Skip to content

Privacy and preparation

Finding shadow data: old exports, shared drives and personal mailboxes

By SourceX Editorial · Updated

Short answer

Shadow data is any copy of business records that lives outside its system of record and outside normal access and retention controls: old CSV exports, folders on shared drives, PST files and mailbox attachments. Find it before licensing, because an approved scope means little if unreviewed copies of the same records sit somewhere else.

Key takeaways

  • Shadow data is a copy of business records that sits outside its system of record and outside normal controls.
  • The usual hiding places are retired-system exports, shared drives, departed employees' storage and mailbox attachments.
  • Some shadow copies are the only surviving history of a retired system, so they need a provenance note rather than automatic deletion.
  • Never delete a found copy before checking retention rules and any legal hold.
  • Run discovery in two passes: ask people and read storage reports first, then scan and decide location by location.

What counts as shadow data in a mid-size company?#

Shadow data is a copy of company records that its system of record no longer controls: a ticket export saved to a file share during a help desk migration, a customer list attached to an email, a database backup on a server nobody logs into. Nobody planned to keep it, so nobody applies access rules, retention or review to it.

Data security vendors popularized the term, but any IT lead at a company that has run several generations of software knows the problem. Every migration, audit, board report and departing salesperson leaves copies behind, and most of them hold the same customer and employee details as the live systems.

Before a licensing project, shadow data matters for two reasons. Unreviewed copies of in-scope records undercut the claim that personal data was handled, and a forgotten export may hold the only remaining history from a system the company retired long ago.

Where shadow data usually hides#

Shadow data collects wherever someone needed records outside a system and had nowhere official to put them. The table covers the usual locations in companies running a mix of SaaS tools, Microsoft 365 or Google Workspace, and a few on-premises servers.

Where shadow data usually hides
LocationTypical contentsHow it got thereFirst check
Shared network drives and NAS devicesCSV dumps, report extracts, scanned filesAd hoc exports and old department foldersStorage reports sorted by size and last modified date
Retired-system export foldersFull ticket, CRM or ERP exports in CSV, JSON or SQLVendor migrations and contract terminationsFinance's list of cancelled software subscriptions
SharePoint, Teams and Google Drive sitesFinished project sites and team sites of reorganized groupsSites created per project and never archivedSites with no recent activity and no current owner
Personal mailboxes and PST archivesExported customer lists, reports sent to selfEmail used as a file transfer toolSearches for large attachments and archive file types
Departed employees' OneDrive or DriveWorking copies of reports and spreadsheetsRetention settings that keep accounts after offboardingOffboarding records matched against retained accounts
Analytics and BI extractsSpreadsheet pivots and dashboard data sourcesAnalysts pulling raw tables for reportsData sources connected to reporting tools
Test and development databasesCopies of production customer tablesDevelopers wanting realistic test dataDatabase inventory on dev servers and cloud accounts
Cloud storage bucketsMigration staging files, backups and logsProjects that ended without cleanupBuckets with no tags, owner or recent access

Is shadow data a risk or an asset?#

Shadow data is mostly a risk and occasionally an asset, and the treatment depends on what the copy is. A duplicate of records still in the live system adds exposure and no value. An export from a help desk you shut down may be the only place years of support history still exist.

Decide each found copy against a short rule set instead of debating it from scratch. The rules stop IT from deleting something the business needs, and they stop a promising archive from entering a licensing scope without anyone knowing where it came from.

Is shadow data a risk or an asset?
What you foundTreat it asNext step
Duplicate of records still in the live systemRisk onlyFlag for retention review and license from the live system instead
Only surviving copy of a retired system's historyPossible licensing candidateRecord provenance: source system, export date, who made it, completeness
HR, payroll, medical or benefits filesExclusionRoute to the records owner; never part of an export scope
Unknown origin or ownerQuarantineRestrict access until an owner identifies it
Files under a legal holdOff limitsLeave untouched and confirm with counsel before any change

A discovery plan in two passes#

A shadow data discovery plan works best in two passes: first ask people and read storage metadata, then scan and decide one location at a time. Asking first is faster than scanning everything, because long-tenured staff usually remember where the old exports went.

Keep discovery metadata-only wherever you can. File names, sizes, dates and owners settle most locations; opening files is needed only for licensing candidates and unknowns.

  • First pass: ask department heads, long-tenured staff and former system owners where old exports, reports and archives were saved.
  • First pass: pull finance's list of cancelled software vendors to name every retired system that might have left an export behind.
  • First pass: run storage reports for large files and archive types such as PST, ZIP, BAK, SQL and CSV across file shares and cloud storage.
  • First pass: list sites, buckets and accounts with no owner or no recent activity.
  • Second pass: scan each found location with your DLP or classification tool and record the match types and counts.
  • Second pass: assign an owner, apply the rule set, and add a row to the data inventory for each location.
  • Second pass: write a provenance note for every licensing candidate before anyone opens or copies the files.

Personal mailboxes need a lighter touch#

Personal mailboxes need a lighter touch than file shares because they mix business records with private correspondence and are often covered by employee notices, retention rules and legal holds. Search them by metadata, not by reading: attachment type, attachment size, sender and recipient domains, and subject lines that suggest exports.

Mailboxes themselves rarely belong in a licensing scope. The aim is to find exports that traveled through them, such as a full customer list sent to a personal address or a ticket dump sent to a contractor, and to trace each one back to its source system. Bring in the privacy lead or counsel before any targeted mailbox search, and record who approved it.

In Microsoft 365, Purview eDiscovery is the usual route for a controlled, logged mailbox search, and it can export results as PST files or individual .msg files. Microsoft states that search exports expire 14 days after creation, so plan the download before starting a large export. Remember too that files shared in Teams chats are stored in the sharer's OneDrive, which makes departed employees' OneDrive accounts a common home for exported reports.

Illustrative: a 3PL finds its old warehouse history#

Illustrative: a fictional third-party logistics company replaced its warehouse management system and moved transportation planning to a new TMS. While preparing to license order exception and service records, its IT lead runs the two-pass discovery before anything is scoped.

Interviews point to a NAS in the main warehouse office. Storage reports find a folder named after a former operations manager that holds full exports of the old WMS exception log and carrier claims, plus a database backup from the retired TMS. A mailbox search by attachment type finds a customer contact list that a sales rep emailed to a personal account before leaving.

The team writes a provenance note for the WMS exports, checks the old vendor contract to confirm the company may use its own exported records, and adds them to the candidate scope pending preparation. The TMS backup duplicates migrated data and goes to retention review. The emailed contact list goes to the privacy lead under the company's incident process.

How SourceX handles found archives#

SourceX handles found archives in the first two steps of the SourceX five-step transaction, Supply and Rights, before Preparation, Approval and Delivery. An old export can be part of a package, but only with a provenance record stating which system produced it, when, by whom and whether it is complete.

That provenance goes into the SourceX Evidence Packet with licensing rights, permitted use, the privacy record and release authorization. Large archives stay in the supplier's own storage or ship on encrypted drives, SourceX never hosts multi-terabyte datasets, and the supplier approves every step.

Frequently asked questions

Should we delete shadow data as soon as we find it?

Not before checking. Retention schedules, contracts and any legal hold may require keeping a copy, and some copies are the only record of a retired system. Decide each location with the records owner, involve counsel where needed, document the decision, and delete through your normal disposal process rather than ad hoc.

Do data security posture management tools replace manual discovery?

They help, especially across cloud storage and the SaaS platforms they connect to, but they only see what they are connected to. A NAS in a warehouse office, an old laptop backup or an export in a personal email account can stay invisible. Interviews and storage reports cover what scanners cannot reach.

Can an export from a retired system still be licensed?

Sometimes. The company needs to confirm it owns or controls the records, that the old vendor terms and customer contracts allow the use, and that the export is complete enough to describe accurately. Weak provenance lowers a buyer's confidence, so document everything known about how and when the export was made.

What about company records on employees' personal devices or accounts?

Treat them as outside any licensing scope. Ask current and departing staff to return or delete company files through your normal process, and record what was reported. Records that exist only on personal devices rarely have the provenance or rights clarity a licensing package needs.

Who should own shadow data discovery?

IT usually runs it, but each location needs a named business owner, and mailboxes and sensitive finds need a privacy or legal contact. In many mid-size companies the COO coordinates, while the CTO or IT lead runs the storage reports and scans.

Sources

  • Microsoft Purview eDiscovery can export search results as .pst files or individual .msg files. Source
  • Microsoft states that Purview eDiscovery search exports expire 14 days after creation. Source
  • Microsoft states that files shared in Teams chats are stored in the OneDrive account of the user who shared them. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify