Overview
Use this article to maintain and group the Data Tag library, including the ingestion of tags from external systems.
Data Tags group and organize classified fields and dataset objects (databases, schemas, and tables). You can use them for searching, filtering, and creating Policy Conditions.
The Classification > Data Tags screen lists every Data Tag available in DSPM, including:
- Built-in tags: Applied to DLP Profiles pre-selected in the default DLP Discovery Profile.
- Custom tags: Created and curated by your organization.
- Infrastructure tags: Ingested from external platforms such as AWS, GCP, and Snowflake.
To apply Data Tags to classification fields, navigate to Classification > Classification Management. For more details, see:
- Use the DSPM Classification Management Page: For field-level classification.
- Object-Level Tagging in DSPM: For object-level classification.
Data Tag Auto-Assignment
When the Netskope DSPM application scans a data store, it automatically assigns Data Tags to newly classified fields based on their associated DLP Profile.
You configure the association between Data Tags and DLP Profiles in the Classification > DLP Profiles and Rules screen. When setting up this association, the platform prompts you to choose an inheritance effect:
- Future-only assignment: Apply the Data Tag(s) only to future fields classified by this DLP Profile (leaving current fields as-is).
- Retroactive assignment: Also apply the Data Tag(s) to currently classified fields.
This configuration determines whether tags are applied only going forward or also backfilled across the existing inventory.
Dynamic Updates via DLP Profiles
Data Tags associated with a DLP Profile maintain a dynamic, two-way relationship with classified objects. This ensures consistency across your data inventory:
- Adding a Data Tag: If you add a Data Tag to a DLP Profile, the system automatically applies that tag to all objects and fields already classified by that specific DLP Profile.
- Removing a Data Tag: If you remove a Data Tag from a DLP Profile, the system automatically removes that tag from all objects and fields previously classified by that specific DLP Profile.
Tag Inheritance Behavior
It is important to understand how tags propagate through your data hierarchy:
- Top-Down Inheritance: When you tag a Data Store, all child objects within it (databases, schemas, tables, and fields) automatically inherit that tag.
- Bottom-Up Visibility: When you tag a child object, the parent object reflects this inheritance. You can view these aggregated tags in the Data Store Inventory page to see which tags are contained within a data store’s datasets.
Built-In Data Tags
Netskope DSPM includes several built-in Data Tags and Categories ready for immediate use:
| Category | Tags |
|---|---|
| Compliance | GDPR, CCPA, PDP, PCI, SOX |
| Healthcare | HIPAA-HI, HIPAA-PI |
| Other | PII |
Manage Data Tags
Perform the following actions from the Classification > Data Tags screen.
Create Tags
- Click Create New Tag.
- Enter the following values:
| Field | Value |
|---|---|
| Tag Category | Select how to group this tag in filters and drop-downs. You can also create a new category here. |
| Tag Name | Enter a friendly name to display throughout the platform (Spaces are not permitted). |
| Description | Explain the tag’s purpose. |
| Color | Select a color from the palette to identify the tag visually. |
- Click Save.
Edit Tags
- Click the edit icon (pencil) on any existing Tag.
- Make your desired changes.
- Click Save.
Delete Tags
- Click the delete icon (trash) on an existing Tag header.
- Click Delete to confirm.
Manage Tag Categories
Create Tag Categories
-
Open the Create or Edit Tag modal (as described above).
-
Click the Tag Category field > select Create new category.
-
Enter the following values:
Field Value Category Name Friendly name to display throughout the platform. Description Explain the category’s purpose. -
Click Save.
-
Continue editing or creating your Tag.
Edit Tag Categories
- Click the edit icon (pencil) on the Category you wish to modify.
- Make your changes and click Save.
Delete Tag Categories
- Click the delete icon (trash) on the Tag Category header.
- Click Delete to confirm.
Ingest External Tags
Netskope DSPM supports ingesting Data Tags from the following external systems.
Amazon Web Services (AWS)
When onboarding AWS Accounts and Organizations, you can auto-ingest tags from the AWS Tag Editor. This triggers the following actions:
- Creates a Data Tag Category named after the AWS Account or Organization ID.
- Creates a Data Tag for each AWS Tag. Ingested tags are automatically adjusted to ensure uniqueness.
Google Cloud Platform (GCP)
When onboarding GCP Projects, you can auto-ingest available GCP Policy Taxonomies. This triggers the following actions:
- Creates a Data Tag Category named after the GCP Policy Taxonomy.
- Creates a Data Tag for each GCP Policy Tag. (Hierarchy paths are prepended if the tag is below the root level).
- Replicates GCP Policy Tag associations to corresponding Netskope DSPM classification fields.
Snowflake
When connecting Snowflake Data Stores, you can auto-ingest Snowflake tags. This triggers the following actions:
- Creates a Data Tag Category named after the Snowflake Data Store Identifier.
- Creates a Data Tag for each Snowflake schema-level tag (prepended with the Data Store Identifier to prevent conflicts).
- Replicates Snowflake tag associations to corresponding Netskope DSPM objects.

