Skip to main content

Govern sensitive database data

Use NineData Sensitive Data Protection to discover sensitive columns, apply sensitivity levels, mask protected values, and route access through approval. This helps teams reduce data leakage risk when users query, export, or manage production data.

Applicable Scenarios

Sensitive data governance is useful when you want to:

  • Identify columns that contain phone numbers, ID numbers, email addresses, or customer information.
  • Mask sensitive values for users who do not have access.
  • Assign approvers for different sensitivity levels.
  • Audit access to sensitive data across data sources.

How NineData Sensitive Data Protection Works

NineData provides six sensitivity levels, S0 through S5, with built-in recognition rules. After sensitive data protection is enabled, NineData can scan database tables, identify sensitive columns, and apply masking for unauthorized users.

Sensitive data protection settings

Administrators can also use the Sensitive Data Dashboard to review sensitive data coverage across the organization, including enabled data sources, sensitivity levels, protected tables, sensitive columns, and sensitive data access counts.

Sensitive Data Dashboard

Before you begin

Before you configure sensitive data protection, make sure that:

  • The target data source has been added to NineData.
  • You have administrator permissions for the Sensitive Data module.
  • The organization has defined who should approve access for each sensitivity level.
  • Users access the database through NineData so masking and audit controls can take effect.

Configure Sensitive Data Protection

1. Scan Sensitive Columns

Open the Sensitive Data Protection switch for the target data source. In the Operation column, select Scan Settings, then select OK to start the scan.

Scan sensitive columns

If the table contains sensitive data, NineData adds the detected sensitive columns after the scan finishes. For larger tables, the scan may take a few minutes. Review the scan status in Task Scan Log.

View the sensitive column scan log

2. Review Sensitive Columns

Open the Sensitive Columns tab to review the detected columns. Manually adjust editable fields when the classification needs to be refined.

Review sensitive columns

3. Configure Approvers

Configure approvers for sensitivity levels S1 through S5. Users who need access to sensitive columns must request the corresponding permission.

Configure sensitive data approvers

4. Verify Masking And Access Requests

When a user queries a sensitive column without the required permission, NineData masks the value. The user must request access before viewing the original value.

Request access to sensitive data

Result

Sensitive columns are classified, unauthorized access is masked, and access requests can be routed to the responsible approvers. Administrators can use dashboard and audit views to monitor sensitive data governance across the organization.

Next Steps