4

Personal Data Access Assurance

SL-05

Continuous monitoring of every identity that touches personal data. Behavioural baselines per identity, joint risk scoring that combines behaviour with the sensitivity of what was accessed, and automated containment before an anomaly becomes an exfiltration.

DischargesS.8(4)R.6S.6
Identities monitored
68
New anomalies
15
View
Critical open
8
Excessive permissions
468
View
Leavers with access
3
With children's data access
19
Anomalies and containment

Detections raised against automated containment actions over the last fortnight.

Identity population

Service accounts are the blind spot.

  • Employee39
  • Privileged administrator9
  • Service account13
  • API / automation identity3
  • Contractor / partner4
Anomaly types

What the baselines are actually catching.

All anomalies
Highest-risk identities

Composite of behaviour deviation, permission exposure and the sensitivity of data reached.

All identities
  • Criticalsvc_scheme_syncService accountNo MFAChildrenSuspended973 anomalies
  • CriticalRahul BhattPrivileged administratorNo MFA920 anomalies
  • CriticalLeela MishraEmployeeChildren920 anomalies
  • CriticalYash PatelEmployee912 anomalies
  • Criticalsvc_warehouse_etl_2API / automation identityNo MFAChildren900 anomalies
  • Criticalsvc_scheme_sync_20Service accountNo MFA891 anomalies
Response playbooks

The signal chains that trigger automated containment. Each ends in an outcome, not just an alert.

Configure
Compromised user account7 triggers

An identity suddenly accesses large volumes of classified personal data outside its baseline.

Outcome: Extraction is stopped before it becomes a reportable breach, or the reportable scope is materially reduced.

Last triggered yesterday

Insider data misuse14 triggers

A legitimate user accesses personal data outside the purpose assigned to their role.

Outcome: The incident is identified before mass extraction rather than after it.

Last triggered 4 days ago

Privileged account abuse4 triggers

An administrator accesses unstructured repositories containing personal data with no operational reason.

Outcome: Chain of custody is preserved and the department's defensibility is maintained.

Last triggered 3 months ago

Consent withdrawal enforcement21 triggers

Consent is withdrawn, the data has not yet been erased, and an identity attempts to access it.

Outcome: Processing genuinely stops on withdrawal rather than waiting for the erasure batch — the difference between compliance and a grievance.

Last triggered 2 days ago

Related