Protecting sensitive customer data has become a defining compliance and risk challenge as privacy laws proliferate across regions. Key drivers include the EU’s GDPR, APEC’s Cross-Border Privacy Rules (CBPR) to build consumer trust as data moves between economies, and U.S. state initiatives spurred by major breaches and scandals. Vermont’s data broker legislation introduces registration, opt-out disclosure, breach notification, and legal recourse requirements, while California’s Consumer Privacy Act (effective 2020) expands consumer rights. Sector-specific mandates add complexity, such as the NY DFS Cybersecurity Regulation (23 NYCRR 500), which requires regulated financial institutions to assess cyber risk and maintain audit trails with a three-year retention expectation rather than five.
Organizations must identify where data resides, classify sensitivity and risk, and demonstrate compliance across overlapping rules. Traditional Identity Governance and Administration (IGA), originally driven by SOX separation-of-duties needs, addresses only part of the broader data compliance problem, motivating a more comprehensive approach based on data intelligence.
BigID positions its Data Intelligence Platform as that foundation by discovering, indexing, and correlating identity-related data across heterogeneous sources without centralizing the underlying sensitive content. It connects to structured and unstructured systems, uses ML/AI techniques (e.g., classification, entity extraction/resolution, clustering, confidence and re-identifiability scoring), and builds an inventory enabling centralized dashboards, risk trends, and relationship/flow visualizations (including swim lanes). BigID layers purpose-built apps for privacy (e.g., subject access automation, RoPA tracking, consent, portals, transfer monitoring), protection (e.g., access intelligence, remediation, labeling, breach investigation), and data perspectives (e.g., quality and retention, with stewardship/provenance planned). The platform supports policy-driven remediation, integrations, SSO (SAML), RBAC, DevOps via REST APIs/SDKs, and flexible deployment (on-prem, cloud, hybrid, SaaS, Kubernetes). Noted constraints include coarse-grained policy granularity, a developing partner ecosystem, VC funding status, and lack of blockchain data-source support.
See All Locations
See All Locations