Forum Discussion
PCI compliance and Tokenization
Hi All,
Hope someone can assist. We are in the banking industry and looking at some more info regarding PCI/POPI/GDPR and all of those Compliance related stuff. We have the sucurity whitepaper and this gives us a good idea of data at rest and all of that. We also implemented a User Acceptance Policy for all business units onboarded to the service to advise that if any of the above mentioned type of data is published to the service that they will be responsible for being in PCI scope.
However being the platform owners of PowerBI for the group we would probably still be held responsible for any PCI or other related data published to the service?
Last question, which I cannot find a topic on, is there any way to scan or check the gateway for PCI/POPI/GDPR related data? most of our datasources connects directly to the service. Only a few of them goes through our holding server.
Please let me know if more info is required.
Regards,
1 Reply
- AnonymousNot applicable
My expectation is that your data model itself would define what is going to be Privacy related data and where it fits into those regulatory frameworks.
Either your data is personality identifiable, or it is not. New data rows shouldn't impact that.
If the concern is where the data is phyicsally held, thats a different consideration, but again new data rows don't change this.
I would place all of this into your Data Modelling and Publishing process to assess what data you are storing and whether its personally identifiable data.