Data Access Management > Introduction to Data Access Management > Data access policy enforcement methods
  

Data access policy enforcement methods

As a Data Steward, it's important that you know where enforcement occurs for each type of policy that you create in Data Access Management. Data Access Management works with other Informatica services to protect data and provide access to it.
The following diagram shows how policies that you create in Data Access Management protect data in Data Integration mappings, Data Marketplace orders, and natively in your cloud data platforms:
The diagram has four rows. The second row shows a Data Steward defining, creating, and approving policies and rules. An arrow points to the top row where a Data Integration Developer creates a mapping to deliver protected data. Another arrow points from the second row to the third bottom row where a Data User shops for data, orders data, and accesses protected data in Data Marketplace. Another arrow points from the second row to the bottom row where a Data User queries data and accesses it in a protected cloud data platform.
When a Data User uses Data Marketplace to place an order with the Managed Access setting turned on, Data Marketplace enforces data filter policies and data de-identification policies created in Data Access Management according to the usage specified in the Data Marketplace order.
For more information about placing orders, see Ordering data collections.
When you use Data Integration to build a data pipeline, you can connect an Access Policy transformation to the mapping. The Access Policy transformation applies data filter policies and data de-identification policies created in Data Access Management according to the properties of the Access Policy transformation.
For more information about Access Policy transformations, see Access Policy transformation.
Policy Type
Enforcement Environment
data filter policy
In Data Integration through Access Policy transformations and in Data Marketplace through the Managed Access setting in a delivery template.
data de-identification policy
In Data Marketplace through the Managed Access setting in a delivery template.
For more information about the Managed Access setting, see Manage access to data with Data Access Management.
data access control policy
In your source system after policy pushdown from Data Access Management.
You can enforce data access control policies in Databricks, Microsoft Power BI, and Snowflake source systems.
For more information about configuring Databricks, Microsoft Power BI, and Snowflake for use with data access control policies, see Data access control policy prerequisites.