Privacy and preparation
Finding shadow data: old exports, shared drives and personal mailboxes
By SourceX Editorial · Updated
Short answer
Shadow data is any copy of business records that lives outside its system of record and outside normal access and retention controls: old CSV exports, folders on shared drives, PST files and mailbox attachments. Find it before licensing, because an approved scope means little if unreviewed copies of the same records sit somewhere else.
Key takeaways
- Shadow data is a copy of business records that sits outside its system of record and outside normal controls.
- The usual hiding places are retired-system exports, shared drives, departed employees' storage and mailbox attachments.
- Some shadow copies are the only surviving history of a retired system, so they need a provenance note rather than automatic deletion.
- Never delete a found copy before checking retention rules and any legal hold.
- Run discovery in two passes: ask people and read storage reports first, then scan and decide location by location.
What counts as shadow data in a mid-size company?#
Shadow data is a copy of company records that its system of record no longer controls: a ticket export saved to a file share during a help desk migration, a customer list attached to an email, a database backup on a server nobody logs into. Nobody planned to keep it, so nobody applies access rules, retention or review to it.
Data security vendors popularized the term, but any IT lead at a company that has run several generations of software knows the problem. Every migration, audit, board report and departing salesperson leaves copies behind, and most of them hold the same customer and employee details as the live systems.
Before a licensing project, shadow data matters for two reasons. Unreviewed copies of in-scope records undercut the claim that personal data was handled, and a forgotten export may hold the only remaining history from a system the company retired long ago.
Where shadow data usually hides#
Shadow data collects wherever someone needed records outside a system and had nowhere official to put them. The table covers the usual locations in companies running a mix of SaaS tools, Microsoft 365 or Google Workspace, and a few on-premises servers.
| Location | Typical contents | How it got there | First check |
|---|---|---|---|
| Shared network drives and NAS devices | CSV dumps, report extracts, scanned files | Ad hoc exports and old department folders | Storage reports sorted by size and last modified date |
| Retired-system export folders | Full ticket, CRM or ERP exports in CSV, JSON or SQL | Vendor migrations and contract terminations | Finance's list of cancelled software subscriptions |
| SharePoint, Teams and Google Drive sites | Finished project sites and team sites of reorganized groups | Sites created per project and never archived | Sites with no recent activity and no current owner |
| Personal mailboxes and PST archives | Exported customer lists, reports sent to self | Email used as a file transfer tool | Searches for large attachments and archive file types |
| Departed employees' OneDrive or Drive | Working copies of reports and spreadsheets | Retention settings that keep accounts after offboarding | Offboarding records matched against retained accounts |
| Analytics and BI extracts | Spreadsheet pivots and dashboard data sources | Analysts pulling raw tables for reports | Data sources connected to reporting tools |
| Test and development databases | Copies of production customer tables | Developers wanting realistic test data | Database inventory on dev servers and cloud accounts |
| Cloud storage buckets | Migration staging files, backups and logs | Projects that ended without cleanup | Buckets with no tags, owner or recent access |
Is shadow data a risk or an asset?#
Shadow data is mostly a risk and occasionally an asset, and the treatment depends on what the copy is. A duplicate of records still in the live system adds exposure and no value. An export from a help desk you shut down may be the only place years of support history still exist.
Decide each found copy against a short rule set instead of debating it from scratch. The rules stop IT from deleting something the business needs, and they stop a promising archive from entering a licensing scope without anyone knowing where it came from.
| What you found | Treat it as | Next step |
|---|---|---|
| Duplicate of records still in the live system | Risk only | Flag for retention review and license from the live system instead |
| Only surviving copy of a retired system's history | Possible licensing candidate | Record provenance: source system, export date, who made it, completeness |
| HR, payroll, medical or benefits files | Exclusion | Route to the records owner; never part of an export scope |
| Unknown origin or owner | Quarantine | Restrict access until an owner identifies it |
| Files under a legal hold | Off limits | Leave untouched and confirm with counsel before any change |
A discovery plan in two passes#
A shadow data discovery plan works best in two passes: first ask people and read storage metadata, then scan and decide one location at a time. Asking first is faster than scanning everything, because long-tenured staff usually remember where the old exports went.
Keep discovery metadata-only wherever you can. File names, sizes, dates and owners settle most locations; opening files is needed only for licensing candidates and unknowns.
- First pass: ask department heads, long-tenured staff and former system owners where old exports, reports and archives were saved.
- First pass: pull finance's list of cancelled software vendors to name every retired system that might have left an export behind.
- First pass: run storage reports for large files and archive types such as PST, ZIP, BAK, SQL and CSV across file shares and cloud storage.
- First pass: list sites, buckets and accounts with no owner or no recent activity.
- Second pass: scan each found location with your DLP or classification tool and record the match types and counts.
- Second pass: assign an owner, apply the rule set, and add a row to the data inventory for each location.
- Second pass: write a provenance note for every licensing candidate before anyone opens or copies the files.
Personal mailboxes need a lighter touch#
Personal mailboxes need a lighter touch than file shares because they mix business records with private correspondence and are often covered by employee notices, retention rules and legal holds. Search them by metadata, not by reading: attachment type, attachment size, sender and recipient domains, and subject lines that suggest exports.
Mailboxes themselves rarely belong in a licensing scope. The aim is to find exports that traveled through them, such as a full customer list sent to a personal address or a ticket dump sent to a contractor, and to trace each one back to its source system. Bring in the privacy lead or counsel before any targeted mailbox search, and record who approved it.
In Microsoft 365, Purview eDiscovery is the usual route for a controlled, logged mailbox search, and it can export results as PST files or individual .msg files. Microsoft states that search exports expire 14 days after creation, so plan the download before starting a large export. Remember too that files shared in Teams chats are stored in the sharer's OneDrive, which makes departed employees' OneDrive accounts a common home for exported reports.
Illustrative: a 3PL finds its old warehouse history#
Illustrative: a fictional third-party logistics company replaced its warehouse management system and moved transportation planning to a new TMS. While preparing to license order exception and service records, its IT lead runs the two-pass discovery before anything is scoped.
Interviews point to a NAS in the main warehouse office. Storage reports find a folder named after a former operations manager that holds full exports of the old WMS exception log and carrier claims, plus a database backup from the retired TMS. A mailbox search by attachment type finds a customer contact list that a sales rep emailed to a personal account before leaving.
The team writes a provenance note for the WMS exports, checks the old vendor contract to confirm the company may use its own exported records, and adds them to the candidate scope pending preparation. The TMS backup duplicates migrated data and goes to retention review. The emailed contact list goes to the privacy lead under the company's incident process.
How SourceX handles found archives#
SourceX handles found archives in the first two steps of the SourceX five-step transaction, Supply and Rights, before Preparation, Approval and Delivery. An old export can be part of a package, but only with a provenance record stating which system produced it, when, by whom and whether it is complete.
That provenance goes into the SourceX Evidence Packet with licensing rights, permitted use, the privacy record and release authorization. Large archives stay in the supplier's own storage or ship on encrypted drives, SourceX never hosts multi-terabyte datasets, and the supplier approves every step.
Frequently asked questions
Should we delete shadow data as soon as we find it?
Not before checking. Retention schedules, contracts and any legal hold may require keeping a copy, and some copies are the only record of a retired system. Decide each location with the records owner, involve counsel where needed, document the decision, and delete through your normal disposal process rather than ad hoc.
Do data security posture management tools replace manual discovery?
They help, especially across cloud storage and the SaaS platforms they connect to, but they only see what they are connected to. A NAS in a warehouse office, an old laptop backup or an export in a personal email account can stay invisible. Interviews and storage reports cover what scanners cannot reach.
Can an export from a retired system still be licensed?
Sometimes. The company needs to confirm it owns or controls the records, that the old vendor terms and customer contracts allow the use, and that the export is complete enough to describe accurately. Weak provenance lowers a buyer's confidence, so document everything known about how and when the export was made.
What about company records on employees' personal devices or accounts?
Treat them as outside any licensing scope. Ask current and departing staff to return or delete company files through your normal process, and record what was reported. Records that exist only on personal devices rarely have the provenance or rights clarity a licensing package needs.
Who should own shadow data discovery?
IT usually runs it, but each location needs a named business owner, and mailboxes and sensitive finds need a privacy or legal contact. In many mid-size companies the COO coordinates, while the CTO or IT lead runs the storage reports and scans.
Sources
- Microsoft Purview eDiscovery can export search results as .pst files or individual .msg files. Source
- Microsoft states that Purview eDiscovery search exports expire 14 days after creation. Source
- Microsoft states that files shared in Teams chats are stored in the OneDrive account of the user who shared them. Source
Related resources
- QuestionShould companies sell or license their data?
- QuestionDo I need customer consent to license support tickets?
- InsightDo former employees have to consent before a closed company licenses their messages?
- InsightCan HVAC and plumbing companies license technician helmet-camera footage?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.