Know whose data was involved.
When a mailbox, a shared drive or an export is compromised, the questions are immediate: whose personal data was in it, what categories, how much of it was special category, and who needs to be told. Redactics processes the affected dataset the way it processes a SAR, and produces the answers with evidence.
What your team is asked
- How many people are affected, once duplicates and aliases are resolved?
- Was special category data involved, and for whom?
- What do we tell the ICO, and can we show how we know?
- Which individuals need to be contacted, and what do we say to each?
How the case runs
- 1
Ingest the affected dataset
Load the compromised mailbox export, drive folder or file set into an isolated case.
- 2
Identify people and categories
Findings are classified by category and resolved to people, so the count of affected individuals is a count of people, not of name strings.
- 3
Assess risk
See special category data, financial data and identifiers by person, to support the risk assessment for notification.
- 4
Evidence the notification
Export the counts, categories and per-person summaries that support the ICO notification and individual communications.
- Cases
- /SAR-2026-0417
- /Findings
SAR-2026-0417/Findings
Findings by category
1,428 total- Contact details486
- Employment371
- Financial118
- Health (special category)64
- Third-party personal data294
- Opinions and assessments95
How findings were made
- Pattern rules for identifiers and references
- 402
- Azure AI Language for entities and contact details
- 611
- Contextual model for health, opinions and relationships
- 415
1,296 at or above 85% confidence, 84 between 70 and 85%, 48 below 70% and queued for judgement.
What changes
- Counts you can stand behind
- Affected individuals are resolved people with evidence, not a keyword search estimate.
- Special category data identified
- Health, ethnicity and similar data is surfaced per person for the high-risk assessment.
- A record of the assessment
- What was examined, what was found and what was decided is recorded for the regulator and for later review.
What a pilot looks like
- Run a tabletop exercise on a synthetic breach dataset in the guided trial
- Or process a historic, already-notified incident dataset to compare against your original assessment
- Receive a breach assessment report with people, categories and evidence
Relevant controls
- Isolated case per incident
- UK or EU Azure processing
- Access restricted to the incident team
- Secure deletion at close
Other solutions
- Subject Access RequestsDefensible SAR fulfilment from collection to disclosure, with the evidence trail built in.
- HealthcareHigh-volume, high-sensitivity requests across clinical, HR and corporate records, with clinician judgement preserved.
- Local governmentSocial care, housing and education files that run to thousands of pages, with families, professionals and third parties throughout.
- Regulated organisationsComplaint-driven and litigation-adjacent requests where privilege, third-party data and the audit trail all matter.
- Managed SAR serviceRedactics technology and a review team, handling the workload with you and within your governance.
Make SARs manageable.
Try Redactics yourself or talk to us about your current process.