ONGOING INDEPENDENT COVERAGE
Questions Buyers Are Asking # Finding Personal Data Across Old Systems Before a Data Law Deadline
A new data protection law does not care how old your systems are. It asks a simple question: where does personal data live, across every system the company has ever used, and can you prove it?
Last date: 6 September 2026
A new data protection law does not care how old your systems are. It asks a simple question: where does personal data live, across every system the company has ever used, and can you prove it? Most companies can answer that for the tools they use today. Almost none can answer it cleanly for the systems from five or ten years ago — old file shares, backups, spreadsheets nobody remembers making. Kyndryl is one of the larger names now selling a tool built to find this kind of data automatically. The question worth asking is how far that tool actually reaches.
The three shapes, side by side
Modern, well-known systems | Old and forgotten systems | Data held by outside vendors | |
|---|---|---|---|
What it is | CRM, HR software, cloud storage in daily use | Old file shares, backups, retired databases, email archives | Personal data a company handed to a contractor or vendor |
How easy it is to find | Easy — someone already knows it exists | Hard — often nobody remembers it's there | Hard — it's not inside the company's own systems at all |
What proving compliance needs | A record of where it is and who can see it | Someone has to go looking for it first | A written agreement with the vendor plus proof they follow it |
Biggest risk if missed | Low — it's visible, so it gets found eventually | High — an old system nobody checks is exactly where a breach hides | High — the company is still responsible, even though someone else is holding the data |
1. Does the tool find personal data everywhere, or only in modern systems?
A tool that only searches cloud storage and current software has not actually answered the deadline question — the risk was never in the tidy systems.
Our take: Kyndryl's data security service, built on Microsoft Purview, is built to work across hybrid and multi-cloud setups. What is less clear is how well it reaches the truly old stuff — retired file shares, systems that never moved to the cloud, storage nobody has opened in years.
Ask for a real example of the tool finding personal data in an old, forgotten system — not a cloud environment it was already built to search.
2. Does it sort personal data using this law's own categories, or a generic security label?
A law defines personal data and sensitive personal data in its own specific way. A tool built for general security best practice does not automatically use the same categories.
Our reading: We could not find Kyndryl's data security work publicly tied to a different country's personal data law, as a stated example.
Ask them to show, in writing, how the tool's categories map onto this law's specific definitions — not just onto general security labels like "sensitive" or "confidential."
3. Who is responsible when the data sits with an outside vendor, not inside the company itself?
A company stays responsible for personal data even after handing it to a contractor or vendor to process. A tool that only scans a company's own systems does not solve that part of the problem.
Our reading: Kyndryl's own data-processing terms describe its role as a processor of a client's data — a company-to-company relationship. That is a different question from whether the tool also accounts for a client's own outside vendors and what they are holding.
Ask whether the coverage includes what a company's own vendors hold on its behalf, or only what sits inside the company's own systems.
4. What happens to a backup copy when someone asks for their data to be deleted?
Deleting personal data from the live system is one thing. A year-old backup copy sitting untouched somewhere is a different problem entirely, and the law does not distinguish between the two.
Our reading: I found detail on finding, sorting, and protecting personal data, but nothing public walking through what happens to backup copies specifically after a deletion request.
Ask for a specific walkthrough of what happens to backup and archive copies after a deletion request — not just the copy in daily use.
5. How fast can it turn a request into an answer, once the law sets a deadline?
A law with a fixed response window does not leave room for "we'll get back to you." Finding the data is only useful if it happens inside the time allowed.
Our reading: General capability was easy to find in public material. A real, timed example — start to finish, on an actual request — was not.
Ask for one real example: how long it took, start to finish, to answer a data request like this in a past engagement.
Where a tool like this fits
A company already running mostly on Microsoft's cloud tools, with most of its data in modern, well-documented systems, and wanting one connected place to see and manage all of it — that's a strong fit for what's being offered here.
Where it does not fit
A company with a large amount of old, on-premises, or non-Microsoft systems. A company whose personal data risk sits mostly with outside vendors rather than its own systems. Any company that needs to prove, with a real number, how fast it can respond once the law's clock starts running.
FAQs
Does this mean Kyndryl's tool doesn't work for this law? No — it means the public material doesn't yet show it mapped specifically to this law's rules. That's a gap worth asking about, not a verdict on whether the tool is any good.
Is this problem unique to Kyndryl? No. Every large IT services company selling a data-discovery tool right now faces the same three questions — old systems, outside vendors, and backup copies are the parts every generic tool struggles with first.
What's the one thing most buyers forget to ask? Whether "finding personal data" includes the data sitting with an outside vendor — most buyers only think about their own systems until it's too late.
This is a piece of opinion — our reading of what buyers should ask, based on public material available as of the date noted above. It is not a statement of fact about any company. No company mentioned pays for the mention. Any company named here can write to hello@analystlayer.com; we respond within three working days and update the piece where the input is factual, with the update dated on this page.