Professional Cloud ArchitectDesign for security and complianceMedium
A research institution is deploying a data analytics pipeline on Google Cloud that processes sensitive genetic data. They need to comply with strict privacy regulations, which require that personally identifiable information (PII) within the datasets is masked or de-identified before being used for analytics, to prevent re-identification. The institution wants a managed service that can automatically discover and redact or transform sensitive data within various data sources (e.g., BigQuery, Cloud Storage). Which Google Cloud service is designed for this purpose?
- ASecurity Command Center
- BCloud Audit Logs
- CCloud Identity
- DCloud Data Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Data Loss Prevention (DLP)
Cloud Data Loss Prevention (DLP) is specifically designed to discover, classify, and redact or transform sensitive data (like PII) across various Google Cloud services, helping organizations comply with privacy regulations.
Why the other options are wrong
- A. Security Command Center provides a centralized security posture management and vulnerability detection service, but it doesn't perform data de-identification.
- B. Cloud Audit Logs record administrative activities and data access, but they do not de-identify sensitive data within datasets.
- C. Cloud Identity manages user identities and groups, which is related to access control, not the de-identification of data content.
Cloud Data Loss Prevention (DLP)
A Google Cloud service that helps discover, classify, redact, and transform sensitive data (like PII) across various data sources to protect privacy and ensure compliance.
- Scans structured and unstructured data for sensitive information.
- Offers various de-identification techniques: redaction, tokenization, format-preserving encryption.
- Integrates with BigQuery, Cloud Storage, Datastore, and more.
Memory trick: DLP Detects and De-identifies Data, Protecting Privacy.