Join our Newsletter — 33% off our NHI Course

Data-centric privacy

Data-centric privacy is an approach that starts with discovering, classifying, and securing sensitive data before layering governance workflows on top. It treats data visibility as the basis for effective privacy and security controls, especially where information moves across many systems.

Expanded Definition

Data-centric privacy is a privacy and security model that begins with the data itself: where sensitive information lives, how it is classified, who can access it, and how it moves across applications, cloud services, endpoints, and third-party workflows. Rather than relying only on perimeter controls or one-time policy statements, it treats visibility into data flows as the foundation for enforcing purpose limitation, access control, retention, masking, and monitoring. That makes it especially relevant in environments where data is fragmented across SaaS platforms, collaboration tools, data lakes, and AI-enabled systems.

In practice, data-centric privacy overlaps with data governance, classification, and security engineering, but it is narrower than broad privacy programs because it focuses on operational control of sensitive data. The model aligns well with control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls, where protection depends on identifying information types and applying safeguards proportionate to risk. It also supports GDPR obligations around data minimisation, access limitation, and accountability under the EU General Data Protection Regulation (GDPR).

The most common misapplication is treating data-centric privacy as a reporting exercise, which occurs when organisations inventory data but fail to connect classification to enforceable controls.

Examples and Use Cases

Implementing data-centric privacy rigorously often introduces operational friction, requiring organisations to balance stronger control over sensitive data against the complexity of keeping business workflows usable.

  • A healthcare provider classifies patient records, then applies field-level masking in analytics and stricter access controls in case-management tools.
  • A financial institution discovers cardholder data in file shares and collaboration platforms, then reduces exposure by limiting retention, encrypting archives, and monitoring transfers.
  • A SaaS company maps personal data across product telemetry, support tickets, and CRM records, then applies purpose-based access rules and deletion workflows for subject requests.
  • An enterprise using AI assistants identifies when prompts or retrieved documents contain sensitive data, then blocks unnecessary disclosure before content enters downstream model workflows.
  • A multinational business creates a data catalog tied to policy tags so teams can locate regulated information before sharing it with vendors or moving it across borders.

These use cases are strongest when discovery, classification, and enforcement are linked, not treated as separate projects. Guidance in the NIST control catalogue reinforces that privacy outcomes depend on implementing safeguards around the data asset, not merely documenting it.

Why It Matters for Security Teams

Security teams need data-centric privacy because most privacy failures happen when sensitive data is unknown, overexposed, or copied into places that were never designed to protect it. Once data moves through cloud apps, automation pipelines, and external collaboration channels, coarse access policies are rarely enough. A data-centric model helps teams reduce unnecessary exposure, support lawful processing, and prove that controls are working across the full data lifecycle.

This becomes increasingly important where identity and data intersect. Non-human identities, service accounts, and AI agents often access high-value datasets at machine speed, which means privacy control must extend beyond human users to systems that read, transform, and redistribute data. In those environments, the question is not only who can log in, but what data is reachable, what can be exported, and whether the access was appropriate for the stated purpose.

Organisations typically encounter the operational cost of weak data-centric privacy only after a breach, regulatory inquiry, or discovery request, at which point data location, access history, and retention controls become operationally unavoidable to reconstruct.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.DS PR.DS covers data security practices that support privacy through protection of information assets.
NIST SP 800-53 Rev 5 RA-2 Risk assessment underpins identifying sensitive data and choosing proportionate safeguards.
NIST SP 800-63 Digital identity assurance informs who may access protected data and under what strength of authentication.
OWASP Non-Human Identity Top 10 NHI guidance is relevant where service accounts or agents access sensitive data.
NIST AI RMF AI RMF applies when data-centric privacy is used to govern data entering AI and agentic workflows.

Apply data classification, protection, and monitoring to sensitive information across its lifecycle.