This topic provides information about Sensitive Data Protection and data security, including certifications, compliance (including GDPR), and encryption. For additional information about data security and Google Cloud, see Google Cloud Security.
Certifications
Sensitive Data Protection meets various certifications and compliance standards, including the following. This is not an exhaustive list.
- ISO/IEC 27001
- ISO/IEC 27017:2015
- ISO/IEC 27018:2014
- Payment Card Industry Data Security Standard (PCI DSS)
- HIPAA business associate agreement (BAA)
- Multi-Tier Cloud Security (MTCS) Singapore Standard (SS) 584
For more information about the compliance offerings that Google Cloud services satisfy, see Compliance resource center.
GDPR
Compliance with the European Union General Data Protection Regulation (GDPR) is a top priority for Google Cloud and our customers.
While Sensitive Data Protection offers several built-in infoType detectors that may be applicable to GDPR compliance, you may need to build your own custom infoType detectors, and should test thoroughly to ensure that the tool fits your specific needs.
You are encouraged to read the