NakodaX

NakodaX blog/Data Pipelines·4 min read

The analytics vendor has your customer table

You shared your customer table because the vendor needed it to do the work. Here is how to give them what they need without giving away the whole file.

Aditi Jain

By Aditi Jain

Director, NakodaX ·

A full customer dataset flowing through a filter into a useful partner view, with selected attributes obscured.
The problem was never that you shared the data. It was that you could not take it back.

A marketing team wants better attribution. They pick an analytics vendor. The vendor asks for a customer export: names, emails, phone numbers, past orders.

The team sends it, because the vendor cannot do the work without it. Months later the contract ends, or the vendor changes hands, and the customer table is sitting on infrastructure your team never controlled.

Nothing went wrong in the sharing itself. Your team did their job and the vendor did theirs. The problem is what happens after the file leaves.

This was never a breach

Once the file reaches the vendor, your control over it ends. You have a contract. You have an agreement about how the data can be used. You do not have the data.

Stripping out names and phone numbers before sending usually breaks the reason you sent it. Attribution needs to match customers across systems. Fraud checks need real identifiers. Remove those fields and the vendor cannot do the job. Leave them in and the vendor has your customers.

Give the vendor a working copy, not the whole table

NakodaX Data Pipelines reads from your warehouse and builds a separate view for each partner. Columns you choose can be masked or encrypted before they ever reach the vendor.

The vendor runs their side exactly as before. Their pipelines, their reports, their joins. Nothing about their day changes.

This is secure partner data sharing in the plain sense of the phrase. The vendor gets a working file built for the job, not a copy of your whole customer table.

Ending the relationship becomes one action

When the engagement ends, you revoke that vendor's policy. The export they were holding does not disappear, but the protected fields in it stop being readable. There is no request for deletion you cannot verify, no certificate you have to take on trust.

Each partner can run on their own policy, so ending one relationship never touches another.

What this changes

You can share a complete, useful dataset, because sharing no longer means giving it up for good.

You can answer the question a board or a regulator eventually asks: who can read our customer data right now, and how would we know.

None of this assumes the vendor meant any harm. It assumes a copy of your customer table on someone else's infrastructure is a risk on its own, whatever their intentions, and that you should be able to turn it off.

The takeaway

Give partners a working copy of what they need, keep the policy in your hands, and end the relationship cleanly whenever it is time.

Related product

NakodaX Data Pipelines

Filter rows, protect columns, deliver data to each recipient and enforce access and retention without storing business data on NakodaX.

See how it works