Oracle Virtual Private Database (VPD) and Oracle Label Security are not enforced during direct path Exports.
The following users are exempt from Virtual Private Database and Oracle Label Security enforcement regardless of the export mode, application, or utility used to extract data from the database:
The database user SYS
Database users granted the EXEMPT
ACCESS
POLICY
privilege, either directly or through a database role
This means that any user who is granted the EXEMPT
ACCESS
POLICY
privilege is completely exempt from enforcement of VPD and Oracle Label Security. This is a powerful privilege and should be carefully managed. This privilege does not affect the enforcement of traditional object privileges such as SELECT
, INSERT
, UPDATE
, and DELETE
. These privileges are enforced even if a user has been granted the EXEMPT
ACCESS
POLICY
privilege.
Oracle Database Security Guide for more information about using VPD to control data access