Data Privacy & Compliance FAQs
Privacy & Compliance Essentials
Why is data privacy important?
Three reasons that show up on the P&L.
Regulatory exposure. GDPR fines reach €20 million or 4% of global annual turnover, and violations of the data subject rights provisions sit in that top tier rather than the lower one.
Operational cost. Manual handling of access and deletion requests consumes legal and engineering time that scales linearly with request volume — and request volumes have risen every year for five consecutive years.
Commercial trust. Enterprise buyers, particularly in financial services and healthcare, now assess privacy posture during vendor selection. Weak controls cost deals, not just fines.
What is personal data?
Personal data is any information relating to an identified or identifiable person — a name, email address, phone number, account number, IP address, device identifier or location record.
Under GDPR the test is whether a person can be singled out, directly or indirectly, from that information alone or combined with other data the organisation holds. That last clause is the one teams underestimate: fragments that look anonymous in isolation frequently become personal data once they can be joined to another table.
What is personally identifiable information (PII)?
PII is the subset of personal data that identifies a specific individual, either on its own or in combination with other records — full name, Social Security number, driver's licence number, passport number, financial account numbers.
"PII" is the term used most often in US law and security standards; "personal data" is the broader European concept. Most enterprise privacy programmes end up protecting both, because the wider definition sets the compliance obligation while the narrower one concentrates the breach risk.
What is sensitive data?
Sensitive data is information that could cause harm, discrimination or financial loss if exposed.
Most privacy regimes single out a defined set as special-category data: health and medical records, biometric and genetic data, racial or ethnic origin, religious belief, political opinion, trade union membership, sexual orientation, and precise geolocation. California adds a right to limit the use of sensitive personal information as a standalone consumer right.
Processing it generally requires a stronger legal basis than ordinary personal data, and the consequences of mishandling it are correspondingly higher.
What is the difference between redaction, masking and anonymisation?
They solve different problems and are not interchangeable.
Redaction permanently removes or obscures sensitive elements from a record so they cannot be recovered. Use it when data is leaving the organisation — disclosure, publication, DSAR responses, regulatory submissions.
Masking substitutes realistic but fictitious values that preserve the format and behaviour of the original, so applications and tests still function. Use it for non-production environments.
Anonymisation goes furthest, irreversibly removing any means of re-identification. Properly anonymised data generally falls outside the scope of privacy law altogether — but the bar is higher than most teams assume, and weakly anonymised datasets have repeatedly been re-identified.
Data Safeguard provides redaction through ID-REDACT® and masking through ID-MASK®.
What is data discovery and classification?
Data discovery is the process of finding where personal and sensitive data actually lives — across databases, warehouses, data lakes, file shares and collaboration tools, including the copies nobody documented. Classification then labels what was found by type and sensitivity.
Everything else in a privacy programme depends on this step. You cannot honour a deletion request, scope a breach, complete an impact assessment or evidence compliance for data you cannot locate. In most enterprises the gap between the data inventory on paper and the data actually present is the single largest source of privacy risk.
Data Safeguard provides this as Confidential Data Discovery, one of the eight modules of ID-PRIVACY®.
What is the difference between structured, semi-structured and unstructured data?
Structured data sits in defined rows and columns, typically in databases and warehouses. Semi-structured data carries tags or markers but no fixed schema — JSON, XML, log files. Unstructured data has no predefined model at all: documents, spreadsheets, presentations, PDFs, email bodies, chat transcripts.
The distinction matters commercially, not just technically. Most privacy tooling handles structured data well and unstructured data poorly — yet unstructured stores are typically where the majority of an enterprise's personal data actually sits. A discovery programme that only covers databases will report a clean bill of health while leaving the largest exposure untouched.
Data Safeguard's products are built to operate across all three.
Which privacy regulations does Data Safeguard support?
Compliance capabilities cover GDPR, CCPA and CPRA, HIPAA, India's DPDP Act, PDPA, NESA, and the NIST privacy and cybersecurity frameworks.
The design intent behind the compliance rules engine is that one set of controls maps to several regimes at once, rather than running a separate programme per regulation. That is increasingly the only workable approach: an enterprise operating in the US, EU and India now faces three overlapping consent regimes and three different response deadlines for what is functionally the same request.
What is the GDPR, and does it apply to us if we are not in Europe?
The General Data Protection Regulation governs the processing of personal data belonging to people in the EU and EEA.
It applies extraterritorially. If you offer goods or services to people in the EU, or monitor their behaviour, you are in scope regardless of where your company is established or where your servers sit. Having no European entity is not a defence.
Penalties run to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious breaches — a category that explicitly includes violations of the data subject rights provisions in Articles 12 to 22. Cumulative GDPR fines have passed €7 billion since 2018.
What is the CCPA, and what did CPRA change?
The California Consumer Privacy Act gives California residents rights to know, delete, correct and opt out of the sale or sharing of their personal information.
The California Privacy Rights Act extended it in two significant ways: it added the right to limit the use of sensitive personal information, and it created a dedicated regulator — the California Privacy Protection Agency, which now operates publicly as CalPrivacy.
Operationally: respond to consumer requests within 45 days, extendable once by a further 45, with receipt acknowledged inside 10 business days. Businesses must also honour the Global Privacy Control browser signal as a valid opt-out. New regulations covering risk assessments, cybersecurity audits and automated decision-making technology took effect on 1 January 2026.
How many US states have comprehensive privacy laws?
Twenty have comprehensive consumer privacy laws in effect as of September 2026 — or nineteen, depending on whether you count Florida's Digital Bill of Rights, which only reaches companies above $1 billion in global revenue and is materially narrower than the rest. Trackers disagree on this point, so treat any single number with care.
Indiana, Kentucky and Rhode Island took effect on 1 January 2026. Three more are enacted but not yet in force: Oklahoma and Louisiana on 1 January 2027, and Alabama on 1 May 2027.
There is still no comprehensive federal privacy law, and no serious prospect of one in the near term — which means multi-state compliance by patchwork remains the operating reality.
What is India's DPDP Act, and what is the compliance deadline?
The Digital Personal Data Protection Act 2023 is India's comprehensive privacy law. Its implementing rules were notified on 14 November 2025 and phase in over eighteen months:
14 November 2025 — Data Protection Board of India established; definitions in force.
13 November 2026 — Consent Manager framework becomes operational.
13 May 2027 — full compliance with all Data Fiduciary obligations.
Consent must be free, specific, informed and unambiguous, presented in a standalone itemised notice in clear plain language, available in English and the 22 languages of the Eighth Schedule. Withdrawal must be as easy as giving consent. Breaches require a detailed report to the Board within 72 hours, and penalties reach ₹250 crore for failing to maintain reasonable security safeguards.
What does HIPAA require, and is the Security Rule changing?
HIPAA governs protected health information held by covered entities and their business associates. It requires administrative, physical and technical safeguards, and gives individuals a right of access with a 30-day response deadline, extendable once by a further 30 days.
HHS proposed a substantial Security Rule update in December 2024 — adding mandatory multi-factor authentication, encryption at rest and in transit, asset inventories and annual audits, and removing the "addressable" versus "required" distinction that has let organisations justify weaker controls.
That rule has not been finalised. It drew over 4,700 comments and heavy provider opposition on cost grounds, and the regulatory agenda now points to 2027. The current Security Rule remains in force. Treat the proposed requirements as a direction of travel to prepare for, not an obligation to comply with today.
Does the EU AI Act affect our privacy programme?
Yes — and the timeline moved in 2026, which is the single most common thing for guidance material to get wrong.
Already in force: prohibited practices and AI literacy obligations since February 2025; general-purpose AI model obligations since August 2025; general applicability of the Act from 2 August 2026.
Still ahead: the AI Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — pushed the high-risk deadlines back. Annex III stand-alone high-risk systems, which include recruitment, credit scoring and education, now apply from 2 December 2027. Annex I systems embedded as safety components in regulated products apply from 2 August 2028.
Anything written before mid-2026 will tell you high-risk obligations bit on 2 August 2026. They did not.
What are the penalties for non-compliance?
They vary by regime, and they are rising.
GDPR reaches €20 million or 4% of worldwide turnover. Cumulative fines have passed €7 billion since 2018.
California enforcement has escalated sharply: a $12.75 million settlement with General Motors in May 2026 over the sale of driver location data, and a $1.35 million order against Tractor Supply in September 2025.
India's DPDP Act provides for penalties up to ₹250 crore for failing to maintain reasonable security safeguards.
The pattern worth noting is what actually draws enforcement. It is rarely an exotic breach. It is ordinary operational failure — opt-out mechanisms that do not work, consent signals that go unread, and data retained past the point of need.
Your Data, Your Rights
What is a Data Subject Access Request (DSAR)?
A DSAR is a request from an individual to see the personal data an organisation holds about them — and often to have it corrected, deleted, restricted or ported elsewhere.
Most modern privacy laws grant the right under slightly different names. GDPR calls it a data subject access request. CCPA calls it a consumer request. India's DPDP Act frames it as data principal rights.
The name varies; the work does not. Fulfilling one means locating every copy of that person's data across every system, verifying that the requester is who they claim to be, removing third-party information from the response, and delivering it inside a statutory deadline.
How long do we have to respond to a DSAR?
It depends on the regime, and the differences are large enough that a single internal SLA rarely works.
GDPR — one month, extendable by two further months for complex or numerous requests. You must notify the individual and give reasons within the first month; no permission from a regulator is needed.
CCPA / CPRA — 45 days, extendable once by a further 45, with receipt acknowledged inside 10 business days.
HIPAA right of access — 30 days, with one 30-day extension. Only one extension is permitted.
India DPDP Act — grievances must be answered within 90 days.
In the UK, the Data Use and Access Act now formally allows the clock to stop while you await clarification of scope or identity — a practical concession that does not exist in the same form under GDPR.
What rights do individuals have over their personal data?
Under GDPR: access, rectification, erasure, restriction of processing, data portability, objection, and the right not to be subject to solely automated decision-making producing legal or similarly significant effects.
Under CCPA and CPRA: know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, non-discrimination for exercising rights, and rights regarding automated decision-making technology.
Under India's DPDP Act: access, correction, completion, updating, erasure, grievance redressal — plus a right of nomination, allowing someone to designate another person to exercise their rights on their behalf. That one has no direct equivalent in EU or US law.
The lists differ in detail but converge on the same core: see it, fix it, delete it, stop it being sold.
Why are DSARs so expensive to handle manually?
Because the work is search, not paperwork.
Each request requires finding every instance of one person's data across databases, file shares, email, chat systems and backups — then reviewing what came back and removing other people's information before anything is disclosed. Neither step compresses well with more headcount.
Published research puts the manual cost at roughly $1,500 per request (Gartner, 2023, as cited by DataGrail). Volumes keep climbing: DataGrail's 2026 analysis reports a fifth consecutive annual increase, with deletion requests now the overwhelming majority of all requests received.
Cost therefore scales linearly with volume unless the search and redaction steps are automated. That is the whole economic case for automation — not speed for its own sake.
Note: these figures are published by privacy-automation vendors and should be read with that in mind.
How does Data Safeguard automate DSAR fulfilment?
DSAR handling is one of the eight modules of the ID-PRIVACY® platform, covering intake through to secure fulfilment.
It draws on the same discovery and classification engine used elsewhere in the platform to locate the requester's data across structured, semi-structured and unstructured sources — including the document repositories and email archives that manual processes tend to miss. ID-REDACT® then removes third-party and non-disclosable information before the response goes out.
The point is to compress the two steps that make manual fulfilment slow: exhaustive search, and pre-disclosure review.
Does a DSAR response need to be redacted?
Almost always. A person is entitled to their own personal data, not to other people's.
Files, email threads, call notes and case records routinely contain information about colleagues, customers or third parties that must be removed before disclosure — alongside anything covered by legal privilege or trade secret protection.
This is the step that makes manual DSAR fulfilment both slow and genuinely risky. Over-redact and you have failed to satisfy the request. Under-redact and you have caused a personal data breach in the act of answering one. Neither error is recoverable once the response has been sent.
What is consent management?
Consent management is the practice of capturing, storing, evidencing and honouring people's permissions for how their personal data is used — and making withdrawal as easy as the original agreement.
In practice it comes down to three things: a durable record of who consented to what, when, and against exactly which wording; reliable propagation of changes to every downstream system relying on that permission; and the ability to produce that evidence on demand when a regulator asks.
The third is where most programmes fail. Collecting consent is straightforward. Proving two years later that a specific person saw a specific notice and agreed to a specific purpose is not.
What makes consent valid?
Under GDPR, consent must be freely given, specific, informed and unambiguous, expressed through a clear affirmative action. Pre-ticked boxes, silence and inactivity do not count. Withdrawal must be as easy as giving consent in the first place.
Under India's DPDP Rules, the notice must additionally be standalone and itemised, written in clear plain language, presented separately from other text, and available in English and the 22 languages of the Eighth Schedule.
In both regimes the burden of proving valid consent sits with the organisation, not the individual. That is why the record matters as much as the collection — consent you cannot evidence is, for enforcement purposes, consent you do not have.
What does Universal Consent Management in ID-PRIVACY® do?
Universal Consent Management is the ID-PRIVACY® module that collects, stores and manages your customers' permission to use their personal data.
Data Safeguard describes it through three characteristics:
Clear and transparent — people understand what they are agreeing to.
Flexible consent control — individuals choose which categories of data they are willing to share, rather than facing an all-or-nothing decision.
Centralised and automated management — consent status is recorded and updated in real time, and withdrawal is available at any time.
What is a Consent Manager under India's DPDP Rules, and do we need to become one?
Almost certainly not — and this is a genuinely common misreading of the DPDP Rules.
A registered Consent Manager is a specific regulated entity: a company incorporated in India, with minimum net worth of ₹2 crore evidenced by audited financials, registered with the Data Protection Board, operating interoperable consent infrastructure that serves multiple Data Fiduciaries — and never accessing the underlying personal data itself.
Most businesses need a consent management capability for their own processing. That is a different thing entirely and carries no registration requirement. Registration applies only if you intend to run consent infrastructure as a service for others.
One practical caveat: as of mid-2026 the Data Protection Board was still being staffed, so whether the registration machinery is fully operational by the 13 November 2026 date remains an open question worth monitoring.
Do we have to honour Global Privacy Control signals?
In California, yes. The CCPA regulations require businesses to treat the Global Privacy Control browser signal as a valid opt-out of the sale or sharing of personal information.
This has quietly become one of the most heavily enforced provisions in US privacy law. Failure to honour opt-out signals featured prominently in the $1.35 million Tractor Supply order and runs through the wider CalPrivacy enforcement programme.
It is also one of the easiest things for a regulator to test. A privacy policy that promises opt-out rights while the signal goes unread is a well-understood and trivially verifiable enforcement target — no complaint or breach required.
Platform, Security & Pricing
What is ID-PRIVACY®?
ID-PRIVACY® is Data Safeguard's unified privacy automation platform.
Rather than a single tool, it bundles eight capability areas that together cover the operational privacy lifecycle — from finding sensitive data, through managing consent and fulfilling individual rights requests, to responding when something goes wrong.
It runs on CCE®, the company's underlying AI engine, which is shared with ID-REDACT®, ID-MASK®, ID-FRAUD® and ID-AML®. That shared foundation is why detection and classification behave consistently whether the use case is a privacy request or a fraud investigation.
What are the eight modules of ID-PRIVACY®?
Eight, designed to work together rather than as separate tools:
1. Universal Consent Management — collecting, recording and honouring permissions.
2. Confidential Data Discovery — finding where sensitive data actually lives.
3. Privacy Impact Assessment — evaluating risk before processing begins.
4. Data Subject Access Request handling — intake through to secure fulfilment.
5. Confidential Data Redaction and Masking — removing or substituting sensitive values.
6. Compliance Audit — evidencing controls against regulatory requirements.
7. Data Privacy Management — day-to-day programme governance.
8. Data Breach Management — incident response and notification.
The dependencies matter: discovery feeds DSAR fulfilment, redaction feeds disclosure, and the compliance audit module draws its evidence from all of them.
What is a Privacy Impact Assessment, and when is one required?
A PIA — called a Data Protection Impact Assessment under GDPR — is a structured evaluation of the privacy risk in a processing activity, carried out before the processing starts.
Under GDPR, one is required where processing is likely to result in high risk to individuals: large-scale profiling, systematic monitoring of publicly accessible areas, or large-scale processing of special-category data.
In California, the new regulations require risk assessments for selling or sharing personal information, processing sensitive personal information, and using automated decision-making technology for significant decisions. Those obligations took effect on 1 January 2026; the first submissions to CalPrivacy are due 1 April 2028 and annually each 1 April thereafter.
ID-PRIVACY® includes a Privacy Impact Assessment module.
What is CCE®, the Cognoscible Computing Engine?
The Cognoscible Computing Engine is Data Safeguard's underlying AI capability — described by the company not as a single technology but as a combination of models and deep learning.
It is the shared engine beneath ID-REDACT®, ID-MASK®, ID-FRAUD®, ID-AML® and the Data Science Lab. The practical consequence of that shared foundation is consistency: the entity detection that identifies a national identifier for redaction is the same capability that recognises it being reused across fraudulent applications.
What is ID-REDACT®?
ID-REDACT® is Data Safeguard's redaction product. It uses artificial intelligence and machine learning to detect, identify, confirm, tag and redact personally identifiable and other sensitive information across large volumes of data.
The distinguishing characteristic is coverage: it operates on unstructured and semi-structured content — documents, spreadsheets, presentations, PDFs, email and chat — not only on database fields. That matters because unstructured stores are where the bulk of enterprise personal data usually sits, and where most privacy tooling reaches least well.
How does ID-REDACT® work?
It analyses the dataset to locate sensitive and personally identifiable elements — names, addresses, national identifiers, payment card numbers and similar — then applies machine learning models and contextual rules to remove what it has identified while preserving the integrity and accuracy of everything else.
The contextual step is what separates it from pattern matching. The same nine-digit string can be a Social Security number in one document and an order reference in another; context is what tells them apart, and getting that wrong in either direction is expensive.
What types of data can ID-REDACT® be applied to?
All three data shapes — structured, semi-structured and unstructured. In practice that means:
Historical stores — databases, data warehouses and data lakes.
Individual files — PDF, Word, Excel, PowerPoint and CSV.
Real-time channels — email, chat, web forms and web logs, with integration available for Outlook, Exchange and Office 365.
Document repositories — local desktops and laptops, network file shares, SharePoint, Documentum, Google Drive, OneDrive, Box and Dropbox.
What are the benefits of using ID-REDACT®?
Three practical ones.
It reduces breach surface area. Data that has been redacted cannot be exposed in an incident, so the volume of recoverable PII in any given store falls.
It makes disclosure safe. DSAR responses, regulatory submissions, analytics extracts and vendor handoffs can go out without leaking third-party information alongside the intended content.
It produces evidence. A documented, repeatable redaction process is what an auditor asks for when testing controls under GDPR, CCPA or HIPAA — ad-hoc manual redaction is difficult to evidence and impossible to prove consistent.
What are the D-TR, DI-TR and DIC-TR tiers?
They describe how far the processing pipeline goes before redaction happens.
D-TR — Detects, Tags and Redacts.
DI-TR — adds an Identification step.
DIC-TR — adds a Confirmation step before redaction.
The confirmation stage is what reduces false positives on ambiguous matches, which is why it matters most on high-volume unstructured content where a naive match rate would generate unusable output.
The self-serve Customer API is sold across all three tiers. Enterprise On-Premise, Enterprise Cloud, Marketplace API and eCommerce deployments all ship the full DIC-TR pipeline.
What is ID-MASK®, and when should we use it instead of redaction?
ID-MASK® intelligently masks sensitive data across structured, semi-structured and unstructured sources, substituting values with realistic, functional but fictitious equivalents that preserve the format and behaviour of the original.
Use masking for non-production environments — development, sandbox, system integration testing, user acceptance testing and training — where teams need data that behaves like production without exposing real people.
Use redaction when data is leaving the organisation or being disclosed, because redaction removes rather than substitutes.
The failure mode worth avoiding is using neither: copying production data into a test environment is one of the most common and least defensible sources of enterprise privacy exposure.
What is Synthetic Fraud?
Synthetic identity fraud is the creation of an entirely new identity by combining real and fabricated information — typically a genuine national identifier paired with a fictitious name, date of birth or address.
The resulting "Frankenstein" identity belongs to no real person. That is precisely what makes it effective: with no genuine individual attached to the account, there is no victim to notice unfamiliar activity and report it. The fraud can therefore run for years before anyone looks.
How does synthetic fraud work?
A fraudster assembles the identity, then applies for low-value credit and — counterintuitively — uses it responsibly.
Each on-time payment builds a credit file that looks increasingly legitimate, and credit limits rise accordingly. This cultivation phase commonly runs for months or years. The scheme then ends in a "bust-out": every available line is drawn down simultaneously and the identity is abandoned.
Because the identity was never real, collections have nobody to pursue and the loss lands entirely with the lender.
Why is synthetic fraud difficult to detect?
Because it defeats controls that assume a real person is either present or absent.
The national identifier is genuine, so verification succeeds. The credit history is real, because the fraudster built it deliberately over months or years. And no consumer ever disputes the account, so the early-warning signal that catches most identity theft never fires.
Traditional identity verification is designed to detect the impersonation of a real person. Synthetic fraud impersonates nobody, so there is nothing for those controls to catch.
How can financial institutions detect synthetic fraud?
By looking at patterns rather than credentials.
Effective approaches combine behavioural analytics, machine learning models trained on known synthetic profiles, cross-application linkage analysis that surfaces identifiers, addresses or devices reused across supposedly unrelated applicants, and scrutiny of thin or anomalously recent credit files attached to older identifiers.
The signal is rarely present in any single application. It lives in the relationships between applications, which is why detection has to operate across the portfolio rather than at the point of origination alone.
What are ID-FRAUD® and ID-AML®?
ID-FRAUD® is Data Safeguard's flagship product for countering synthetic fraud. It is built to classify, identify, confirm and report on genuine customers versus Frankenstein identities, with named use cases across credit card, auto loan, personal loan and boat loan applications.
ID-AML® is an AI and machine learning product suite that detects and identifies risk for anti-money laundering purposes, supporting Customer Identification Program, Know Your Customer, Customer Due Diligence, Enhanced Due Diligence and High Risk Customer Analysis programmes.
Both run on the same CCE® engine as the privacy products, which is why an institution can apply one detection capability to fraud and privacy obligations rather than procuring two.
How can Data Safeguard be deployed?
Five models, chosen mainly by where your data is allowed to sit.
Enterprise On-Premise — the software runs inside your own data centre.
Enterprise Cloud — runs within your own cloud environment.
Customer API — self-serve SaaS; data is uploaded to Data Safeguard's cloud environment.
Marketplace API — deployed into your cloud environment via a cloud marketplace.
eCommerce storefront — self-serve, for individual document redaction.
Enterprise deployments include 12 months of support. The Customer API carries a 3-hour response commitment; the eCommerce tier is email support on an 8-hour SLA.
Can we keep data inside our own environment?
Yes. Under Enterprise On-Premise, your data and applications stay in your data centre. Under Enterprise Cloud, they stay in your cloud environment. In both cases the software is brought to the data rather than the data being sent out.
This is usually the deciding factor for regulated buyers in financial services, healthcare and government, where data residency and sovereignty constraints rule out uploading content to a vendor's environment at all — regardless of how well that environment is secured.
The self-serve Customer API and eCommerce storefront work the other way: data is uploaded to Data Safeguard's cloud for processing. Choose accordingly.
What data sources and repositories can be connected?
Historical stores — databases, data warehouses and data lakes.
Real-time channels — email, chat, web forms and web logs, with integration available for Outlook, Exchange and Office 365.
Individual files — PDF, Word, Excel, PowerPoint and CSV.
Document repositories — local laptops and desktops, network file shares, SharePoint, Documentum, Google Drive, OneDrive, Box and Dropbox.
If a specific source in your estate is not listed here, ask — scoping the actual data channels in play is part of any enterprise evaluation.
Is Data Safeguard available on cloud marketplaces?
Yes — ID-REDACT® is listed on the Microsoft Azure Marketplace and Microsoft AppSource.
For organisations with an existing Microsoft commercial agreement, that route can shorten procurement considerably, since the purchase runs through a vendor relationship that is already approved rather than requiring a new one.
Which industries does Data Safeguard serve?
Five core verticals: financial services, healthcare, government, retail and technology.
Each carries a different regulatory profile, which shapes what a deployment actually has to do:
Financial services — GDPR, CCPA, NIST, and DPDP for Indian operations.
Healthcare — HIPAA first, alongside GDPR, NIST and CCPA.
Government — GDPR and DPDP.
Retail — GDPR, NIST, CCPA and DPDP.
Technology — GDPR, CCPA, NIST and DPDP.
What security certifications does Data Safeguard hold?
Data Safeguard's information privacy management systems are assessed by accredited independent auditors. Current assurances are:
SOC 2 Type 1 and Type 2 reports
ISO/IEC 27001 — information security management
ISO/IEC 27701 — privacy information management
Quarterly VAPT — vulnerability assessment and penetration testing
SOC 2 is an attestation performed under AICPA standards rather than a certification, and the ISO references relate to Data Safeguard's management systems within their stated scope.
Current reports and certificates are available to prospective customers under a mutual NDA — contact us to request them.
Where does processing happen, and does our data leave our environment?
It depends entirely on the deployment model, and this is worth settling early in any evaluation.
Enterprise On-Premise and Enterprise Cloud — processing happens inside your own infrastructure. Content does not leave it.
Customer API and eCommerce storefront — data is uploaded to Data Safeguard's cloud environment for processing.
If data residency or sovereignty is a hard constraint for your programme — as it typically is in regulated sectors and for EU or Indian personal data — the enterprise deployment models are the relevant options and the self-serve tiers are not.
How is Data Safeguard priced?
Self-serve tiers are published.
Customer API — $99/month for D-TR, $199/month for DI-TR, $299/month for DIC-TR.
eCommerce storefront — $49 monthly, or $429 annually.
Enterprise deployments are quoted. Enterprise On-Premise, Enterprise Cloud and Marketplace API pricing depends on use cases, data channels and usage volume, so it is scoped during evaluation rather than listed. Contact us for a quote.
Is there a free trial, and how do we get started?
To test redaction quality: the eCommerce storefront includes a 7-day free trial covering one document per day. No sales conversation required — run it against your own material and judge the output yourself.
For an enterprise evaluation: contact us to arrange a demo and scoping conversation. The useful version of that conversation covers three things — which data sources are actually in scope, what your deployment and residency constraints are, and which regulatory regimes you have to satisfy. Those three answers determine most of the rest.