This page documents production updates to Sensitive Data Protection. You can periodically check this page for announcements about new or updated features, known issues, and deprecated functionality.
For a list of known issues for Sensitive Data Protection, see Known issues.
Current version: v2
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
August 13, 2026
The ANTHROPIC_API_KEY, GEMINI_API_KEY, and OPENAI_API_KEY infoType detectors are available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
July 14, 2026
The CRIME_STATUS infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
July 13, 2026
If you leave InfoType.version unset
or set it to stable when setting the MEDICAL_ID
infoType in your InspectConfig,
Sensitive Data Protection includes MEDICAL_RECORD_NUMBER
findings as type MEDICAL_ID in the scan results.
You can still use the old functionality by setting
InfoType.version to legacy for the next 90 days.
July 09, 2026
The SWITZERLAND_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
June 29, 2026
You can configure Sensitive Data Protection to detect specific file labels, which can represent Google Drive labels or Microsoft sensitivity labels. For more information, see Create a custom metadata label detector.
June 23, 2026
Image safety classification infoTypes are now supported in ExcludeByImageFindings and AdjustByImageFindings detection rules.
For information about configuring these rules, see Modifying infoType detectors to refine scan results.
June 22, 2026
Image scanning is available in the following cloud regions:
asia-southeast1us-east4us-west1
For more information, see Locations that support image scanning.
Between July 2025 and June 2026, some table data
profiles saved to BigQuery contained an incorrect
1970-01-01 timestamp instead of NULL in expiration_time
for tables that don't expire. This issue has been fixed. New exports of table
data profiles show the correct expiration timestamps.
June 12, 2026
Added support for inspecting and de-identifying batched content. You can now include a BatchContentItem in your ContentItem requests.
June 08, 2026
The OBJECT_TYPE/PERSON/SIGNATURE infoType detector is available in global and the asia, europe, and us multi-regions. For more information about all infoTypes, see InfoType detector reference.
June 03, 2026
Added support for inspecting and de-identifying conversational content. You can now include a Conversation in your ContentItem requests.
May 11, 2026
If you set InfoType.version to latest when including the MEDICAL_ID infoType in your InspectConfig, Sensitive Data Protection will now include MEDICAL_RECORD_NUMBER findings as type MEDICAL_ID in the scan results.
You can still use the old functionality by setting InfoType.version to stable. In 30 days, the new functionality will be promoted to stable.
March 28, 2026
You can configure Sensitive Data Protection to detect specific client-provided metadata. For more information, see Create a custom metadata label detector.
March 13, 2026
The USER_NAME infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
March 11, 2026
The CRIME_STATUS infoType detector is available in Preview. For more information about all infoTypes, see InfoType detector reference.
March 07, 2026
You can configure Sensitive Data Protection to detect specific metadata labels in your content. For more information, see Create a custom metadata label detector.
February 23, 2026
Sensitive Data Protection can discover and profile Vertex AI tuning jobs. For more information, see Sensitive data discovery for Vertex AI.
The following features are in General Availability:
- Adjustment rules, which let you customize the likelihood of findings based on their context. Adjustment rules support text-based and image-based operations.
- Image-based exclusion rules, which let you refine your image inspection results by excluding findings based on their spatial relationships with other findings.
- Enhanced rule ordering, which lets you chain rules based on the order you specify them in the ruleset.
For information about configuring these rules, see Modifying infoType detectors to refine scan results.
The KOREA_BRN infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
January 20, 2026
Sensitive Data Protection is available in the asia-southeast3 (Bangkok) region. For more information, see Sensitive Data Protection locations.
January 16, 2026
The following infoType detectors are available in global and the asia,
europe, and us multi-regions:
IMAGE_TYPE/CONTEXT/VIOLENCEIMAGE_TYPE/CONTEXT/SEXUALLY_EXPLICITIMAGE_TYPE/CONTEXT/SEXUALLY_SUGGESTIVE
For more information about all infoTypes, see InfoType detector reference.
January 05, 2026
General infoType functionality and the following infoTypes are now available in all regions:
CREDIT_CARD_DATADEMOGRAPHIC_DATADRIVERS_LICENSE_NUMBERFINANCIAL_IDGEOGRAPHIC_DATAGOVERNMENT_IDMEDICAL_DATAMEDICAL_IDSECURITY_DATATECHNICAL_ID
For more information about all built-in infoTypes, see the InfoType detector reference.
December 15, 2025
The OBJECT_TYPE/PERSON/FACE infoType detector is available in Preview in global and the asia, europe, and us multi-regions. For more information about all infoTypes, see InfoType detector reference.
November 23, 2025
The KOREA_NHI_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
November 07, 2025
The following infoType detectors are available in global and the europe and
us multi-regions:
DOCUMENT_TYPE/CONTEXT/FINANCEDOCUMENT_TYPE/CONTEXT/HEALTHDOCUMENT_TYPE/CONTEXT/LEGALDOCUMENT_TYPE/CONTEXT/OBSCENEDOCUMENT_TYPE/CONTEXT/OFFENSIVEDOCUMENT_TYPE/CONTEXT/POLITICSDOCUMENT_TYPE/CONTEXT/RELIGIONDOCUMENT_TYPE/CONTEXT/SEXUAL
For more information about all infoTypes, see InfoType detector reference.
November 03, 2025
The OBJECT_TYPE/PERSON/PASSPORT and OBJECT_TYPE/PERSON/PHOTO_ID_CARD infoType detectors are available in global and the asia, europe, and us multi-regions. For more information about all infoTypes, see InfoType detector reference.
October 27, 2025
The NEW_ZEALAND_DRIVERS_LICENSE_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
October 17, 2025
Customers with an organization-level activation of Security Command Center Premium have an organization-level discovery subscription at no charge from Sensitive Data Protection. For more information, see Sensitive data discovery in Security Command Center Premium.
October 10, 2025
The BRAZIL_RG_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
October 02, 2025
This is an addition to the May 1 release note announcing the deprecation of the ability to send inspection and discovery results from Sensitive Data Protection to Data Catalog.
If you have workflows that create inspection jobs or job triggers and set the
deprecated
PublishFindingsToCloudDataCatalog
action, you must update those workflows by January 30, 2026. On or after this
date, new jobs and job triggers that are created by those workflows will fail.
September 22, 2025
The DOCUMENT_TYPE/FINANCE/INVOICE and DOCUMENT_TYPE/MEDICAL/RECORD infoType detectors are available in global and the asia, europe, and us multi-regions. For more information about all infoTypes, see InfoType detector reference.
September 19, 2025
When you inspect a BigQuery table for sensitive data, you can send the inspection findings to Dataplex Universal Catalog. For more information, see Send inspection results to Dataplex Universal Catalog as aspects.
September 08, 2025
Fixed the issue preventing Sensitive Data Protection from detecting sensitive data in the headers and footers of certain rich document types.
September 02, 2025
When configuring schedules for Cloud Storage data discovery, you can select data based on specific tags. For more information, see Profile Cloud Storage data in an organization or folder or Profile Cloud Storage data in a single project.
August 29, 2025
The August 25 release note announcing the release of the DOCUMENT_TYPE/FINANCE/INVOICE and DOCUMENT_TYPE/MEDICAL/RECORD infoType detectors was published in error. These infotypes are not available.
August 25, 2025
The DOCUMENT_TYPE/FINANCE/INVOICE and DOCUMENT_TYPE/MEDICAL/RECORD infoType detectors are available in global and the asia, europe, and us multi-regions. For more information about all infoTypes, see InfoType detector reference.
August 15, 2025
The AUSTRIA_SOCIAL_SECURITY_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
During discovery operations, Sensitive Data Protection scans the contents of various archive files. For a list of supported file types, see Supported file clusters in discovery operations.
August 13, 2025
You can configure Sensitive Data Protection to save the findings from an inspection job to a Cloud Storage bucket or folder. For more information, see Save findings to Cloud Storage.
August 04, 2025
Sensitive Data Protection provides recommendations to optimize your infoType selections. In the Google Cloud console, if you select a specific infoType that is covered by a general infoType, Sensitive Data Protection recommends general infoTypes that you can use instead.
For information about the benefits of using general infoTypes, see General and specific infoType detectors.
August 01, 2025
The following infoType detectors are available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
DOCUMENT_TYPE/R&D/SOURCE_CODE/CDOCUMENT_TYPE/R&D/SOURCE_CODE/CPPDOCUMENT_TYPE/R&D/SOURCE_CODE/CSDOCUMENT_TYPE/R&D/SOURCE_CODE/GODOCUMENT_TYPE/R&D/SOURCE_CODE/HTMLDOCUMENT_TYPE/R&D/SOURCE_CODE/JAVADOCUMENT_TYPE/R&D/SOURCE_CODE/JAVASCRIPTDOCUMENT_TYPE/R&D/SOURCE_CODE/JSONDOCUMENT_TYPE/R&D/SOURCE_CODE/PHPDOCUMENT_TYPE/R&D/SOURCE_CODE/POWERSHELLDOCUMENT_TYPE/R&D/SOURCE_CODE/PYTHONDOCUMENT_TYPE/R&D/SOURCE_CODE/RUSTDOCUMENT_TYPE/R&D/SOURCE_CODE/SHELLDOCUMENT_TYPE/R&D/SOURCE_CODE/SQLDOCUMENT_TYPE/R&D/SOURCE_CODE/TYPESCRIPT
July 04, 2025
Sensitive Data Protection can detect and redact the following object infoTypes in images:
OBJECT_TYPE/BARCODEOBJECT_TYPE/LICENSE_PLATEOBJECT_TYPE/PERSONOBJECT_TYPE/WHITEBOARD
For more information, see the following:
June 25, 2025
The CZECHIA_PERSONAL_ID_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
May 19, 2025
The InfoType detector reference was updated to include the designated categories (locations, industries, and types) and default sensitivity score of each infoType.
May 14, 2025
Inspection jobs for XSLX files in Cloud Storage have improved performance. Sensitive Data Protection reads large custom dictionary source data only once for each sheet that has potential findings.
May 12, 2025
By default, scans for MAC_ADDRESS findings now include MAC_ADDRESS_LOCAL findings. Previously, you could only use this functionality if you set the InfoType.version of MAC_ADDRESS to latest in your InspectConfig.
You can still use the old version of MAC_ADDRESS by setting its InfoType.version to legacy or by using the MAC_ADDRESS_UNIVERSAL infoType. In 90 days, the new functionality will be promoted to legacy.
May 01, 2025
On or after September 30, 2025, you can no longer send inspection and discovery results from Sensitive Data Protection to Data Catalog. Data Catalog is deprecated and will be discontinued on January 30, 2026. For Sensitive Data Protection, no action is required from you. No inspection or discovery configuration will break.
For discovery operations, we recommend that you add Dataplex Catalog aspects based on insights from data profiles instead.
You can automatically attach aspects to Dataplex entries after profiling supported data resources. For more information, see Add Dataplex Catalog aspects based on insights from data profiles.
April 28, 2025
The discovery service of Sensitive Data Protection now supports Azure Blob Storage. You can run discovery to generate data profiles of your Blob Storage containers. Data profiles provide metrics and insights about the sensitivity and risk levels of your data to help you plan your data protection and governance workflows.
This feature is available only to Security Command Center Enterprise customers. To use this feature, you need an Azure connector in Security Command Center that has permissions for Sensitive Data Protection discovery.
To get started on profiling Blob Storage data, see the following:
April 17, 2025
The discovery findings that Sensitive Data Protection generates in Security Command Center include recommended next steps. This improvement applies to the finding categories listed in Publish data profiles to Security Command Center.
April 11, 2025
If you set InfoType.version to latest when including the MAC_ADDRESS infoType in your InspectConfig, Sensitive Data Protection will now include MAC_ADDRESS_LOCAL findings as type MAC_ADDRESS in the scan results.
You can still use the old functionality by setting InfoType.version to stable, by leaving InfoType.version unset when using the MAC_ADDRESS infoType, or by using the MAC_ADDRESS_UNIVERSAL infoType. In 30 days, the new functionality will be promoted to stable.
April 02, 2025
The MAC_ADDRESS_UNIVERSAL infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
March 19, 2025
The CZECHIA_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
March 04, 2025
Sensitive Data Protection is available in the europe-north2 region. For more information, see Sensitive Data Protection locations.
February 17, 2025
Data profiles that send findings to Security Command Center include the INFO_TYPES and RELATED_RESOURCES fields when available. These fields appear in the sourceProperties field of the finding in Security Command Center. The affected finding categories are DATA_RISK, DATA_SENSITIVITY, PUBLIC_SENSITIVE_DATA, SECRETS_IN_STORAGE, and SENSITIVE_DATA_CMEK_DISABLED.
February 14, 2025
Sensitive data discovery for Vertex AI is in General Availability. You can run discovery at the organization, folder, or project level to generate profiles of your Vertex AI training data. Data profiles provide metrics and insights about the sensitivity and risk levels of your data to help you plan your data governance workflows.
February 11, 2025
The JAPAN_CORPORATE_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
February 10, 2025
The RELIGIOUS_TERM infoType detector is now generally available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
February 05, 2025
The CREDIT_CARD_EXPIRATION_DATE infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
February 04, 2025
Regional endpoints for Sensitive Data Protection are available in the eu and us multi-regions. For more information, see Global and regional endpoints for Sensitive Data Protection.
February 03, 2025
The CVV_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
January 13, 2025
The TAIWAN_ID_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
The FRANCE_DRIVERS_LICENSE_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
December 06, 2024
The current default DATE_OF_BIRTH infoType detection model, which is available when InfoType.version is set to latest or stable, is now also used when InfoType.version is set to legacy.
The old detection model that was previously available by setting InfoType.version to legacy is no longer available.
November 25, 2024
The PHONE_NUMBER infoType functionality that was previously only available by setting InfoType.version to latest or stable is now also used when InfoType.version is set to legacy. The new model includes US_TOLLFREE_PHONE_NUMBER findings as type PHONE_NUMBER in the scan results.
The old detection model that was previously available by setting InfoType.version to legacy is no longer available.
November 19, 2024
The November 4 release note announcing the release of sample discovery findings was published in error. This feature is not available.
November 15, 2024
Sensitive data discovery is now included in Security Command Center Enterprise. To enable discovery in the Security Command Center Enterprise tier, see Enable sensitive data discovery in the Enterprise tier in the Security Command Center documentation.
The Sensitive Data Protection discovery service remains available to Security Command Center Premium and Standard customers as a separately priced feature. For more information, see Publish data profiles to Security Command Center.
November 14, 2024
The current default STREET_ADDRESS infoType detection model, which is available when InfoType.version is set to latest or stable, is now also used when InfoType.version is set to legacy.
The old detection model that was previously available by setting InfoType.version to legacy is no longer available.
November 11, 2024
The current default ORGANIZATION_NAME infoType detection model, which is available when InfoType.version is set to latest or stable, is now also used when InfoType.version is set to legacy.
The old detection model that was previously available by setting InfoType.version to legacy is no longer available.
The region restriction on the ORGANIZATION_NAME infoType has been lifted. It is now available in all regions.
November 08, 2024
The EMPLOYMENT_STATUS infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
November 04, 2024
You can configure discovery to save sample findings to a BigQuery table. This feature is useful if you want to evaluate whether your inspection configuration is correctly matching the type of information that you want to flag as sensitive. To enable this feature, create or edit the scan configuration for the data resource that you want to profile.
October 28, 2024
The ITALY_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
October 25, 2024
The PARAGUAY_TAX_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
The sensitive data discovery service can now detect the presence of secrets, such as passwords and authentication tokens, in your Cloud Run service revision environment variables. Sensitive Data Protection sends any findings to Security Command Center as vulnerability findings. For more information, see Report secrets in environment variables to Security Command Center.
October 11, 2024
The KOREA_DRIVERS_LICENSE_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
October 10, 2024
The INDONESIA_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
October 01, 2024
The current default LOCATION infoType detection model, which is accessible when InfoType.version is set to latest or stable, is now also used when InfoType.version is set to legacy.
The old detection model that was previously accessible by setting InfoType.version to legacy is no longer accessible.
The region restriction on the LOCATION infoType has been lifted. It is now available in all regions.
September 30, 2024
The FINLAND_BUSINESS_ID infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
September 17, 2024
The POLITICAL_TERM infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
The NEW_ZEALAND_NHI_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
September 11, 2024
The discovery service of Sensitive Data Protection now supports Amazon S3. You can run discovery to generate data profiles of your S3 buckets. Data profiles provide metrics and insights about the sensitivity and risk levels of your data to help you plan your data governance workflows.
This feature is available only to Security Command Center Enterprise customers. To use this feature, you need an AWS connector in Security Command Center that has Sensitive Data Protection enabled.
To get started on profiling Amazon S3 data, see the following:
- Connect to AWS for vulnerability detection and risk assessment
- Sensitive data discovery for Amazon S3
- Profile Amazon S3 data
For more information about sensitive data discovery, see Data profiles.
September 10, 2024
The DOD_ID_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
September 06, 2024
The SEXUAL_ORIENTATION infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
August 27, 2024
Regional endpoints are available for Sensitive Data Protection. Regional endpoints help you meet data residency requirements by keeping data at rest, in use, and in transit within your specified region. For more information, see Global and regional endpoints for Sensitive Data Protection.
Regional endpoints for Sensitive Data Protection are available in the following regions:
australia-southeast1asia-east1asia-east2asia-northeast1asia-northeast3asia-south1asia-south2asia-southeast1asia-southeast2europe-central2europe-north1europe-southwest1europe-west1europe-west2europe-west3europe-west4europe-west6europe-west8europe-west9me-central1me-central2me-west1southamerica-east1southamerica-west1northamerica-northeast1northamerica-northeast2us-central1us-east1us-east4us-east5us-south1us-west1us-west2us-west3us-west4
August 15, 2024
The PHONE_NUMBER infoType functionality that was previously only accessible by setting InfoType.version to latest has been promoted to be the default detection model for this infoType. The new model includes US_TOLLFREE_PHONE_NUMBER findings as type PHONE_NUMBER in the scan results.
To enable the new functionality, leave InfoType.version unset, or set it to latest or stable. To use the old functionality, set InfoType.version to legacy. You can continue to use the legacy functionality for 90 days.
August 05, 2024
The ORGANIZATION_NAME infoType detection model that was previously only accessible by setting InfoType.version to latest has been promoted to be the default detection model for this infoType. The new model offers improved detection quality.
To use the new model, leave InfoType.version unset, or set it to latest or stable. To use the old detection model, set InfoType.version to legacy. You can continue to use the legacy model for 90 days.
The STREET_ADDRESS infoType detection model that was previously only accessible by setting InfoType.version to latest has been promoted to be the default detection model for this infoType. The new model offers improved detection quality.
To use the new model, leave InfoType.version unset, or set it to latest or stable. To use the old detection model, set InfoType.version to legacy. You can continue to use the legacy model for 90 days.
July 31, 2024
The DATE_OF_BIRTH infoType detection model that was previously only accessible by setting InfoType.version to latest has been promoted to be the default detection model for this infoType. The new model offers improved detection quality.
To use the new model, leave InfoType.version unset, or set it to latest or stable. To use the old detection model, set InfoType.version to legacy. You can continue to use the legacy model for 90 days.
July 25, 2024
Sensitive Data Protection can now apply tags to your profiled resources based on their calculated data sensitivity. Using these tags, you can configure IAM conditions that automatically grant or deny IAM access to resources based on the sensitivity of the data in those resources.
For more information, see Control IAM access to resources based on data sensitivity.
July 17, 2024
The ARMENIA_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
July 01, 2024
The BELARUS_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
June 28, 2024
Terraform support
You can now use Terraform to create and manage scan configurations. Terraform management of discovery scan configurations is supported for BigQuery data, Cloud SQL data, and secrets in Cloud Functions environment variables. For a detailed reference document about Terraform resources, see data_loss_prevention_discovery_config in the Terraform documentation.
June 27, 2024
The INDIA_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
If you set InfoType.version to latest when including the PHONE_NUMBER infoType in your InspectConfig, Sensitive Data Protection will now include US_TOLLFREE_PHONE_NUMBER findings as type PHONE_NUMBER in the scan results.
You can still use the old functionality by setting InfoType.version to stable or leaving it unset when using the PHONE_NUMBER infoType. In 30 days, the new functionality will be promoted to stable.
June 24, 2024
The RELIGIOUS_TERM infoType detector is available in Preview in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
A new detection model is available for the ORGANIZATION_NAME infoType detector. The new model offers improved detection quality. You can try it out by setting InfoType.version to latest when including the ORGANIZATION_NAME infoType in your InspectConfig.
You can still use the old model by setting InfoType.version to stable or leaving it unset when using the ORGANIZATION_NAME infoType. In 30 days, the new model will be promoted to stable.
June 21, 2024
The discovery service of Sensitive Data Protection now supports Cloud Storage. You can run discovery at the organization, folder, or project level to generate data profiles of your Cloud Storage buckets. Data profiles provide metrics and insights about the sensitivity and risk levels of your data to help you plan your data governance workflows.
To get started on profiling Cloud Storage data, see the following:
- Profile Cloud Storage data in a single project
- Profile Cloud Storage data in an organization or folder
For more information about sensitive data discovery, see Data profiles.
June 14, 2024
The AZERBAIJAN_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
June 10, 2024
A new detection model is available for the DATE_OF_BIRTH infoType detector. The new model offers improved detection quality. You can try it out by setting InfoType.version to latest when including the DATE_OF_BIRTH infoType in your InspectConfig.
You can still use the old model by setting InfoType.version to stable or leaving it unset when using the DATE_OF_BIRTH infoType. In 30 days, the new model will be promoted to stable.
June 07, 2024
From May 27 through June 7, 2024, a bug caused Sensitive Data Protection to sometimes inaccurately populate integer fields as null instead of zero for findings written to BigQuery. This bug is now resolved.
For more information about sensitive data inspection, see Inspect Google Cloud storage and databases for sensitive data.
June 06, 2024
The KAZAKHSTAN_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
May 23, 2024
The TRADE_UNION infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
May 17, 2024
The LOCATION infoType detection model that was previously only accessible by setting InfoType.version to latest has been promoted to be the default detection model for this infoType. The new model offers improved detection quality.
To use the new model, leave InfoType.version unset, or set it to latest or stable. To use the old detection model, set InfoType.version to legacy. You can continue to use the legacy model for 90 days.
May 13, 2024
The UKRAINE_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
The RUSSIA_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
The UZBEKISTAN_PASSPORT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
The IMMIGRATION_STATUS infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
April 25, 2024
A new detection model is available for the STREET_ADDRESS infoType detector. The new model offers improved detection quality. You can try it out by setting InfoType.version to latest when including the STREET_ADDRESS infoType in your InspectConfig.
You can still use the old model by setting InfoType.version to stable or leaving it unset when using the STREET_ADDRESS infoType. In 30 days, the new model will be promoted to stable.
April 02, 2024
If you opted to publish your data profiles to Security Command Center, you can configure Security Command Center to prioritize resources automatically according to the sensitivity of the data that the resources contain. For more information, see Set resource priority values automatically by data sensitivity.
If your discovery scan configuration isn't set to publish data profiles to Security Command Center, see Enable publishing to Security Command Center in an existing configuration.
March 28, 2024
The SWITZERLAND_SOCIAL_SECURITY_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
March 25, 2024
From February 12 through 27, 2024, a bug caused Sensitive Data Protection to inaccurately set the free-text scores of certain data profiles to 0, where they should have been higher. This bug is now resolved. All affected data profiles have been reprofiled.
For more information about the discovery service, see Data profiles.
March 22, 2024
The discovery and inspection services, which support BigQuery, now support tables that contain columns with INTERVAL, RANGE<DATE>, RANGE<DATETIME>, and RANGE<TIMESTAMP> data types.
For more information about sensitive data discovery, see Data profiles.
For more information about sensitive data inspection for BigQuery, see Inspect a BigQuery table.
March 07, 2024
The discovery service of Sensitive Data Protection now supports Cloud SQL. You can run discovery at the organization, folder, or project level to generate data profiles of your Cloud SQL tables. Data profiles provide metrics and insights about the sensitivity and risk levels of your data to help you plan your data governance workflows.
To get started on profiling Cloud SQL data, see the following:
For more information about sensitive data discovery, see Data profiles.
March 04, 2024
A new detection model is available for the LOCATION infoType detector. The new model offers improved detection quality. You can try it out by setting InfoType.version to latest when including the LOCATION infoType in your InspectConfig.
You can still use the old model by setting InfoType.version to stable or leaving it unset when using the LOCATION infoType. In 30 days, the new model will be promoted to stable.
February 27, 2024
An improvement was made in the way Sensitive Data Protection calculates the predicted infoType of the data that it profiles. The service now considers correlations between the detected infoTypes, where one infoType is a subset of another. For more information, see Predicted infoType.
For more information about data profiling, see Data profiles.
February 16, 2024
The HTTP_USER_AGENT infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
February 15, 2024
The BLOOD_TYPE infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
February 01, 2024
You can now configure your discovery scans to reprofile data when the inspection template changes. By default, inspection template changes do not cause the affected data to be reprofiled. For more information, see Frequency of data profile generation.
January 31, 2024
Sensitive Data Protection is now available in Johannesburg, South Africa (africa-south1 region).
For more information, see Sensitive Data Protection locations.
January 10, 2024
The FINANCIAL_ACCOUNT_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
November 21, 2023
For BigQuery inspection jobs, when you set a sampling limit based on a percentage of the total number of table
rows
(rowsLimitPercent),
Sensitive Data Protection can inspect more rows than expected. If you need to
put a hard limit on the number of rows to scan, we recommend setting a maximum
number of rows
(rowsLimit)
instead.
November 17, 2023
The sensitive data discovery service can now detect the presence of secrets, such as passwords and authentication tokens, in your Cloud Functions environment variables. Sensitive Data Protection sends any findings to Security Command Center as vulnerability findings. For more information, see Report secrets in environment variables to Security Command Center.
November 09, 2023
The following changes were made to the COUNTRY_DEMOGRAPHIC infoType detector:
- The sensitivity score was changed from
HIGHtoMODERATE. - The type category was changed from
PIItoDEMOGRAPHIC.
September 19, 2023
Sensitive Data Protection is available in me-central2 (Dammam). For more information, see Sensitive Data Protection locations.
September 14, 2023
Since August 12, 2023, there has been an increase in latency issues with inspection jobs and data profile generation. These latency issues have been resolved.
July 31, 2023
You can enrich your manually curated metadata in Dataplex with insights gathered from Sensitive Data Protection data profiles. When you export your data profiles to Dataplex, tags are automatically attached to the profiled BigQuery tables. The tags include the following insights:
- Information types (infoTypes) detected in the columns of the table
- Calculated sensitivity level of the table
- Calculated data risk level of the table
For more information, see Tag tables based on insights from data profiles.
July 14, 2023
The PORTUGAL_SOCIAL_SECURITY_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
June 28, 2023
The CROATIA_PERSONAL_ID_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
June 14, 2023
The subscription pricing mode for the discovery service is now generally available. This pricing mode offers predictable and consistent costs, regardless of your data growth. In subscription mode, you choose how much compute time (capacity) to reserve for profiling. There is no charge for bytes profiled in this pricing mode. For more information, see Discovery pricing.
May 22, 2023
The COUNTRY_DEMOGRAPHIC infoType detector, which identifies when countries are used for place of birth, residency, or citizenship, is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
May 04, 2023
The discovery service can now generate the following observation finding types in Security Command Center: