Overview
Solving Data Challenges: Compliance Made Easy for Life Insurance
165M+ records masked in Salesforce Sandbox ✅
Privacy regulations met ✅
All in less than 24 hours.
About Life Insurance Company
- Major life insurers in Australia and New Zealand
- $20B+ assets under management, 1M+ policies managed.
- Offers life insurance, superannuation, and retirement products
Challenge
- As one of the major insurers in Australia and New Zealand, it has a lot of data (like a lot) and wants its sandbox ready for business users in less than 48 hours.
- They wanted the same masking pattern as their other integrations for masking for non-salesforce solutions.
- Compliance with the Privacy Act 1988 and APRA.
How Cloud Compliance Helped?
They came up to us with these challenges, and here is how the DataMasker and Cloud Compliance teams helped them:
- Used SOQL Slicing to mask more records in sandbox in less time and run in parallel batches.
- Have Apex Action Masking to mask sandbox data in their desired pattern.
Results
- No more spending working hours on masking the sandbox. Get it done over the weekend and have it ready for business users by Monday.
- Consistent masking patterns across all systems to avoid the guessing game of what this data is.
Solutions Used
DataMasker for Salesforce Sandbox
Learn more about Sandbox DataMasker
Join the club
Secure your Salesforce Sandbox with DataMasker
Related Resources
How to Evaluate Salesforce Data Masking Tools: 12 Criteria That Matter
What Is a Data Processing Agreement (DPA)?
A Data Processing Agreement is not optional paperwork. GDPR Article 28(3) requires a written contract whenever a processor handles personal data on your behalf, and it specifies eight things that contract must cover. Most DPA reviews check that one exists and skip what it says.
What Is a DPIA (Data Protection Impact Assessment)?
A Data Protection Impact Assessment is a documented risk assessment carried out before high-risk processing begins. GDPR Article 35 makes it mandatory in defined cases, and several of those cases are triggered by things Salesforce teams do routinely, including deploying AI features over customer data.
What Is a Record of Processing Activities (RoPA)?
The Record of Processing Activities is the document a regulator asks for first. Article 30 sets out exactly what it must contain. The under-250-employee exemption sounds broad and turns out to cover almost nobody, because it excludes any processing that is regular rather than occasional.
What Is a Sub-Processor?
Controller, processor, sub-processor is a chain of responsibility, and GDPR Article 28 governs how each link is authorised and contracted. Every vendor that touches personal data on your behalf becomes a link, which is why adding tools has a compliance cost that is separate from their licence fee.
Learn More About Cloud Compliance
Explore our native Salesforce data privacy products.