← Back to news 28.07.2026

The biggest data store is a mailbox

No system accumulates as much personal data as an organization's email mailboxes: bank details, ID scans, sick notes, passwords in plain text. Two questions bring this to light, and both arrive under time pressure: what data do you hold about me? And: who is affected by this incident?

No system accumulates as much personal data as an organization's email mailboxes. Applicants' bank details, ID scans in attachments, sick notes, draft contracts, occasionally a password in plain text because it had to be quick. Unlike a database, this store has no schema, no retention period and no owner. It simply grows.

Two questions bring it to light

In daily work this goes unnoticed. It surfaces in two moments, and both arrive under time pressure. The first: someone files an access request under Article 15 and wants to know what data you process about them. The second: a mailbox has been compromised, and the notification duty under Article 33 requires a report within 72 hours, including the type of data and the number of people affected. Neither question can be answered if nobody knows what is in the mailboxes.

Searching is not the same as knowing

The usual reflex is a keyword search on the mail server. It finds a name, but not the ID scan in an attachment, not the IBAN in a spreadsheet, not the password in an old conversation. And it says nothing about how sensitive the findings are. Exactly this gap between searching and knowing is the problem: you can only protect, delete and report what you know about.

How isidaten opens up the mailboxes

Data classification scans Exchange mailboxes and other data sources and recognizes sensitive content by itself: bank details and credit card numbers, health data, credentials and API keys, personal information. Every finding is classified, receives a sensitivity level and can be closed with an action. On this basis the two questions above no longer run into a void: a DSAR search compiles which data exists about a person, and the breach analysis determines after an incident which people and which data types are involved, through to the status of the notification.

More is shown on the data classification module page. Why you can only delete what you know about was covered here before, and the other data protection duties are listed on the GDPR solution page.

Matching solution isidaten for DSGVO

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.