Legal

Notice to employees

A notice an employer can adapt and send to its people before a scan begins. Written to be read once and understood.

Version
0.1
Drafted
15 Sep 2026
In force from
Not in force
Draft for review

This is a draft for review and a template. Adapt it to your organisation and check it against your own information obligations before you send it. The facts about the product in it are accurate to this release.

1

What we are doing

[Your organisation] is going to use a tool called Pritect Sonar to find out where personal data is stored in our [Microsoft 365 / Google Workspace] systems. We are doing this so that we know what personal data we hold, where it is, and whether any of it is shared more widely than it should be. That is something we are required to know, and at the moment we only partly do.

This notice tells you what the tool looks at, what it records, what it cannot do, and who to ask about it. It is worth two minutes.

2

What it looks at

It reads the files and, where we have chosen to include them, the mail in the parts of our systems we have put in scope. Here is what we have put in scope:

  • [SharePoint sites: which ones.]
  • [OneDrive: whose, or all.]
  • [Shared drives: which ones.]
  • [Mailboxes: whose, or none. If none, say none plainly, because it is the question people most want answered.]

Teams chat and channel messages are not read. The tool covers the files behind Teams, in SharePoint and OneDrive, and not the conversations.

3

What it records, and what it does not

The tool reads a document, works out what kind of personal data is in it, and then throws the document away. It does not keep a copy. What it writes down is a note about the document.

A note looks like this: a spreadsheet in a named location contains national identity numbers, there are about forty of them, and they are in column D. It does not record what any of those numbers is, and it cannot show them to anyone afterwards, because it never wrote them down.

It also records the name and the folder path of the file, so that somebody reviewing the note can open the file itself in the normal way, with their normal permissions. Opening the file is a person doing what they could already do, not the tool showing them something new.

4

Four things it cannot do

These are limits built into the product, not promises about how we intend to use it.

  • It cannot search for a person. There is no way to ask it where a named individual's data is. That capability does not exist in the version we are using.
  • It cannot show anyone the content of anything. No text, no message body, no attachment and no excerpt is stored anywhere, so there is nothing for it to show.
  • It cannot monitor productivity, conduct or communications. It reports on documents and where they sit, not on people and what they do.
  • It cannot change anything in our systems. It has read access only. It cannot move, delete, label or share a file.

5

The one place a person is named

The tool records who owns a site, a drive or a mailbox, because knowing that a drive belongs to a departed colleague is exactly the kind of thing we need to find. That is the only place an individual appears.

Showing those names is a setting, it is off unless we turn it on, and while it is off the underlying system returns nothing for them rather than the screen simply hiding them. [Say here whether you have turned it on, and if so, who can see it.] Every change to that setting is written to a log that nobody can edit or delete, including the supplier.

6

Where it runs and who else is involved

The tool runs in the European Union, in [Frankfurt]. The supplier uses four other companies to run it: one for the database, one for the website, one for the machine that does the reading, and one that helps classify a passage where the pattern matching is not sure. All four process in the EU. Two of them ever see content, and only in memory, for the moment it takes to classify it.

Microsoft and Google are not part of the supplier's arrangements. Our files and mail already sit with them under our own agreements, and that has not changed.

7

Your rights, and who to ask

Our lawful basis for this is [legitimate interests / compliance with a legal obligation], and our full privacy notice for employees is at [link]. Your rights under it are unchanged: you can ask what personal data we hold about you, ask for it to be corrected, and object to processing based on legitimate interests.

If you want to know more, or you are uncomfortable with any of this, contact [role, for example the data protection officer] at [contact]. [Where there is a works council or employee representative body, name it here and say what it has been told.]

We would rather answer a question now than have somebody find out about this from a colleague later.