.
Data Classification & Sensitivity Tiers
3 Terms
Data Classification Levels
4 Tiers
The statutory classification tiers recognized in Saudi Arabia: "Top Secret", "Secret", "Restricted", and "Public".
Protected Data
Non-Public
Any data assets classified as Top Secret, Secret, or Restricted under institutional classification policies, subject to heightened safeguards.
Sensitive Data
High Impact
Data whose unauthorized access, alteration, loss, or misuse inflicts severe harm upon national interests, institutional continuity, or individual rights.
Public Information & Open Data Assets
2 Terms
Public Information
General Access
Processed, non-protected records received, produced, or managed by public authorities, subject to Freedom of Information provisions.
Open Data
Machine-Readable
A specific subset of public information published freely, in machine-readable formats, reusable without restrictive licensing barriers.
Personal Data Protection Framework (PDPL)
4 Statutory Concepts
Data Subject
Natural Person
The natural person to whom personal data relates, or their legal representative or lawful guardian.
Personal Data
Identifiable Record
Any data that leads directly or indirectly to identifying an individual when combined with other elements; including names, national IDs, addresses, contact details, bank accounts, or images.
Sensitive Personal Data
Enhanced Protection
Personal data disclosing racial or ethnic origin, religious, philosophical, or political beliefs, civil society memberships, criminal records, biometric traits, genetic information, credit records, health records, or location coordinates.
Personal Data Processing
Lifecycle Operations
Any automated or manual operation performed on personal data; including collection, transfer, recording, storage, sharing, disposal, analytics, pattern extraction, inference, or cross-referencing.