NotableotherDatabricks

Databricks Implements Read Restrictions and Catalog Labels for Data Governance

Published
Oct 1, 2026 — 00:00 UTC

Databricks has introduced read restrictions and catalog labels to unify data governance across various engines, including Apache Iceberg, Spark, DuckDB, and Trino. This initiative follows the recent adoption of these features by the Iceberg community, which aims to standardize data governance practices. The implementation includes nine predefined column-projection actions that streamline governance processes.

Key responsibilities for governed queries now include identity context evaluation, policy evaluation, and enforcement decision-making. However, routing these governed queries through a filter fleet may introduce latency, impacting performance. Additionally, user-specific table responses will prevent the reuse of cached tables across different users, enhancing security but potentially affecting efficiency.

Databricks' approach allows for a standardized method to delegate enforcement to trusted engines, which is crucial for organizations managing sensitive data. The introduction of catalog labels facilitates the portability of governance and business context across various data catalogs, including Snowflake, AWS Lake Formation, and Google Cloud Knowledge Catalog. This development could lead to future innovations in data governance as collaboration with the Iceberg community continues.

Summarised from Databricks Blog's original report by the Turing Wire Newsdesk. Read the original for the full story.

Source: Databricks Blog