Skip to main content
Cloud / Google Cloud / Products / Sensitive Data Protection - Data Discovery and Protection

Sensitive Data Protection - Data Discovery and Protection

Sensitive Data Protection (formerly Cloud DLP) automatically discovers, classifies, and protects sensitive data in Google Cloud.

Security
Pricing Model Pay-per-use (including per amount of data scanned)
Availability Global with EU regions
Data Sovereignty EU regions available
Reliability SLA as published by the provider SLA

Automatic discovery, classification, and de-identification of sensitive data in Google Cloud.

What is Sensitive Data Protection?

Sensitive Data Protection, formerly known as Cloud Data Loss Prevention (Cloud DLP), is Google’s service for automatic discovery and protection of sensitive data. Cloud DLP is now part of Sensitive Data Protection; the API name Cloud Data Loss Prevention API (DLP API) remains. The service scans structured and unstructured data in Cloud Storage, BigQuery, text streams, and other sources to identify personally identifiable information (PII), financial data, and other confidential content. With over 200 predefined detectors, the service recognizes patterns such as credit card numbers, social security numbers, email addresses, and country-specific identifiers.

The de-identification engine offers various techniques for protecting discovered data. Masking replaces sensitive content with placeholders, tokenization converts data into tokens that are not directly reversible, format-preserving encryption maintains the data format, and date-shifting consistently shifts date values. These methods enable using data for analytics and development without exposing sensitive information.

Discovery scans automate continuous monitoring of entire projects or organizations. The service creates data profiles showing where sensitive data is stored, what types are present, and what risk exists, including risk metrics such as k-anonymity. This transparency is the foundation for compliance audits and data protection strategies.

Core Features

  • Data Discovery: Automated scans across Cloud Storage, BigQuery, and other sources to detect sensitive data across entire organizations
  • Classification: Over 200 predefined detectors for PII, financial data, health data, and country-specific identifiers, extensible via custom dictionaries and regular expressions
  • De-identification: Masking, tokenization, format-preserving encryption, and date-shifting for protecting sensitive data
  • Risk Assessment: Data profiling with risk metrics (e.g., k-anonymity, l-diversity) and recommendations for risk mitigation

Typical Use Cases

GDPR Compliance and Data Protection

Organizations use Sensitive Data Protection to identify and protect personal data across their cloud environments. Automated scans support correct classification of PII according to GDPR requirements. De-identification enables using data for analytics without violating privacy regulations.

Secure Data Sharing for Development and Analytics

Development and analytics teams need realistic test data that contains no real personal information. Sensitive Data Protection automatically de-identifies production data so teams can work with structurally correct but anonymized data.

Benefits

  • Automatic detection of sensitive data without manual classification
  • Over 200 predefined detectors with high detection rates
  • Flexible de-identification methods for various use cases
  • Integration with BigQuery, Cloud Storage, and other Google Cloud services

Integration with innFactory

As a certified Google Cloud partner, innFactory supports you with Sensitive Data Protection: setting up discovery scans, configuring de-identification pipelines, GDPR compliance strategies, and integration into existing data architectures.

Typical Use Cases

Automatic detection of sensitive data in Cloud Storage and BigQuery
De-identification and tokenization of personal data
Compliance support for GDPR, PCI DSS, and HIPAA

Frequently Asked Questions

What is Sensitive Data Protection?

Sensitive Data Protection (formerly Cloud Data Loss Prevention / Cloud DLP) is a Google Cloud service that automatically discovers, classifies, and protects sensitive data such as credit card numbers, social security numbers, and personal information. The service uses over 200 predefined detectors.

How does de-identification work?

Sensitive Data Protection offers various de-identification techniques, including masking, tokenization, format-preserving encryption, and date-shifting. These methods protect data while keeping it usable for analytics.

Which data sources are supported?

The service scans Cloud Storage, BigQuery, text streams, files in repositories, and images, among others. Discovery scans can be automated across entire projects or organizations.

What does Sensitive Data Protection cost?

Billing is usage-based, including by the amount of data scanned and the features used. Current prices should be checked against the official Google Cloud pricing page.

What is the difference from Cloud DLP?

Cloud DLP is now part of Sensitive Data Protection and has been folded into its feature set. The API name Cloud Data Loss Prevention API (DLP API) remains, while the overall product is branded as Sensitive Data Protection.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Ready to start with Sensitive Data Protection - Data Discovery and Protection?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation