priivacy
Compliance Assessment

Which privacy obligations your data puts at risk.

An article-by-article assessment of the personal information found against the active framework — the evidence behind each obligation, and the actions to close the gaps.

Prepared for
ACME INC - SP
Source
SharePoint · 409,757 documents
Issued
14 September 2026
Framework
General Data Protection Regulation
Framework
GDPR
Active compliance framework
12 PII types
assessed
Articles triggered
6/7
Framework articles engaged
GDPR
active framework
Special category
0
GDPR Art 9 / sensitive
0 types
special-category
Restricted
608,760
Most-sensitive findings
67% of findings
restricted items

Risk posture

sensitivity-weighted exposure
88
Exposure index

Elevated exposure

A high share of identifiable records carry restricted-grade PII (TFN, Medicare, passport), concentrated in a small number of documents.

608,760 restricted-grade findings
Sensitivity distribution
Restricted
608,760
Confidential
261,400
Internal
37,025
Public
0

Compliance assessment

General Data Protection Regulation · EU/UK · ICO (UK) / national DPAs (EU) · 6/7 articles
402,315 scanned · 7,442 partial · 3,803 declined · 23,797 excluded · 240 failed
Top actions to take
  1. 1.Art-5Assess whether the volume of personal data collected is proportionate to stated purposes (data minimisation).
  2. 2.Art-5Identify duplicate records across systems — duplication may violate the accuracy principle.
  3. 3.Art-32Redact or quarantine files containing restricted PII.
  4. 4.Art-32Review access controls — apply least-privilege on files containing personal data.
  5. 5.Art-32Verify encryption at rest and in transit for systems holding personal data.
  6. 6.Art-33Ensure an incident response plan exists that can meet the 72-hour notification window.
  7. 7.Art-33For files flagged with externally-shared sensitive PII, consider whether a breach has already occurred.
Article-by-article assessment
Art-5
Principles relating to processing of personal data
Data must be processed lawfully, fairly, transparently; collected for specified purposes; adequate, relevant, limited.
HIGH
Evidence from this scan
PII typeSensitivityFindingsFiles
Person Nameinternal36,38218,590
Date of Birthconfidential231,62872,980
Recommended actions
  • Assess whether the volume of personal data collected is proportionate to stated purposes (data minimisation).
  • Identify duplicate records across systems — duplication may violate the accuracy principle.
Art-6
Lawfulness of processing
Processing requires a lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests).
NONE
Evidence from this scan
No findings in this scan touch this principle.
Recommended actions
  • Document the lawful basis for each category of PII identified in the scan.
Art-9
Processing of special categories of personal data
Special categories (health, biometric, genetic, religious, sexual orientation, etc.) require explicit consent or statutory basis.
NONE
Evidence from this scan
No findings in this scan touch this principle.
Art-15
Right of access by the data subject
Data subjects have the right to obtain confirmation of, and a copy of, their personal data being processed.
NONE
Evidence from this scan
No findings in this scan touch this principle.
Recommended actions
  • Ensure a documented process exists for DSARs against the scanned data sources.
Art-17
Right to erasure (right to be forgotten)
Data subjects can request erasure of personal data — including where data is no longer necessary for the original purpose.
NONE
Evidence from this scan
No findings in this scan touch this principle.
Recommended actions
  • Enforce retention policies on files containing personal data no longer needed.
  • Identify files with PII older than the stated retention period and remediate.
Art-32
Security of processing
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
CRITICAL
Evidence from this scan
PII typeSensitivityFindingsFiles
Credit Card Numberrestricted2,462302
Passport Numberrestricted3,5711,416
Date of Birthconfidential231,62872,980
Person Nameinternal36,38218,590
Recommended actions
  • Redact or quarantine files containing restricted PII.
  • Review access controls — apply least-privilege on files containing personal data.
  • Verify encryption at rest and in transit for systems holding personal data.
Art-33
Notification of a personal data breach to the supervisory authority
Data controllers must notify the supervisory authority within 72 hours of becoming aware of a breach where it poses risk to rights and freedoms.
CRITICAL
Evidence from this scan
PII typeSensitivityFindingsFiles
Credit Card Numberrestricted2,462302
Passport Numberrestricted3,5711,416
Tax File Number (TFN)restricted40,71318,041
Recommended actions
  • Ensure an incident response plan exists that can meet the 72-hour notification window.
  • For files flagged with externally-shared sensitive PII, consider whether a breach has already occurred.
General Data Protection Regulation · ICO (UK) / national DPAs (EU)