Sensitive data discovery software helps businesses locate sensitive data—such as personally identifiable information (PII), protected health information (PHI), payment card industry (PCI) data, intellectual property (IP), and other important business data—stored across multiple company systems including databases and applications, as well as on user endpoints.
Businesses use sensitive data discovery software to uncover the location of their important data, often to comply with common industry regulatory standards for data protection and privacy; these include the General Data Protection Regulation (GDPR); the California Consumer Privacy Act (CCPA); Health Insurance Portability and Accountability Act (HIPAA); the Payment Card Industry Data Security Standard (PCI DSS); standards from the International Organization for Standardization (ISO); and others. Sensitive data discovery software is typically deployed and managed by information security teams, while privacy teams may request data from the reports. These solutions search structured, semi-structured, and unstructured data stored in on-premises databases, cloud storage, email servers, websites, applications, and more.
Sensitive data discovery can be achieved through multiple ways, including through manual surveys (managed via workflows) or via automated discovery tools. To be included in this category, a product must provide automated data discovery functionality.
Sensitive data discovery software shares similarities with many types of tools, including data loss prevention (DLP) software, data-centric security software, database security software, and privacy software. Generally speaking, sensitive data discovery is offered as a native function of these tools. Sensitive data discovery is different than data discovery software, which is a subset of business intelligence software and helps companies explore their data to uncover trends, identify outliers, and analyze their data trends in a visual way. Sensitive data discovery software also differs from eDiscovery software, which is used for litigation purposes to gather and compartmentalize data files from companies and individuals involved in pending court cases.
To qualify for inclusion in the Sensitive Data Discovery category, a product must:
Provide automated data discovery tools
Monitor data stores in real time to search for newly created sensitive data
Offer contextual search functions to understand factors such as file type, sensitivity, user type, location, and other metadata
Facilitate compliance and enable adherence to common industry regulatory standards (GDPR, CCPA, HIPAA, PCI DSS, ISO, and others)