Overview
The DLP Profiles & Rules screen consolidates classification visibility in Netskope DSPM and replaces the previous Sensitive Data Type management screen.
Use this screen to view any DLP Profile or Rule that is currently relevant to your configuration or has historically classified data within your environment.
This article explains:
- How the DLP Profiles tab determines which profiles are listed.
- How the DLP Rules tab determines which rules are listed.
- How Data Tags behave when associated with DLP Profiles.
DLP Profiles Tab Behavior
This tab lists DLP Profiles based on specific criteria. A profile appears in this list if it meets either of the following conditions:
- Actively Selected: The profile is currently selected within the DSPM Discovery Profile. It appears here even if it has not yet classified any data.
- Previously Applied: The profile has successfully classified data in the past, even if you have removed it from the current Discovery Profile. This ensures visibility into:
- Objects classified under older versions of the Discovery Profile.
- Objects classified externally (e.g., via DSPM for SaaS Apps), which may use a separate rule configuration.
This view helps you distinguish between profiles that are in-scope for current scanning and those that are relevant historically because they have already classified data objects.
DLP Rules Tab Behavior
The DLP Rules tab filters content based on successful matches.
- Displayed: Rules that have successfully applied classification to at least one object.
- Hidden: Rules that exist in your configuration but have never resulted in a classification match.
This filter helps you focus on rules that are actively contributing to your DSPM inventory and risk posture.
Data Tags on DLP Profiles
When you associate a Data Tag with a DLP Profile from this screen, the system enforces a dynamic relationship across your inventory.
- Adding a Data Tag: If you add a Data Tag to a profile, the system automatically applies that tag to:
- All objects previously classified by that profile.
- Any new objects classified by that profile in the future.
- Removing a Data Tag: If you remove a Data Tag from a profile, the system automatically removes that tag from:
- All objects and fields previously classified by that profile.
This behavior ensures that changes at the profile level are automatically reflected across all relevant objects, eliminating the need to re-scan or manually retag data.
If you want to know more details on creating and ingesting tags, see Manage DSPM Data Tags.

