Most companies that own a database, make copies (cloning) of the database for development, QA, testing, patch testing, etc. These databases are distributed to programmers, contractors, sub-contractors, outside vendors and at time off shore vendors.
The cloned copy of the database contains all the information in the ‘production’ system — depending on the nature of the database it can contain sensitive personal (salary, SSN, address, age, etc) as well as corporate (pricing information, supplier, financial data, etc).
With the extra-ordinary levels of legislation/ standards around privacy, this area should be one that gets a lot of attention.
How do organizations protect the information in these databases?