Automatic discovery, classification, and de-identification of sensitive data in Google Cloud.
What is Sensitive Data Protection?
Sensitive Data Protection, formerly known as Cloud Data Loss Prevention (Cloud DLP), is Google’s service for automatic discovery and protection of sensitive data. Cloud DLP is now part of Sensitive Data Protection; the API name Cloud Data Loss Prevention API (DLP API) remains. The service scans structured and unstructured data in Cloud Storage, BigQuery, text streams, and other sources to identify personally identifiable information (PII), financial data, and other confidential content. With over 200 predefined detectors, the service recognizes patterns such as credit card numbers, social security numbers, email addresses, and country-specific identifiers.
The de-identification engine offers various techniques for protecting discovered data. Masking replaces sensitive content with placeholders, tokenization converts data into tokens that are not directly reversible, format-preserving encryption maintains the data format, and date-shifting consistently shifts date values. These methods enable using data for analytics and development without exposing sensitive information.
Discovery scans automate continuous monitoring of entire projects or organizations. The service creates data profiles showing where sensitive data is stored, what types are present, and what risk exists, including risk metrics such as k-anonymity. This transparency is the foundation for compliance audits and data protection strategies.
Core Features
- Data Discovery: Automated scans across Cloud Storage, BigQuery, and other sources to detect sensitive data across entire organizations
- Classification: Over 200 predefined detectors for PII, financial data, health data, and country-specific identifiers, extensible via custom dictionaries and regular expressions
- De-identification: Masking, tokenization, format-preserving encryption, and date-shifting for protecting sensitive data
- Risk Assessment: Data profiling with risk metrics (e.g., k-anonymity, l-diversity) and recommendations for risk mitigation
Typical Use Cases
GDPR Compliance and Data Protection
Organizations use Sensitive Data Protection to identify and protect personal data across their cloud environments. Automated scans support correct classification of PII according to GDPR requirements. De-identification enables using data for analytics without violating privacy regulations.
Secure Data Sharing for Development and Analytics
Development and analytics teams need realistic test data that contains no real personal information. Sensitive Data Protection automatically de-identifies production data so teams can work with structurally correct but anonymized data.
Benefits
- Automatic detection of sensitive data without manual classification
- Over 200 predefined detectors with high detection rates
- Flexible de-identification methods for various use cases
- Integration with BigQuery, Cloud Storage, and other Google Cloud services
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Sensitive Data Protection: setting up discovery scans, configuring de-identification pipelines, GDPR compliance strategies, and integration into existing data architectures.
Typical Use Cases
Frequently Asked Questions
What is Sensitive Data Protection?
Sensitive Data Protection (formerly Cloud Data Loss Prevention / Cloud DLP) is a Google Cloud service that automatically discovers, classifies, and protects sensitive data such as credit card numbers, social security numbers, and personal information. The service uses over 200 predefined detectors.
How does de-identification work?
Sensitive Data Protection offers various de-identification techniques, including masking, tokenization, format-preserving encryption, and date-shifting. These methods protect data while keeping it usable for analytics.
Which data sources are supported?
The service scans Cloud Storage, BigQuery, text streams, files in repositories, and images, among others. Discovery scans can be automated across entire projects or organizations.
What does Sensitive Data Protection cost?
Billing is usage-based, including by the amount of data scanned and the features used. Current prices should be checked against the official Google Cloud pricing page.
What is the difference from Cloud DLP?
Cloud DLP is now part of Sensitive Data Protection and has been folded into its feature set. The API name Cloud Data Loss Prevention API (DLP API) remains, while the overall product is branded as Sensitive Data Protection.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
