Ketch and Google BigQuery

Find where personal data lives inside a cloud data warehouse, and fulfill deletion requests against it directly, using standard Google Cloud IAM roles rather than a custom permission scheme.

Google BigQuery

About Google BigQuery

BigQuery runs analytical workloads at cloud scale, and Google's own IAM roles already define clean boundaries between viewing data and modifying it. Connecting a privacy integration through those same standard roles, rather than a bespoke permission set, keeps the setup consistent with how every other GCP service is governed.

Ketch connects to BigQuery through a Ketch Transponder using exactly those standard roles.

Capabilities

How Ketch works with Google BigQuery

The Ketch BigQuery integration covers Discovery and Rights Orchestration for both Right to Access and Right to Delete.

Discovery

Access rights require the standard `roles/bigquery.dataViewer` role (read access to table data and metadata) and `roles/bigquery.metadataViewer` role (view dataset and table metadata).

Rights Orchestration

Right to Delete requires an additional role, `roles/bigquery.dataEditor`, granted separately to enable `UPDATE` and `DELETE` operations.

With Ketch, teams can

  • Discover which BigQuery datasets and tables hold personal data using standard, read-only GCP IAM roles
  • Grant the `dataEditor` role separately from Discovery roles, deciding independently whether and when to authorize direct deletion and update
  • Set up the service account using standard `gcloud` commands, consistent with any other GCP service account provisioning

The gap

The problem this integration solves

A cloud data warehouse still needs personal data actually located and reachable, using a permission model that doesn't require a custom scheme:

01. Manually reviewing datasets and tables for personal data doesn't scale across a real BigQuery project

02. A privacy integration that requires a non-standard permission model adds friction to a cloud security team's review

03. Fulfilling a deletion request against a warehouse has historically meant a manually written query, slow and hard to prove complete

Ketch resolves this by using Google's own standard IAM roles, so a security review sees familiar, well-understood permissions rather than a bespoke grant.

Why Ketch

Why teams choose Ketch for Google BigQuery privacy compliance

Permissioning infrastructure that governs Google BigQuery the same way it governs every other system in your stack — not a one-off connector bolted onto a banner.

  • Standard GCP IAM roles, not a custom scheme

    `dataViewer`, `metadataViewer`, and `dataEditor` are roles any GCP-familiar security team already recognizes.

  • Least-privilege by design

    Discovery and access rights use read-only roles; `dataEditor` is a separate, explicit grant required only for deletion.

  • Backed by enforcement precedent

    Regulators increasingly expect businesses to prove technical enforcement, not just describe it on paper, the same underlying expectation that applies to knowing what personal data a warehouse holds.

Questions about the Google BigQuery integration

Integrations

Pre-built APIs with 1,000+ systems, apps, and models

Ketch ships connectors and SDKs so consent, rights, and policy flow into your CDPs, warehouses, ad platforms, and AI stack — without a custom data pipeline.

Browse All Integrations

See Google BigQuery permissioning running end to end

Book a demo to walk through rights, consent, and preference orchestration on your stack — or start free and connect Google BigQuery yourself.

Get Started Free

Get started in less than 5 min