“Scan your data on local and cloud-based systems for sensitive information in minutes. DataMapper is a Sensitive Data Discovery tool that scans your data to find the documents, emails and images that contain words and terms related to privacy regulations such as UK-GDPR. DataMapper is for companies that has lost track of its sensitive data on e-mail, hard drives, cloud etc., and who lack the time to go through it all.
DataMapper is a cloud-based SaaS (Software as a Service), that use artificial intelligence and machine learning algorithms to find numbers and words which can be categorised as sensitive across your company’s employees and data systems. It automatically classifies files into 80 different categories with up to 98% accuracy.
After a scan, you will be presented with an overall overview of the files that are at risk of containing sensitive information. The administrator can see where the inappropriate workflows are, so you can improve your practices for handling data. DataMapper is run from a browser-based and can be used by all your employees or an administrator who can scan the entire company’s data.”
Sebastian Allerelli
Founder & COO
How DataMapper can help you
Clean up
Cleaning up your sensitive data can be a daunting task. Even if you spent weeks at it, it would be impossible to be sure you didn’t miss something important. DataMapper flags your risk data accurately in just minutes.
Enhance IT security
Most companies don’t know they are putting people’s privacy at risk until it is much too late. Use DataMapper to spot your data processing mistakes now and fix them before they affect your customers.
Avoid fines
Storing sensitive data unprotected can result in privacy fines, that cost up to 4% of your annual turnover and irreparable damage to your reputation as a data processor. DataMapper shows you exactly what data you need to protect to reduce privacy risks and liability.
Here is your overview with DataMapper





Features
Monitor your documents, emails and images for sensitive words and numbers.
Get a complete overview and key statistics about your risk files.
Files containing sensitive content are classified as high or medium level depending on the severity of the information.
For each file, you can see the file location, file age, document type, who created the file, who has access to the file, sensitive term etc.
Use filters to get an overview of your files and make clean-up easier.
Open a preview of the document and see where sensitive terms appear.
After a scan, you can easily decide what to do with the document; open, move or delete the document directly in DataMapper.
Set up deletion rules, file moves, notification emails and other automations through integration to Logic Apps.
Admins can invite users, see which employees have the most sensitive data, and monitor risk files for the whole company.
Create the privacy search engine that suits your business by adding your own sensitive terms. Or leave out those that are irrelevant to you.
Follow developments in the processing of sensitive data over time.
With a Power BI-tool you can get complete reports on how you handle sensitive data to use as documentation for data audits.
Get clean up assistance with a notification mail once every month with updates to your data containing sensitive data.
DataMapper detects sensitive terms in Danish, Swedish, English, German, Norwegian, Finnish, and Polish. More languages coming.
Setup
Get started in minutes
Integrations
Made for you
- Native integrations – These include Microsoft OneDrive, Microsoft Outlook, Microsoft SharePoint, Google Drive, Google Mail, Azure Blob Storage, Local Drives and Network Drives (Windows Fileshare).
- Logic Apps – We have integrated DataMapper with Azure Logic Apps to provide access to over 1000 connectors. See the full list here.
- Custom Connector – Logic Apps allows for integration to any RESTful API, providing flexibility for customers who have specific requirements.
Search
Look for sensitive content
DataMapper scans for words and numbers that, according to privacy regulations such as GDPR fall into the sensitive category. The list is constantly being expanded with new words and numbers. In addition, you have the option of adding or omitting words and numbers from a scan. DataMapper scans for these three categories of sensitive terms:
- Personally identifiable data/PII (e.g. ID, driver’s license or passport number)
- Sensitive personal data (e.g. trade union, health info or sexual orientation)
- Business-critical terms (e.g. contract, budget or IP document)
To identify sensitive content, DataMapper uses a combination of search methods.
File types
Search through documents, images and emails
Find sensitive information in these file types:
- Documents (txt, rtf, pdf, doc, docx, gdoc, odt, pptx, ppt, xls, xlsx, gsheet, html, htm)
- Images (jpg, jpeg, png, heic)
- Emails (msg, txt)
Overview
All your sensitive data in a list
After a scan, all files containing sensitive content are displayed in a list. As an administrator, you gain a comprehensive overview of the entire company’s sensitive data, while individual users receive an overview of their own sensitive data. This allows you to quickly identify areas and processes that need attention to enhance your compliance efforts.
Categorisation
Understand Your Data
Files with GDPR risk are categorised by age, file location, file type, type of personal data, risk words, risk numbers, and the individuals related to the file. You can sort and filter by these categories, making it easy for you to get an overview of your files.
Action
Delete, move or approve
With just a few clicks, you can delete or approve files with sensitive content and ensure proper cleanup. DataMapper simplifies adherence to your privacy policy and data processing rules. Any deviations from the company’s data policy are automatically recorded, prompting users to clean up according to internal guidelines and applicable data legislation.
Notifications
Help to clean up
Control
You are in charge
As an administrator, you manage DataMapper on behalf of your company. You can invite new users and have rights to customise the cleanup on behalf of your employees. You get key statistics for both the entire company’s and the individual employee’s processing of sensitive data. As an admin, you get an overview of which processes generate risk.
Documentation
Demonstrate your compliance
Business Intelligence
Get the Full Overview with Power BI
With Power BI integration, you can gain deeper insights into your company’s data management and identify risk areas.
- Reports: View detailed key metrics and create your own customised reports.
- Visualisation: Use interactive visualisations to present data and get a clear overview.
- Integration: Power BI works seamlessly with Excel and other Microsoft products, so you can export data to your existing systems.
- Decisions: Interactive reports and accurate data empower you to make more informed, data-driven decisions.
Workflows
Clean up big scale
The administrator has the opportunity to create automations and get sensitive data processing done much faster. For example, set up rules such as:
- Delete all files with National Insurance numbers that are over 5 years old
- Approve all word files that contain the word “corona”
- Move all CVs to a special folder
Note: only applies to Private Tenant users.
Trust
Make privacy an advantage
IT security
Protect data following best practice
Pricing
SubscriptionClean up now
£ From 214
monthSelect integrations (see list) and invite the employees you want to clean up. All users get monitoring and insight into their data, as well as the option to delete. Your price depends on the number of users and integrations. See price examples for price indication*.
- Subscription
-
Option to delete
-
Continuous monitoring of data
-
Personal onboarding & support
Trial VersionTry for free
£ 0
-Create an account in DataMapper and scan test data or upload your own data (max. 1,000 emails, documents or images). This is a terrific opportunity to see if DataMapper is for you. The trial version does not allow you to delete or monitor data.
- 14 days trial
- Scan your own data (max 1.000 files)
Option to deleteContinuous monitoring of data
AssessmentAnalysis
£ From 700
-With a GDPR Risk Assessment you will get a report that will provide you with a clear overview of your sensitive data. This solution is popular for companies that are unsure of what sensitive data they store and where it is located. Read more here.
- Report
- Personal support
Option to deleteContinuous monitoring of data
* Price Example 1: Outlook, 24 users = £214/month, Price example 2: Outlook, 90 users = £378/month, Price example 3: Office 365, 170 users = £764/month
FAQ
How can DataMapper help you comply with regulations? What should you do with high-risk documents you find? Get answers to frequently asked questions.
What is DataMapper?
DataMapper is a file scanner that helps organisations identify, classify, and manage sensitive data across their internal systems. Technically, DataMapper is a Data Discovery tool.
How can DataMapper help us with complance?
Files containing sensitive information must be protected in accordance with international data regulations such as UK-GDPR, GDPR, CCPA and PIPL. If these data are not properly safeguarded, it can lead to GDPR fines, damage to the company’s credibility, and more.
DataMapper helps ensure UK-GDPR compliance by identifying sensitive information within your systems. You gain a precise overview of files containing sensitive content, enabling you to manage them with ease.
Who is DataMapper for?
DataMapper is created for companies that want control over their sensitive data and how they manage compliance. It is particularly relevant for organisations that handle large volumes of sensitive information.
Is DataMapper cloud-based or on-premise?
DataMapper is cloud-based.
What systems does DataMapper integrate with?
DataMapper supports integrations with various systems, including cloud storage, ERP systems, CRM platforms, and file servers. DataMapper offers three types of connectors for automation:
- Native Connectors, which integrate with the platforms Microsoft OneDrive, Microsoft Outlook, Microsoft SharePoint, Google Drive, Google Mail, Azure Blob Storage, local drives, and network drives (Windows Fileshare).
- Logic Apps integration, providing access to over 1,000 apps via Logic Apps. See the full list here.
- Custom Connector, allowing integration with any RESTful API, offering flexibility for specific integration requirements.
How does DataMapper search for sensitive data?
DataMapper uses a combination of advanced AI and Machine Learning algorithms to detect terms classified as sensitive. Read more here.
What does DataMapper search for?
DataMapper detects words and numbers classified as sensitive under privacy regulations like the GDPR.
- Personally identifiable data/PII (e.g. ID, driver's license or passport number)
- Sensitive personal data (e.g. trade union, health info or sexual orientation)
- Business-critical terms (e.g. contract, budget or IP document)
You can also customise your scans by adding or excluding specific words and numbers, ensuring that DataMapper identifies exactly what you consider sensitive.
What kinds of files can I scan?
DataMapper supports files smaller than 30MB and with following formats:
Documents:
txt, rtf, pdf, doc, docx, gdoc, odt
Email types:
msg, txt (email bodies)
Presentations:
pptx, ppt
Spreadsheets:
xls, xlsx, gsheet
Hypertext:
html, htm
Images:
jpg, jpeg, png, heic
Is it the administrator or the employee who will do the clean-up?
In DataMapper, administrators and employees have different roles: administrators have full visibility of scans and risks across the organisation, but they do not have access to clean up individual employees’ files. The administrator invites employees into DataMapper to carry out the clean-up, while setting the framework, defining the clean-up method, initiating scans and monitoring progress. It is the individual employee who is responsible for reviewing their own files and deciding what to clean up.
This division of responsibilities has been chosen because it often requires the employee’s knowledge of the file’s content and context to make the right decision. At the same time, it is in line with GDPR principles and spares the administrator from an unmanageable clean-up task.
Is DataMapper difficult to set up?
It only takes a few minutes to install DataMapper. The onboarding follows a clear plan, which you can read more about here. If you have any questions during or after implementation, our customer support team is ready to help.
What can we expect to find?
It is difficult to predict exactly what DataMapper will detect in your data. However, our scans show that up to 7% of all documents, emails, and images contain sensitive information.
What should I do with files containing sensitive information?
Files containing sensitive content do not necessarily need to be deleted – but they must be handled correctly.
GDPR makes you responsible for protecting the sensitive information you store. Your company will likely need to retain certain information about employees and customers in order to function normally.
However, it is also common for companies to hold on to sensitive data that they no longer need. How long you may store data depends on the regulations applying to your sector and organisation. If you keep sensitive information for too long – even if it is stored securely and not misused – you can still be in breach of GDPR requirements.
When DataMapper identifies files containing sensitive information, the file should therefore be reviewed and either:
-
deleted
-
redacted so the sensitive content is removed
-
moved to a secure data location
By reducing the amount of sensitive data you collect and retain, you can also minimise the risk and potential damage in the event of a data breach.
Why not just search for sensitive content manually?
Manual searching for sensitive files might initially seem like a good solution, but this method comes with significant limitations that make it time-consuming and inefficient:
-
The volume of data: It can be overwhelming to review all files manually.
-
Human factor: Employees can make mistakes and overlook important files.
-
Limited search knowledge: Employees often don’t know what to look for, as many sensitive terms are unfamiliar.
-
Evolving sensitive expressions: GDPR and other regulations change continuously—new risk terms emerge all the time.
-
Sensitivity hides in images: Data may be stored in scanned documents, images, or notes—difficult to review without automation.
-
Context is everything: Words like “COVID” are only considered sensitive when linked to a person.
-
Language and formats vary: Sensitive information appears differently depending on language and country.
Read more here.
Why not just delete files older than 5 years?
While it may seem straightforward to delete everything older than five years, this is rarely a sustainable approach. Different types of data are subject to varying retention requirements depending on legal obligations and processing purposes. Some data must be kept for longer – for example, in connection with accounting, employment, or contractual obligations – while other data should not be retained that long at all. Many files also contain a mix of information, some of which must be deleted and some of which must be preserved, meaning careful assessment is required rather than automatic deletion. A blanket five-year rule can therefore lead to either unlawful retention or unintended data loss.
Why not just use Microsoft Purview?
There are three reasons why DataMapper is more appropriate to use for cleaning up sensitive files than Microsoft Purview:
- Difficult implementation and setup – Purview requires a complex setup with Azure integration, access rights and data classification policies, which can take weeks or months and often requires external consultants. DataMapper works out-of-the-box without extensive IT involvement.
- Not suitable for users or to clean up – Purview identifies data, but does not give users a concrete overview or the opportunity to clean up themselves. Everything is handled centrally by IT and compliance, which makes cleanup difficult and inefficient. DataMapper shows exactly what needs to be removed and makes it easy for users to take action themselves.
- No OCR scanning – Purview can only read text, while DataMapper also scans images, scanned documents and non-editable PDFs for sensitive information.
What is the security behind DataMapper?
DataMapper processes all of personal information as confidential, including basic details such as names and email addresses. The system is crafted to adhere to the highest standards of data security. Read more about the security in DataMapper here.
How much does DataMapper cost?
The price of DataMapper is based on three factors:
-
Which integrations you require
-
How many employees will use DataMapper
-
The size of your data volume
Where can I get DataMapper?
To get started with DataMapper, you must contact us. You can also purchase DataMapper through your Microsoft subscription on the Azure Marketplace.
DataMapper is part of PrivacyHub
DataMapper belongs to the SaaS platform, PrivacyHub, which is a platform for handling the company’s sensitive personal data. PrivacyHub has divided the processing of personal data into three phases. With RequestManager, it is possible for a company to receive data requests. To locate data, data must be found – here DataMapper is used. ShareSimple is used to securely share (or receive) personal data. With PrivacyHub, a company gets the opportunity to automate the process from personal data entering the company’s data systems while personal data is in the company until personal data leaves the company again. The three services work separately, but can work in a symbiosis. PrivacyHub is created so that companies can start with one solution and add another if the need arises.
How ShareSimple works with DataMapper
DataMapper users find loads of sensitive data in old emails and attachments. Identifying all this sensitive data with DataMapper makes it quick and easy to clean up your inboxes. But if sensitive data keeps coming in emails, you may find yourself repeating the same steps over and over, just to keep up. By using ShareSimple sensitive information is kept out of your emails and inboxes altogether.
ShareSimple is a user-friendly add-in for Microsoft Outlook that instantly creates an encrypted connection for sharing sensitive information securely. Why is this so awesome? When you share personal data with regular email, two or more copies are created. This increases the risk of data leaks and breaches. With ShareSimple, no extra copies are made; and all data is encrypted and deleted automatically within a set data retention period.
How RequestManager works with DataMapper
DataMapper makes it easy to keep track of all the personal data you store about your customers, employees and others. But what about someone sends you a request about their data? Many of the companies we talk to say they still don’t have a system in place for receiving data requests and responding to them. Enter RequestManager. RequestManager receives, verifies and delivers all your data requests to one dashboard, then reminds you to respond on time. Then, just use DataMapper to quickly pull up all the data you store about the requester and deliver it neatly and safely before the deadline.
Get our newsletter
In our newsletter you get tips and tricks for dealing with privacy management from our founder Sebastian Allerelli.
When you sign up for our newsletter you get a license for one user to ShareSimple, which will give you a secure email in Outlook. This special offer is for new customers only, with a limit of one freebie per company.


