Professional Data EngineerManaging and securing dataMedium
A global e-commerce company uses BigQuery for analyzing customer purchasing behavior. They have a dataset containing sensitive customer information, including personally identifiable information (PII) like email addresses and phone numbers. To comply with privacy regulations, they need to ensure that this PII is not directly exposed to analysts but can be used for aggregated reporting. The solution must allow for different levels of obfuscation based on the analyst's role (e.g., some analysts might see only the domain of an email, others only a masked version). Which BigQuery feature should they implement?
- ABigQuery Data Masking
- BBigQuery Authorized Views
- CBigQuery Column-level Security
- DBigQuery Row-level Security
Show answer & explanationAnswer & explanation
Correct answer: A. BigQuery Data Masking
BigQuery Data Masking allows for obfuscating sensitive data within columns while still allowing queries. It supports different masking rules based on user roles, directly addressing the requirement for varied levels of PII exposure.
Why the other options are wrong
- B. Authorized Views restrict access to rows and columns, but don't inherently provide dynamic data obfuscation based on roles within a single column.
- C. Column-level security restricts access to entire columns, not obfuscates data within them.
- D. Row-level security restricts access to rows, not obfuscates data within columns.
BigQuery Data Masking
A BigQuery feature that obfuscates sensitive data in specified columns based on policy tags, allowing different levels of data visibility depending on the user's role.
- Applies masking rules to column data values.
- Masking can be dynamic and role-based.
- Does not alter the underlying data.
Memory trick: Mask the PII, different roles see different levels, so privacy is protected but analysis still flows.