Upload any CSV, Excel or JSON file and get an instant report showing which columns contain personal data, how sensitive it is, and what GDPR says about it.
Any information that can identify a living person — directly (their name, email) or indirectly (their employee ID, login alias, or tour ID combined with other data).
Sharing a file with employee emails, login aliases, or management hierarchy chains outside Amazon without proper controls is a GDPR violation. Fines can reach €20 million or 4% of global turnover.
Every person whose data you hold has the right to access it, correct it, or request deletion. Knowing exactly what data you hold is the first step to compliance.
It scans column headers and actual cell values in your file, matches them against GDPR risk patterns, and tells you exactly which fields are a concern — and why.
The most protected class under GDPR Article 9. Processing is prohibited by default under Art. 9(1) and needs both an Art. 6 lawful basis and a separate Art. 9(2) condition — two tests, not one. Art. 10 (criminal convictions and offences, including alleged offences) additionally requires official authority or a Member State law authorising it.
Fields that directly name or reach a specific person. No inference needed — the data alone identifies someone.
Fields that don't name someone directly but can identify them when combined with other data. Still personal data under GDPR.
The scanner looks inside the actual cell values, not just column names. It uses regex patterns to detect personal data hiding in unexpected columns.
Drop in a CSV, Excel (.xlsx/.xls), JSON, TSV or TXT file. Nothing leaves your browser — all processing happens locally on your machine.
Pass 1 checks every column header against 29 GDPR rules. Pass 2 samples up to 200 rows per column and runs 9 regex patterns on the actual values.
Get a risk score, category breakdown and sortable findings table. Export a clean HTML report to share with your team or compliance lead.
| Level | Score per field | What it means | Examples |
|---|---|---|---|
| Critical | +20 pts | Art.9 special categories, Art.10 criminal-offence data, or unique identifiers. Needs an Art. 6 basis plus an Art. 9(2) condition or Art. 10 authorisation. | SSN, passport, IBAN, health data, biometrics, criminal record |
| High | +12 pts | Direct identifiers that clearly point to a person. Should never appear in shared files without pseudonymisation. | Email, phone, full name, date of birth, IP address, GPS |
| Medium | +6 pts | Indirect identifiers. Low risk alone but can identify someone in combination with other fields. | Login alias, employee ID, gender, age, address, device ID |
| Low | +2 pts | Operational IDs loosely linked to people. Worth noting but unlikely to cause a violation on their own. | Tour ID, contract ID, session token |
Upload a data file to detect personal data fields and assess compliance risk
Build 2.3 · scans every sheet · minimisation + singling-out + DPIA analysis · 25 file formats
Drag & drop your file here
or
Tabular CSV · TSV · XLSX · XLS · XLSM · ODS · JSON
Documents PDF · DOCX · PPTX · ODT · XML · HTML · TXT · MD · LOG
Images (OCR) PNG · JPG · WEBP · BMP · TIFF
Every sheet in a workbook is scanned, not just the first. PDF and image reading downloads its engine on first use.