Ketch and AWS Glue

Discover personal data across a data catalog and the storage it actually points to, not just the metadata layer alone.

AWS Glue

About AWS Glue

The AWS Glue Data Catalog organizes metadata about data stored elsewhere, most often in Amazon S3, which means discovering personal data here means reaching two things at once: the catalog's own database and table definitions, and the actual objects in S3 those definitions describe.

Ketch connects to AWS Glue through a Ketch Transponder to discover across both layers.

Capabilities

How Ketch works with AWS Glue

Discovery

Automatically finding Glue databases, tables, and columns from the Data Catalog. Requires two categories of scoped IAM permissions. Glue-specific permissions (`GetDatabases`, `GetDatabase`, `GetTables`, `GetTable`, `GetPartitions`, `GetPartition`, `GetTableVersion`, `GetTableVersions`) provide read access to catalog metadata. Separately, S3 permissions (`ListBucket` and `GetObject`) scoped to the specific bucket and path prefixes used by the catalog's databases give access to the underlying data those catalog entries describe.

With Ketch, teams can

  • Discover both Glue Data Catalog metadata and the underlying S3 data it references, in one connected discovery process
  • Scope S3 access to specific bucket paths rather than granting broad account-wide storage access
  • Fold Glue-cataloged data into the same Data Mapping workflows used for every other connected system

The gap

The problem this integration solves

A data catalog is only as useful for privacy purposes as the ability to reach both the metadata and the actual data behind it:

01. Metadata-only discovery tells you what a table is supposed to contain, not necessarily confirms personal data actually lives there

02. Granting broad, account-wide S3 access for a discovery tool creates unnecessary security exposure

03. Manually cross-referencing Glue catalog entries against the specific S3 paths they describe doesn't scale

Ketch resolves this by connecting to both layers with permissions scoped specifically to the catalog databases and their corresponding S3 paths.

Why Ketch

Why teams choose Ketch for AWS Glue privacy compliance

Permissioning infrastructure that governs AWS Glue the same way it governs every other system in your stack — not a one-off connector bolted onto a banner.

  • Reaches both metadata and underlying data

    Discovery isn't limited to catalog definitions alone; it extends to the S3 objects those definitions describe.

  • Backed by enforcement precedent

    Regulators increasingly expect businesses to prove technical enforcement, not just describe it on paper, the same underlying expectation that applies to knowing what personal data a data lake holds.

Questions about the AWS Glue integration

Integrations

Pre-built APIs with 1,000+ systems, apps, and models

Ketch ships connectors and SDKs so consent, rights, and policy flow into your CDPs, warehouses, ad platforms, and AI stack — without a custom data pipeline.

Browse All Integrations

See AWS Glue permissioning running end to end

Book a demo to walk through rights, consent, and preference orchestration on your stack — or start free and connect AWS Glue yourself.

Get Started Free

Get started in less than 5 min