Protecting sensitive customer data is increasingly difficult as organizations store information across multiple locations and business units, while security teams, database administrators, and developers face conflicting approaches to securing it. Beyond internal access control, governments and consumers are asserting rights over how personal data is collected, used, shared, and deleted. Privacy regulations are expanding, highlighted by GDPR’s consent-driven control for EU residents and US responses to high-profile breaches and misuse. Vermont’s law requires data brokers to register, disclose collection and opt-out mechanisms, notify breaches, and provides legal recourse; California’s Consumer Privacy Act was enacted to introduce new consumer rights and was expected to take effect in 2020. Momentum is expected to push toward a more uniform US federal approach in the long term.
A parallel trend is consumer-accessible data via APIs, such as Australia’s Consumer Data Right and the EU’s PSD2, which enables third-party access to bank data through secure APIs with customer consent. As digital services become more complex and integration-heavy, demand grows for developer-centric APIs and for protecting sensitive data at the API layer, often via proxy-style gateways.
Ping Identity’s PingDataGovernance addresses these pressures with dynamic, fine-grained authorization and API-layer data protection. It uses a policy administration UI (via an embedded Symphonic OEM component) for drag-and-drop policy creation, separation of duties (administrators configure data sources; business users define rules), and policy testing with graphical evaluation traces. Capabilities include consent enforcement, delegated access controls that limit visible attributes and search scope, and API response filtering (redaction, obfuscation, blocking). Deployment supports sideband integration with API gateways, operation as an API gateway, and SCIM-based access to protect directories and data sources. It supports OAuth 2.0, OpenID Connect, LDAP v3, and SCIM 2.0, integrates with PingDirectory, PingFederate, and PingOne, and can be deployed on-premises, in clouds, or containerized—though it is primarily geared to structured data and has some out-of-the-box connector limits.
See All Locations
See All Locations