GDPR File-Level Discovery and DSARs
GDPR file-level discovery is finding, classifying, and governing personal data inside files. Documents, spreadsheets, PDFs, emails. Not just structured database records. It is what lets you answer a data subject access request (DSAR) or "right to erasure" accurately when personal data lives in files scattered across SharePoint, cloud storage, and file shares.
File-level vs record-level discovery
Record-level discovery finds personal data in structured rows and columns: databases, CRMs. File-level discovery finds it inside documents, spreadsheets, and emails. A name buried in a contract. An ID number in a scanned PDF. PII in an email attachment. Personal data in an enterprise lives overwhelmingly in files, not databases. Record-level tools alone leave the majority of a data subject access request unaddressed.

Why files are the hard part of GDPR
Data subject access requests, erasure requests, and Article 30 records all require knowing where a person's data is. In file estates, that means opening files at scale. Nested archives, scans needing OCR, email attachments. Everything has to be classified. Manual review does not scale to millions of files. And a "redaction" that only draws a black box over text an examiner can still extract is not compliant deletion.