Ghost data detection

Catch undeclared PII findings before they become privacy drift.

Chameleon records ghost-data findings from configured warehouse scans and turns them into reviewable policy work for data, privacy, and compliance teams.


Why it matters

Scanner findings

Capture findings from configured warehouse scans so suspicious customer-data fields do not live only in logs.

Policy drift

Show when a column, model, or derived identifier needs registration, removal, or review against warehouse policy.

Actionable review

Give each finding a resource, pattern, severity, row context, and recommended action for follow-up.


The problem

Undeclared PII is the data you get fined for.

Ghost data is personal data that ended up in the warehouse without being registered or governed — an email address nested in a JSON blob, a phone number pasted into a free-text field, a customer name that rode along in an export and got joined into a mart. Nobody decided to store it there, so nobody is watching it.

That is exactly the data that fails an audit. When you assert you have deleted a customer's information, an undeclared copy in a derived table quietly contradicts you. Ghost-data detection exists to surface those copies before a regulator, a breach, or a DSAR does.


How it works

Turn scanner noise into reviewable policy work.

Configured scans flag columns whose contents look like personal data even though the registry does not declare them. Instead of burying those hits in a log file, Chameleon records each one as a finding with a resource, a matched pattern, a severity, sample row context, and a recommended action.

From there the finding becomes a decision, not a mystery: register the column and attach a deletion strategy, remove the source data, or confirm aggregate-only handling. Every finding has an owner and a status, so privacy drift is measured and closed instead of accumulating silently.


Chameleon workflow
01 / Scan

Configured scans flag fields that look like undeclared email, phone, identifier, or derived customer data.

02 / Record

Findings are captured with resource, column, pattern, count, and recommended action.

03 / Route

Teams decide whether to register the column, remove source data, or keep aggregate-only handling under review.

04 / Track

Policy status and ghost-data counts remain visible in the demo control plane.


Proof surface
finding: GHOST_DATA
resource: chameleon_dev.stg_users
column: data.email
action: register column or remove source data

FAQ

Common questions

What is ghost data?

Ghost data — sometimes called dark data — is personal or sensitive data that exists in your systems without being registered, classified, or governed. It typically arrives through free-text fields, nested JSON, copied exports, or derived tables, and it is a common source of audit findings because no one is actively managing it.

How is ghost data different from declared PII?

Declared PII is data you know about and have attached a policy and deletion strategy to. Ghost data is the same kind of sensitive information, but undeclared — so it is excluded from your deletion workflows and your compliance inventory until a scan surfaces it.

Why is undeclared PII an audit risk?

Because you cannot prove you deleted data you did not know you had. An undeclared copy of a customer's data in a derived table or backup directly contradicts an erasure claim, and Article 5(2) of GDPR requires you to be able to demonstrate compliance — including completeness.


Keep reading

The registry that ghost-data findings are measured against — a live map of declared personal data.