Skip to content

Personally identifiable information

Use Personally identifiable information (PII) to detect data that can identify an individual in messages and attachments, such as national ID numbers or passport numbers.

We recommend that you use the Sophos list. This list includes predefined content control lists (CCLs) that are selected to help detect personally identifiable information accurately.

In Search in, select where Sophos Email searches for personally identifiable information. You can search in the message subject, message body, attachment names, attachment content, or any combination of these locations.

You can use a custom list if you need to change the predefined CCL selections. When you select Use custom list, Sophos Email automatically selects the CCLs recommended for personally identifiable information. You can then add or remove CCLs, change the number of matches required to trigger the rule, and choose where Sophos Email searches for the selected CCLs.

"Personally identifiable information" custom list.

Warning

Only change the custom list if you understand how the selected CCLs affect detection. Removing recommended CCLs may reduce detection coverage, and adding unrelated CCLs may cause the rule to match more messages than expected.

To learn more about CCLs and how to configure them, see Content control lists.