Skip to main content
Version: v4

Data Policy

Data Policy is a privacy management tool that helps enterprises define unified data privacy and access control policies on the Canner platform.

Configure a Data Policy​

A Data Policy must first be configured by the Admin, after which authorized users apply it to data sources and workspaces. This chapter describes how the Admin configures Data Policies on the Data Policies page. For the permissions and steps to apply Data Policies in data sources and workspaces, see Chapter 2.3 Data Catalog Module.

Data Policy limit

Up to 100 Data Policies are supported

Step 1: Open the Data Policies page​

Click the settings icon in the upper-right corner and select Data Policies.

caution

Data Policy permissions: only admin users can create Data Policies.

1_data_policy.png

Step 2: Create a Data Policy​

On the Data Policies page, click the Create a Data Policy button.

2_data_policy.png

In the Create Policy dialog, configure the following:

3_data_policy.png

  • Name: The display name of the policy; it can be changed
  • Definition: The data protection method used by the policy
    • Masking, Hashing, or Encryption
  • Description: An optional description of the policy

4_data_policy.png

  1. Masking

    • Masking pattern: Built-in masking patterns for six types of personal data, including Email, Identification Number, Date of birth, Name, and Phone Number. Up to 2 patterns can be stacked. Note that stacked patterns are applied in order.
    • Replace value with: The replacement value

    5_data_policy.png

  2. Hashing

    6_data_policy.png

  3. Encryption

    Supports AES, PBE, and RSA encryption

    Notes on using RSA

    With RSA encryption, column values must be within 200 bytes; values over the limit fail to encrypt. RSA is also a strong encryption method, so encryption and decryption take longer, depending on the data length.

    7_data_policy.png

    • Assign decrypt permission to identities: The groups and users allowed to decrypt. Note that the person who configures the Data Policy does not have decryption permission by default and must also be granted it to decrypt.

    8_data_policy.png

Step 3: Finish​

After you click Submit, all Data Policies created so far are listed.

9_data_policy.png

Edit a Data Policy​

All fields of an existing Data Policy can be edited. If you change the masking/encryption method (the Definition field), the system warns you which data sources and workspaces the change may affect, as shown below.