DataSafe — Personal Data Protection
Protection and anonymisation of personal data in CRM, HR and other corporate systems. DataSafe hides sensitive fields, controls disclosure and logs access without replacing business systems.
- Scope
- CRM, HR and related systems
- Deployment
- Local, without a public perimeter
- Regulatory framework
- Federal Law No. 152-FZ, Government Decree No. 1154, Federal Law No. 420-FZ
- Licensing
- Based on the number of environments and controlled users
Personal-data protection after stronger liability from 30 May 2025
Federal Law No. 420-FZ introduced turnover-based fines and a scale based on the size of a leak. At the same time, Article 272.1 of the Criminal Code applies, with up to ten years of imprisonment.
A data leak is no longer an IT incident that can be resolved quietly. The legal, financial and reputational consequences now reach the board level. DataSafe helps reduce risk before the data leaves the company: sensitive values are separated, access is controlled, and every disclosure is logged.
Where personal data really leaks
DataSafe closes three common leak scenarios that perimeter protection and a traditional SIEM cannot cover on their own.
A hacker enters the infrastructure and exports the database
A group enters through a vulnerability, phishing or a compromised contractor account. Then it exports tables with real personal data or encrypts systems and demands payment. Perimeter security detects the attack, but by then the data may already be gone.
At Gemotest, an employee account was compromised and 300 GB of data from up to 30 million customers was exported, including medical test results. At CDEK, a ransomware attack disrupted systems and destroyed backups. The issue is not only entry into the infrastructure but the value of the data available after entry.
- 01Sensitive fields are stored separately from the production database and are available only through DataSafe for targeted requests.Even after a full table export
- 02the attacker receives anonymised values rather than real personal data.Access is controlled by role
- 03scenario and signed requests
- 04and every disclosure is logged.
An employee or contractor with legitimate access
The user has access rights required for their role. They export data manually, through bulk reports or through an API. A traditional SIEM sees a legitimate login and does not know whether the request was justified.
A Sberbank department head exported and published a customer database. An MTS Bank branch manager sold data on 5,600 customers to fraudsters and received three and a half years in prison. In these cases, the attacker already had legitimate access.
- 01By default
- 02users see protected valuesrather than real data. Disclosure is allowed only in an explicit
- 03signed scenario.Every access to a sensitive field is logged with role
- 04purpose and time.Behavioural analytics identifies unusual volumes
- 05times and patterns and sends alerts to existing security tools.
Real data in test, demo and development environments
Real personal data is copied from production to a test environment so the team can verify functionality. Contractors, analysts and demo environments gain access. These environments usually have lower protection, which makes them a convenient leak channel.
This is one of the most common leak channels, created by companies themselves. Government Decree No. 1154 directly requires personal-data anonymisation when information systems are used for testing, training and demonstrations.
- 01Testtraining and demo environments receive anonymised data sets instead of real values. Structure and formats are preserved.Contractors and analysts work with the data model and do not gain access to personal data.DataSafe controls export
- 02creation and refresh of each data set.
Personal-data protection and anonymisation in corporate systems
Four functions that create a protected personal-data environment inside your systems—without replacing CRM or rewriting product code.
Hides sensitive fields completely
By default, users see protected fields rather than the values themselves. Disclosure depends on role and scenario and requires an explicit employee action.
Anonymises test and development environments
Test, demo and training environments receive anonymised sets instead of real personal data. Structure, types and relationships are preserved, so functionality is unaffected.
Logs requests without recording personal data
Every data request becomes traceable, but personal data itself never enters the log. The log provides context, not a second copy of the database.
Detects deviations and notifies security
Suspicious scenarios are identified through behavioural analytics and passed to existing monitoring and response tools: Splunk, MaxPatrol, KUMA and R-Vision.
How DataSafe masks data and controls disclosure
This is how everyday work with a customer or employee profile changes after DataSafe is connected.
Opening a profile
Users work in their familiar CRM, HR system or internal service. The interface does not change.
Fields are hidden by default
Sensitive fields appear fully protected, not partly masked with asterisks.
Viewing follows a rule
Disclosure depends on role, work scenario and request context. The action is explicit and signed by the user.
The action is logged
The request enters the log. If it differs from the role profile, a signal is sent to existing security tools.
Personal-data protection results for business, security and the team
These are not features but measurable effects for commercial, security and operational teams after DataSafe goes live.
Protection and compliance
Lower risk of a customer-database leak
Even if the database is compromised, the attacker receives anonymised values. Sensitive fields are stored separately and available only through DataSafe.
A protected layer in production
A separate personal-data access environment works within existing production systems, with a role model, visibility policy and access log.
Data management in test environments
Anonymised sets replace real records in test, demo and development. Compliance with Government Decree No. 1154 of 30 May 2025—without a separate project.
Making a breach worthless, even if it succeeds
An attacker who enters the infrastructure does not obtain real personal data. The value of the data falls to zero.
Investigation and control
Support for incident investigations
A complete access log linked to role, scenario and time. During an incident, evidence is ready in minutes instead of weeks of forensics.
Automated security control
Rules, behavioural analytics and dashboards. Security receives signals in existing SIEM/SOAR tools, not a separate product to administer.
Greater employee accountability
Every data disclosure is an explicit action with a signature and context. Transparency removes hidden access without putting pressure on the team.
Trust and reputation
Customer trust in personal-data processing
The ability to clearly tell a customer, regulator or auditor who accessed personal data, when and on what basis.
Operations and resilience
No 24/7 employee required
Control works automatically through rules, logs and signals, without a dedicated around-the-clock monitoring service or night shifts.
Support for testing in test environments
Anonymised sets preserve statistical properties, formats and relationships. Testing, demonstrations and training remain realistic without restrictions.
Does not disrupt existing business processes
Connects to existing CRM and HR systems through targeted integrations, without rewriting products or retraining the team.
Where personal-data protection works without stopping processes
Start with one environment where risk is high and the effect is easy to show to leadership and security. Then scale to the other systems.
Sales and customer service
Unnecessary viewing of customer profiles in CRM is reduced without slowing service. Managers work as before but see only what the scenario requires.
HR and internal services
Employee, candidate, contractor and internal-user data is protected in HR systems and self-service portals.
Support and contractors
Access becomes targeted, while every data request is traceable and auditable. External teams do not receive excessive rights.
Development and testing
Anonymised data is used instead of real records in test, training and demo environments. Contractors work with the structure, not with PII.
How the first stage starts
- 01
Choose an environment
Sales, HR, support or a test environment—where the risk of excessive access is highest and the effect is easiest to demonstrate.
- 02
Define fields and roles
Decide which fields are fully hidden and who may disclose them in each scenario and on what basis.
- 03
Connect the system to DataSafe
Configure writing, reading and hiding of values in the selected environment, without rewriting CRM or replacing product forms.
- 04
Connect security to the process
Configure the access log, control rules and dashboards for the security team. Send signals to existing SIEM/SOAR.
How DataSafe fits into the corporate data-protection environment
DataSafe works inside the company environment and exchanges data only between corporate systems. The solution has no direct access from the internet.
Internal environment without a public perimeter
Works with CRM, HR and integration systems through targeted connections. Calls run between systems and are not exposed externally.
Encrypted connections with signature verification
All interactions use protected internal channels with signature verification and time-window control.
Event log without personal-data records
The fact and context of access are recorded, but personal data itself never enters the log. The log does not become a second copy of the database.
Signals to existing security tools
Sends events to Splunk, MaxPatrol, KUMA, R-Vision and other SIEM/SOAR tools in standard formats, without a separate monitoring console.
Anonymisation for test and development
Test, training and demo environments receive anonymised data sets instead of real values, in accordance with Government Decree No. 1154.

What the solution closes in the working environment
Each scenario is a working environment where the solution delivers measurable value.
Sensitive-field catalogue
One model of what counts as personal data in CRM, HR and integration systems, with a managed visibility policy.
Hiding data from employees
Values are masked based on role, scenario and environment—without changing storage methods or rewriting the product.
Anonymised storage
A separate data environment for analytics and testing. It is not coupled with production systems and never returns real personal data.
Breaking the individual/company link
Separating people from identifiers in technical environments without losing business logic or process relationships.
Audit log and behavioural analytics
An end-to-end history of access to sensitive data, with anomaly detection and integration into existing SIEM/SOAR.
What often goes together
Ready to see DataSafe — Personal Data Protection on your data?
Thirty minutes with an engineer, no slides and no NDA for the demo.