{
  "id": "data-classification-to-dlp-protocol",
  "name": "Data Classification to DLP Protocol",
  "type": "skill",
  "provider": "generic",
  "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"],
  "summary": "Defines the end-to-end data protection flow from sensitive data discovery through Microsoft Purview sensitivity label taxonomy design, DLP policy coverage mapping, auto-labeling opportunity assessment, Power Platform and Dataverse DLP alignment, and label adoption monitoring. Enforces taxonomy completeness and DLP coverage gates before any policy recommendation proceeds to the Purview compliance administrator. Never creates or modifies labels or policies; all production-impacting changes require human sign-off from the Purview admin and data owner.",
  "source_type": "original",
  "official_docs": [
    "https://learn.microsoft.com/purview/sensitivity-labels",
    "https://learn.microsoft.com/purview/dlp-learn-about-dlp",
    "https://learn.microsoft.com/training/paths/purview-implement-information-protection-data-loss-prevention/",
    "https://learn.microsoft.com/power-bi/guidance/powerbi-implementation-planning-info-protection-data-loss-prevention-overview"
  ],
  "security_notes": "Protocol is recommendation and orchestration only — never an authorization to create, modify, or delete sensitivity labels, DLP policies, or auto-labeling policies. All production-impacting policy changes require explicit approval from the Purview compliance administrator and the data owner. Encryption settings on sensitivity labels covering regulated data must not be removed without legal and compliance owner review. Never requests credentials, tenant IDs, session tokens, or customer personal data to perform the classification assessment; works from sanitized taxonomy and policy summary signals only. Special-category personal data (health, biometric, genetic) triggers a jurisdiction and privacy owner confirmation gate. Deliberate under-classification of regulated personal data to evade regulatory obligations is a hard refusal trigger. Planned escalation target: purview-information-protection-specialist-agent (not yet built); current escalation routes to m365-maestro-agent.",
  "last_verified": "2026-06-16",
  "path": "skills/cross-functional/data-classification-to-dlp-protocol",
  "author": "github: VincentChuWaiChow",
  "version": "0.1.0"
}
