Home icon

Automate custom PII detection at scale with Amazon Macie and Step Functions

Architecture Blog



This article demonstrates how to build an event-driven pipeline using Amazon Macie and AWS Step Functions to automatically detect PII and custom sensitive data in S3 files at scale.

  • Amazon EventBridge triggers AWS Step Functions workflows when files arrive in S3
  • Amazon Macie scans objects using built-in and custom data identifiers for organization-specific PII
  • Pipeline generates compliance reports in CSV and JSON formats with full timestamps
  • Real-time SNS notifications alert security teams to high-severity findings
  • Three-bucket pattern isolates data by processing state: raw, staged, and scanned
  • AWS Lambda orchestrates steps including job creation, status polling, and report generation
  • Solution includes hardening measures for production deployment and multi-tenant environments

The automated pipeline enables compliance teams to detect and classify sensitive data without manual intervention, maintaining clear data lineage and audit trails throughout the scanning lifecycle.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jul 13
2026
OpenAI privacy-filter for PII detection and masking is now available in Amazon SageMaker JumpStart
Jul 6
2026
Automatically redact PII in images with Amazon Nova
Jan 9
2024
Detect PII data in Amazon Aurora with Amazon Comprehend
Oct 1
2024
How to perform a proof of concept for automated discovery using Amazon Macie

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.