Data Governance Consulting for Egypt and Saudi Arabia

We help government entities and enterprises put data governance to work: clear ownership, policies people follow, measured data quality and a living catalogue, aligned with Saudi Arabia’s NDMO standards and Egypt’s Personal Data Protection Law 151/2020.

A core of blue and green data cubes held inside three crossing glass rings, with outer cubes tethered to the rings.

What Is Data Governance?

Data governance is the set of roles, decisions and rules that determine who owns each kind of data in an organisation, who may use it and how its quality and protection are assured. DAMA, the international data management association, defines it as the exercise of authority and control over the management of data assets. In practice it turns data that each department keeps for itself into an asset the whole organisation can trust.

Sustainable Software Solutions provides data governance consulting and implementation from Cairo, for government entities and enterprises in Egypt, Saudi Arabia and the other Gulf states. The work builds on the data practice of our parent group, Jadara Solutions in Riyadh, and on our founder’s own record: he established and led the data management office of a Saudi government agency, with a three-year data strategy and a governance framework built to NDMO regulations.

Governance comes before analytics and AI, not after them. A dashboard or a model is only as reliable as the data beneath it, which is why we treat governance as the first step of any data programme: trusted AI starts from trusted data.

What it covers

What Our Data Governance Work Covers

Eight parts of a governance programme. We can run the whole programme or strengthen the parts you already have.

Maturity assessment and roadmap

We assess where your data management stands today against the framework that applies to you, and turn the gaps into a roadmap ordered by priority.

Data management office and roles

The data management office, the governance committee and the roles of data owners and stewards, with their decision rights written down.

Policies and standards

Policies for classification, sharing, retention, privacy and quality, written for the people who have to follow them.

Data quality

Quality rules for your critical data, measured for accuracy, consistency and reliability, with each issue routed to the owner who can fix it.

Metadata and data catalogue

A business glossary and a living catalogue, so people can find data, understand what it means and see where it came from.

Data classification

Each data set is given a sensitivity level that decides how it is stored, shared and protected.

Personal data protection

A register of the personal data you hold, where it flows and how long it is kept: the groundwork that consent, breach notification and transfer rules all depend on.

Indicators and evidence

Governance indicators reported to management, and the evidence kept ready for an audit or an assessment.

Rules and frameworks

The Rules We Align Governance With

Four frameworks shape most of our governance work in the two markets. This is a summary of public rules, not legal advice.

Saudi Arabia: the NDMO standards

The National Data Management Office (NDMO), part of the Saudi Data and AI Authority (SDAIA), issued the Data Management and Personal Data Protection Standards. They set out 15 domains, with 77 controls and 191 specifications across 14 of them; data security is left to the National Cybersecurity Authority. They apply to public entities and extend to business partners that handle government data.

Saudi Arabia: the National Data Index

SDAIA measures government entities through the National Data Index (NDI). It scores three things: the maturity of data management on six levels from 0 to 5, compliance with the 191 specifications, and operational excellence.

Saudi Arabia: the Personal Data Protection Law

The Saudi Personal Data Protection Law (Royal Decree M/19) came into force on 14 September 2023 and has been fully enforceable since 14 September 2024, with SDAIA as its regulator.

Egypt: Personal Data Protection Law 151/2020

Egypt’s law covers personal data that is processed electronically. Its Executive Regulations were issued in November 2025 (Decree 816 of 2025), with one year for organisations to comply. It requires explicit consent, a licence or permit from the Personal Data Protection Center (PDPC), a registered data protection officer, notice of a breach within 72 hours and a licence for transfers abroad.

How we deliver

How a Governance Programme Runs

Five steps, each ending in something you can see, test and sign off.

  1. STEP 01

    Discover

    We meet the people who hold the data, review existing policies and systems, and assess maturity against the framework that applies to you.

  2. STEP 02

    Design

    We agree the operating model, the roles, the policies and the roadmap, starting with the data that matters most.

  3. STEP 03

    Build

    We write the policies, define the quality rules and build the glossary and catalogue, one data domain at a time, with its owners.

  4. STEP 04

    Deploy

    We bring governance into daily work: owners and stewards in place, issues tracked and evidence collected.

  5. STEP 05

    Improve

    We measure quality and compliance indicators, report them to management and extend to further domains.

Questions & answers

Frequently Asked Questions

What is the difference between data governance and data management?

Data management is the daily work of collecting, storing, integrating and securing data. Data governance decides how that work should be done: who owns the data, which rules apply and how compliance is checked. Governance oversees; management carries out.

What is the difference between data quality and data governance?

Data quality describes the data itself: whether it is accurate, complete, consistent and up to date. Data governance is the system of ownership and rules that keeps it that way. Quality problems return when nobody owns the data, so quality work lasts only inside a governance framework.

Who has to comply with the NDMO standards?

The standards are written for public entities in Saudi Arabia, a term that includes companies that run public utilities or national infrastructure, and their scope extends to business partners that handle government data. Entities report on their compliance every year.

What is the National Data Index (NDI)?

The National Data Index is the index SDAIA uses to track the progress of Saudi government entities in data management. It combines a maturity score on six levels (0 to 5), compliance with the 191 specifications of the NDMO standards, and operational excellence.

Does Egypt’s Personal Data Protection Law apply to my organisation?

It applies to organisations that process the personal data of individuals electronically, and it reaches those abroad when the data belongs to Egyptians or to residents of Egypt. Some data is outside the law, including data held by the Central Bank of Egypt and the entities it supervises. This is general information, not legal advice: confirm your position with legal counsel.

We operate in Egypt and Saudi Arabia. Do we need two governance programmes?

No. One framework of ownership, classification, quality rules and a catalogue serves both countries. What differs is the set of controls mapped onto it: the NDMO specifications and the Saudi law for Saudi operations, and Law 151 for Egyptian ones. We design the framework once and map it twice.

Where should a data governance programme start?

With an assessment and one or two data domains that the organisation depends on, such as customers or finance. Naming owners and fixing quality for those shows results early and gives the wider programme a pattern to follow. It should not start with buying a tool.

Do you sell a data governance tool?

No. We design the framework first, then implement it on the catalogue and data quality platform you already run, or help you choose one against your requirements.

Keep exploring

Related Services

Data Analytics & BI

Dashboards, reports, analytical portals and self-service BI on governed data, and the data platform that feeds them.

Learn more

AI & Intelligent Automation

Document understanding, forecasting and assistants that work on your own data, built on data whose quality and governance are in place.

Learn more

Technology Consulting

Assessment, strategy, architecture and a roadmap grounded in what your teams can actually run.

Learn more

All services

Start With a Governance Assessment

Tell us which data you depend on and which rules apply to you. We will show you where you stand and what to fix first.