PII Data Scanner for Files
Find the personal data in your files before you share, migrate or delete them.
Free preview.
- Free preview: every count of the personal data in one of your files, with the first rows of its inventory (up to 10); of several files, the first ones (up to 3).
- Locked until you unlock it: download.
- Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews. Batch runs unlock with a pass only.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Files to scan
Spreadsheets, CSV, JSON, text and log files, Word documents and PDFs with a text layer — one or many at once. The files are read on this device and never uploaded.
Personal data inventory
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the PII Data Scanner for Files
Before you share an export with a vendor, migrate a database, answer an access request or delete old files, find out what personal data is in them. Choose your files — CSV and spreadsheets, JSON, text and log files, Word documents and PDFs with a text layer, many at once — and the scanner lists, for each file and each column or field, the kind of personal data it holds, how many values and how many different ones, with masked examples and how sure each match is.
It finds e-mail addresses, phone numbers for the country you choose, card numbers with a valid Luhn check digit, IBANs, Aadhaar numbers with a valid Verhoeff check digit, PAN, GSTINs with a valid check character, UPI IDs, US Social Security numbers, UK National Insurance numbers, NHS numbers with a valid modulus 11 check, IP and MAC addresses and dates of birth. Column and field names point to the rest — names, postal addresses, salaries and the special categories of GDPR Article 9 such as health and religion. The free preview shows every count of one file with the first rows of its inventory — of several files, the first ones; scanning many files at once, the full inventory, the CSV for your record of processing and the PDF report need a Premium pass. The files never leave your device.
How to use it
- Choose or drop your files — one or many. Press Scan the sample to see the result on a made-up customer list first.
- Under What to look for, choose the country of phone numbers written without + and how dates are written, and switch off any pattern you do not need.
- Read the summary — how many values of each kind — and each file’s inventory: where the data is, the kind, the counts, masked examples and the confidence. Low confidence means a check digit matched in only a few values of a column: look-alike numbers are likely.
- With a Premium pass, use Inventory (CSV) to seed your record of processing activities and Report (PDF) for the file; without one, the page shows the free preview.
- Mask or remove what is not needed with the PII Redactor or PDF Redact, and set how long to keep the rest with the Data Retention Schedule Generator.
Examples
4 customers · columns Customer ID, Full name, Email, Phone, Date of birth, Postcode, Card number, IBAN, Notes
E-mail addresses 4, names 4, postal addresses 4, dates of birth 4, phone numbers 3, customer IDs 4, a card number, an IBAN, and in the notes an Aadhaar number, a US Social Security number and an IP address.
Every number in the sample is a published test or documentation value.
[{"customer": {"name": "…", "email": "…"}, "messages": [{"text": "my card is 4111 1111 1111 1111"}]}]Fields customer.name (names, from the field name), customer.email (e-mail addresses) and messages[].text (a card number found in running text).
Sheets “Staff” and “Absence” · columns Employee ID, Name, Sick leave reason, Salary
Health data (special category, from the column name), names, salaries and staff IDs — a sign the file needs an Article 9 condition and tight access.
Common uses
- Checking an export before it goes to a vendor, an agency or an AI tool.
- Mapping the personal data in shared drives and old exports for a record of processing activities.
- Finding where card numbers, Aadhaar numbers or national insurance numbers ended up in logs and spreadsheets.
- Preparing a data migration or a clean-up: what has to move, be masked or be deleted.
How each kind is found
- Checked numbers: card numbers pass the Luhn check (ISO/IEC 7812-1), IBANs the MOD 97-10 check (ISO 13616), Aadhaar numbers the Verhoeff check, GSTINs their mod-36 check character, NHS numbers the modulus 11 check of the NHS Data Dictionary; US Social Security and UK National Insurance numbers follow the issuers’ rules for numbers never issued.
- Formats: e-mail addresses, PAN, UPI IDs, IP and MAC addresses (private, loopback and documentation addresses are left alone unless you untick the option); phone numbers are checked with the libphonenumber metadata for the country you choose, or must start with +.
- Context: NHS numbers count only in a column named for them or after the word “NHS”, and dates of birth only in a column named for them or after “date of birth”, “DOB” or “born” — any other date could be an invoice date.
- Names of columns and fields: names, addresses, ages, nationality, passport and licence numbers, bank accounts, salaries, usernames, passwords and the special categories are reported from the column or field name, marked “from the name”.
Special category data
Racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to identify a person, health data and data about a person’s sex life or sexual orientation are special categories under Article 9; criminal convictions and offences fall under Article 10. Recital 35 counts a number assigned to identify a person for health purposes — an NHS number — as health data. Processing them needs a condition of Article 9 as well as a lawful basis, and usually a data protection impact assessment (ICO).
From the inventory to a record of processing
Article 30 asks for a record of the categories of data subjects and personal data, the purposes, the recipients, transfers, the time limits for erasure and the security measures. The inventory CSV lists each file, sheet and column with the kind of data, its category and whether it is a special category, and leaves columns ready for the data subjects, purposes, lawful basis, recipients, transfers, retention and security measures you fill in.
Confidence
- High: a check digit or format matched in at least half of a column, or the column is named for the data.
- Medium: matches in part of a column, or a column name alone.
- Low: a check-digit match in only a few values of a column — about one random 16-digit number in ten passes the Luhn check, and one random 12-digit number in ten the Verhoeff check, so order numbers and IDs can look like card or Aadhaar numbers.
Limitations
- Patterns miss names, addresses and other details written in running text, and can flag numbers that only look like identifiers. Read the inventory as a starting point, not a guarantee that a file is clean.
- Scanned PDFs and images have no text to read: run PDF OCR or Image to Text first, then scan the text. Password-protected files are skipped.
- Up to 50 files at a time, 50 MB each; in each file up to 200,000 rows or 2,000,000 cells, or 20 million characters of text; in a JSON file, lists up to 1,000 items and nesting up to 12 levels. Whatever lies past a limit is named in the file’s notes, never skipped silently.
- It reports what the data is, not whether you may hold it: the lawful basis, the purpose and the retention period are yours to decide. Not legal advice.
Privacy
Your files are read and scanned in your browser and never uploaded or stored. The report shows masked examples only. Only your choices under What to look for are remembered in this browser.
Frequently asked questions
What do I get without a pass?
Without a pass, PII Data Scanner for Files shows every count of the personal data in one of your files, with the first rows of its inventory (up to 10); of several files, the first ones (up to 3). Until you unlock it, the result can’t be downloaded. A Premium or Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
Are my files uploaded?
No. They are read in your browser, on this device; nothing in them is sent or stored. The readers for spreadsheets, Word, PDF and phone numbers are downloaded from this site the first time they are needed.
Does it find names in running text?
No. Recognising names reliably needs a language model and still misses many, which would give a false sense of safety. Names are reported from column and field names (“Full name”, “customer.name”); to hide names in text, list them in the PII Redactor.
Why is a card number marked low confidence?
Because only a few values of its column passed the Luhn check. About one random 16-digit number in ten passes it, so an order-number column will show a few “card numbers” by chance. A real card column passes in almost every row and is marked high.
What can I do with the inventory?
Seed your record of processing activities (GDPR Article 30), decide what to mask or delete before you share or migrate a file, check where special category data is, and set retention periods. The CSV leaves the columns a record of processing needs ready to fill in.
Do I need a pass?
To scan many files at once, see the whole inventory or download the CSV and the PDF report, yes: a Premium pass unlocks every Premium tool. Without a pass you see a free preview of your own result: every count of one file with the first rows of its inventory, or of several files the first ones.
Which files can it read?
CSV and TSV, Excel (XLSX, XLSM, XLSB, XLS) and OpenDocument (ODS) spreadsheets with every sheet, JSON and JSON Lines, text, log, Markdown, HTML, XML and vCard files in UTF-8, UTF-16 (Excel’s “Unicode text”) or Windows-1252, Word documents (DOCX) and PDFs with a text layer. Older Word (.doc), PowerPoint and Outlook files need saving as DOCX, PDF or text first.