Skip to content

Know whose data was involved.

When a mailbox, a shared drive or an export is compromised, the questions are immediate: whose personal data was in it, what categories, how much of it was special category, and who needs to be told. Redactics processes the affected dataset the way it processes a SAR, and produces the answers with evidence.

What your team is asked

  • How many people are affected, once duplicates and aliases are resolved?
  • Was special category data involved, and for whom?
  • What do we tell the ICO, and can we show how we know?
  • Which individuals need to be contacted, and what do we say to each?

How the case runs

  1. 1

    Ingest the affected dataset

    Load the compromised mailbox export, drive folder or file set into an isolated case.

  2. 2

    Identify people and categories

    Findings are classified by category and resolved to people, so the count of affected individuals is a count of people, not of name strings.

  3. 3

    Assess risk

    See special category data, financial data and identifiers by person, to support the risk assessment for notification.

  4. 4

    Evidence the notification

    Export the counts, categories and per-person summaries that support the ICO notification and individual communications.

SAR-2026-0417/Findings

Findings by category

1,428 total
  • Contact details486
  • Employment371
  • Financial118
  • Health (special category)64
  • Third-party personal data294
  • Opinions and assessments95

How findings were made

Pattern rules for identifiers and references
402
Azure AI Language for entities and contact details
611
Contextual model for health, opinions and relationships
415

1,296 at or above 85% confidence, 84 between 70 and 85%, 48 below 70% and queued for judgement.

From the guided sample case. All data is synthetic.

What changes

Counts you can stand behind
Affected individuals are resolved people with evidence, not a keyword search estimate.
Special category data identified
Health, ethnicity and similar data is surfaced per person for the high-risk assessment.
A record of the assessment
What was examined, what was found and what was decided is recorded for the regulator and for later review.

What a pilot looks like

  • Run a tabletop exercise on a synthetic breach dataset in the guided trial
  • Or process a historic, already-notified incident dataset to compare against your original assessment
  • Receive a breach assessment report with people, categories and evidence
Run a SAR pilot

Relevant controls

  • Isolated case per incident
  • UK or EU Azure processing
  • Access restricted to the incident team
  • Secure deletion at close
Security and trust

Make SARs manageable.

Try Redactics yourself or talk to us about your current process.