Cloud Data Loss Prevention (Cloud DLP) is now part of Sensitive Data Protection. Learn more.

Sensitive Data Protection

Discover and protect your sensitive data

A fully managed service designed to help you discover, classify, and protect your valuable data assets with ease. 

Try our discovery service for BigQuery by scanning and profiling a single table of your choice. 

Features

Automated sensitive data discovery and classification

Discover sensitive data by profiling every BigQuery table and column across your entire organization, select organization folders, or individual projects. Powerful and easy-to-use UI available in the cloud console. Use table and column profiles to inform your security, privacy, and compliance posture. Choose from 150+ predefined detectors or add your own custom types, adjust detection thresholds, and create detection rules to fit your needs and reduce noise.

Sensitive data intelligence for security assessments

With direct feeds into Chronicle and Security Command Center, you can leverage sensitive data intelligence to reduce noise and prioritize threats, vulnerabilities, and security investigations. 

De-identification, masking, tokenization, and bucketing

Sensitive Data Protection helps you take a data-centric approach to securing your assets. De-identification enables you to transform your data to reduce data risk while retaining data utility. Additionally you can use insights to apply column-level, fine-grained access or dynamic masking policies.

Powerful and flexible masking of your AI/ML workloads

Sensitive Data Protection provides tools to classify and de-identify specific sensitive elements within your data. This fine-grained data minimization can help you prepare data for AI model training or protect customer identifiers in chats, feedback, AI prompts, and generated responses to ensure you adhere to regulations and internal policies.

Cover use cases anywhere, on or off cloud with the DLP API

Cloud Data Loss Prevention and the DLP API are part of Sensitive Data Protection. Use the DLP API’s built-in support for various Google Cloud services. Additionally, the DLP API’s in-line content methods enable support for additional data sources, custom workloads, and applications on or off cloud.

Options table

Sensitive data discovery

Used to discover, scan, and classify across a wide set of data

Monitoring for sensitive data across a large set of assets, such as your entire data warehouse

Storage inspection

Targeted, focused inspection to help you find every data element in Google Cloud storage systems

Investigations or dealing with high-value unstructured data like chat logs stored in Google Cloud

Hybrid inspection

Targeted, focused inspection to help you find every data element in storage systems outside Google Cloud

Investigations or dealing with high-value unstructured data like chat logs stored outside Google Cloud

Content inspection

Synchronous, stateless inspection on data from anywhere

Inspecting in near real time or integrating into custom workloads, applications, or pipelines 

Content de-identification

Synchronous, stateless transformation on data from anywhere

Masking, tokenizing, de-identifying in near real time or integrating into custom workloads, applications, or pipelines

Service type Description Suggested use

Sensitive data discovery

Used to discover, scan, and classify across a wide set of data

Monitoring for sensitive data across a large set of assets, such as your entire data warehouse

Storage inspection

Targeted, focused inspection to help you find every data element in Google Cloud storage systems

Investigations or dealing with high-value unstructured data like chat logs stored in Google Cloud

Hybrid inspection

Targeted, focused inspection to help you find every data element in storage systems outside Google Cloud

Investigations or dealing with high-value unstructured data like chat logs stored outside Google Cloud

Content inspection

Synchronous, stateless inspection on data from anywhere

Inspecting in near real time or integrating into custom workloads, applications, or pipelines 

Content de-identification

Synchronous, stateless transformation on data from anywhere

Masking, tokenizing, de-identifying in near real time or integrating into custom workloads, applications, or pipelines

How It Works

To use Sensitive Data Protection, you use one of its services, such as discovery, to scan your data for sensitive elements. You can enable post-scan actions, including alerting and automatic publishing to systems like Chronicle, Security Command Center, and Pub/Sub.
View documentation

Common Uses

Gain awareness of your sensitive data

Investigate your storage

Understand sensitive anomalies

Automate de-identification

Advanced masking and de-identification

De-identify: redact and tokenize data

Protect high-value AI and ML workloads

Redact sensitive data elements in chat

Pricing

How our pricing works

Discovery is billed based on the pricing mode you select. Inspection and transformation pricing is based on total bytes processed.

Discovery

Consumption mode

$0.03/GB


Fixed-rate subscription mode

$2500/unit

Inspection and transformation

Up to 1GB

Free


Inspection of Google Cloud storage systems

Starting at

$1/GB

Lower with volume


Inspection of data from any source (hybrid inspection)

Starting at

$3/GB

Lower with volume


In-line content inspection

Starting at

$3/GB

Lower with volume


In-line content de-identification

Starting at

$2/GB

Lower with volume

Risk analysis

Analyze sensitive data to find properties that might increase the risk of subjects being identified

No Sensitive Data Protection charges* 

Risk analysis uses resources in BigQuery; charges appear as BigQuery usage

How our pricing works Discovery is billed based on the pricing mode you select. Inspection and transformation pricing is based on total bytes processed.
Category or type Description Price USD
Discovery

Consumption mode

$0.03/GB

Fixed-rate subscription mode

$2500/unit

Inspection and transformation

Up to 1GB

Free

Inspection of Google Cloud storage systems

Starting at

$1/GB

Lower with volume

Inspection of data from any source (hybrid inspection)

Starting at

$3/GB

Lower with volume

In-line content inspection

Starting at

$3/GB

Lower with volume

In-line content de-identification

Starting at

$2/GB

Lower with volume

Risk analysis

Analyze sensitive data to find properties that might increase the risk of subjects being identified

No Sensitive Data Protection charges* 

Risk analysis uses resources in BigQuery; charges appear as BigQuery usage

Pricing Calculator

Estimate your monthly costs.
Estimate your costs

Custom Quote

Connect with our sales team to get a custom quote for your organization.
Request a quote

Start your proof of concept

New customers get $300 in free credits.

Try Sensitive Data Protection

See Sensitive Data Protection in action.

Profile a table in test mode

Sensitive data discovery for your data warehouse

Get started

De-identify sensitive data stored in Cloud Storage

Learn more

Try our classification engine for yourself

View demo

Business Case

Explore how other businesses cut costs, increase ROI, and drive innovation with Sensitive Data Protection