Company Profile
- Company
- Large Enterprise Financial Services Company
- Size
- Large Enterprise
- Industry
- Financial Services
Background
We’ve all heard the standard customer-support call message that says, “This call is being recorded.”
At a financial services company, those recorded calls are turned into text and stored. The raw files hold things that can be used to improve service.
They also hold highly sensitive personal data: customer names and addresses, device serial numbers, and payment card data. Keep that personally identifiable information (PII) in a data lake or a database and the company is exposed.
The raw data comes in several forms. It can be structured, semi-structured, or unstructured. More than 16,000 employees oversee 12 PB of data in 18 countries, and it grows daily.
The company stores many petabytes, and terabytes of new data reach the lake every day. At that size you cannot meet any data privacy law until you know where the sensitive data sits, and can then protect and watch it.
The company could see the General Data Protection Regulation (GDPR) coming in the European Union, and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) with it. Neither was to be taken lightly.
A GDPR fine can reach 4 percent of a firm’s annual global revenue. Given the nature of its business, the company had to keep itself compliant and limit the risk to its large carrier clients as well.
One breach, by accident or not, could set off a chain that damages every party’s name.
So the order was a tall one but a plain one. Account for all sensitive data, and keep PII out of the Amazon S3 data lake.
Challenges
A financial services company needed to find, protect, and watch personally identifiable information (PII) across all its AWS data repositories. It had to be ready for data protection laws that differ by country and by state, among them GDPR, CCPA, and PIPEDA.
Our Approach
■ Established process and policies to meet privacy regulations including GDPR, CCPA, and PIPEDA ■ Scanned 12 PB of data—and growing ■ Consistently finds “no results” in searches for PII, indicating that the system is clear of PII
PKWARE was able to locate specific sensitive elements in locations no other solution was able to find. The alternative of manually sifting through the data warehouse or implementing a solution that required extensive, time-consuming professional services was simply not feasible. Big Data Architect
Use Cases
The financial services company already ran on Amazon Web Services (AWS). Apps pulled personal data into streams, pushed it into an Amazon S3 data lake, and queried it on Amazon Redshift.
Its requirements were simple but firm. Any solution had to fit the AWS setup already in place, scale with the data, and cost little.
Above all, the data had to be stripped of personal information before it ever left Amazon S3 or was queried in Amazon Redshift.
That is where PKWARE came in. “What helped make this decision clear was reviewing the initial test results from PKWARE and confirming there were sensitive elements within our Amazon S3 environment that were outside their originally perceived locations,” said a senior big data architect at the financial services company.
“PKWARE’s broad platform support covered all of our disparate hybrid environments at an overall cost lower than their competition.”
Looking at data privacy, the company had to put proper controls around its data. Those had to meet in-house information security (InfoSec) rules and local law alike.
“In an attempt to protect sensitive information on Amazon S3, we evaluated over a half-dozen technology vendors. In the end, it was clear that PKWARE has the only solution on the market that can find sensitive data in the specific formats we store and at the speed in which we need to achieve our business goals.”
Rolled out across the company, PKWARE let the financial services company audit and clean all of its data at rest.
The solution maps where sensitive personal data sits in Amazon S3, Amazon Redshift, Amazon EMR, and Amazon Aurora. It does the same for other stores running on AWS in a virtual machine, Oracle and SQL Server among them.
Once the sensitive data is found, PKWARE protects it by encryption, masking, and pseudonymization. It then watches who opens that data over time.
PKWARE also helped the company find PII buried in its audio files.
“If people give sensitive information over the phone that is converted from voice to text, we should be able to make sure that those things are encrypted and removed off the data lake,” says the big data architect at the company. PKWARE found that PII and masked it, which was a key part of the client’s compliance.
The solution met the company’s tests for fit, scale, and cost. It was also quick to start: PKWARE was up and running within a few hours of the proof of concept.
Results
Today the financial services company runs PKWARE on AWS to find, protect, and watch sensitive data across the business. It keeps every compliance step in place as the data grows.
If something breaks, or the company misses something, the tool should flag it quickly and help close the gap. As the big data architect says, that rarely happens.
Most of the time the tool returns “no results”, which means no PII was found anywhere in the company’s systems.
“PKWARE was able to locate specific sensitive elements in locations no other solution was able to find,” says the big data architect.
“The alternative of manually sifting through the data warehouse or implementing a solution that required extensive, time-consuming professional services was simply not feasible.”
The company has met GDPR and PIPEDA so far. With PKWARE in place, it no longer has to spend its days hunting for sensitive data, and can turn to other parts of the business.
It can also look ahead. Both PKWARE and the company take GDPR as a start rather than an end, with more privacy law likely to follow it around the world.
That has already begun. The California Consumer Privacy Act (CCPA) and the Australian Government Agencies Privacy Code both set strict regional rules on how data is used and how privacy is kept.
