
[EDRM Editor’s Note: The opinions and positions are those of the author.]
Introduction: The Risk No One Sees Until It Is Too Late
Privacy risk is no longer confined to structured databases or enterprise systems. Increasingly, the most significant exposure lies in what organizations do not track well, unofficial and duplicative copies of information created and stored in the ordinary course of business.
This shift is reflected in the recently updated Information Governance Reference Model version 4.1, which prompted a broader reevaluation of how organizations approach privacy, information governance, and operational risk. The updated model emphasizes lifecycle management, cross functional alignment, and the reality that information moves far beyond formal systems into everyday workflows where controls are less defined.
In practice, these copies exist everywhere, residing on laptops, in shared drives, within email threads, and across collaboration platforms. They are created for convenience and efficiency, yet often exist outside the controls organizations rely on to demonstrate compliance with privacy obligations.
The result is a growing disconnect between how organizations say they manage information and how information is actually handled in practice. That disconnect is where privacy risk is now emerging most clearly.
Defining Private Copies
For purposes of this discussion, private copies refer to unofficial or duplicative instances of information that are created, stored, or shared outside formal systems of record and established governance controls.
These may include locally saved files, email attachments, shared documents in collaboration platforms, or other copies created through routine work activities.
While the term itself is not expressly defined in the Information Governance Reference Model, the updated IGRM recognizes that information is routinely copied and transferred across systems and users throughout its lifecycle. These additional instances of information often fall outside centralized oversight, creating gaps between governance intent and operational reality.
The Shift from Systems to Operational Reality
For years, privacy compliance has been framed around systems of record. Organizations invested heavily in securing databases, implementing access controls, and developing retention schedules tied to formal repositories.
That model is no longer sufficient, particularly as the updated IGRM reinforces that information governance must account for how information is actually used, protected, retained, and transferred across the enterprise. This includes informal handling of data that occurs outside structured systems, especially as information moves through its lifecycle.
Consider a common example.
A business user exports customer data from a system into a spreadsheet for analysis. That spreadsheet is saved locally, shared by email, and later uploaded into a collaboration platform. Each step creates additional copies of personal information, often without consistent controls, tracking, or retention logic.
Even when the original system is well governed, these downstream copies often are not.
A Brief Aside: What Changed in IGRM Version 4.1
While the core concepts of the Information Governance Reference Model remain familiar, version 4.1 reflects a meaningful evolution in how governance is framed.
Earlier versions emphasized stakeholder alignment and coordination between legal, information technology, and records management functions. The updated version retains that foundation but places greater emphasis on:
- The full lifecycle of information from creation through disposal
- The integration of privacy as a core stakeholder and risk driver
- The continuous interaction between policy and operational processes
- Governance that reflects how information is handled in practice across the enterprise
This evolution brings into focus a reality that many organizations are beginning to confront. Information does not remain confined within controlled systems. Instead, it is copied, shared, and transferred in ways that introduce risk outside traditional governance boundaries. Private copies exist directly within that space.
Why Private Copies Matter More Than Ever
They Undermine Data Minimization
Privacy laws increasingly emphasize limiting retention to what is necessary. Duplicative copies make that difficult to enforce.
If the same dataset exists in multiple locations, deletion in one system does not ensure deletion elsewhere. Over time, organizations accumulate unnecessary data that increases both cost and exposure.
They Disrupt Lifecycle Governance
Information governance frameworks depend on managing data across its lifecycle from creation through disposal. Private copies introduce fragmentation into that lifecycle.
A document subject to defined retention requirements may persist indefinitely when copied into personal storage locations or external tools. This inconsistency between policy and practice undermines defensibility.
They Complicate Discovery and Regulatory Response
From an eDiscovery perspective, private copies increase both volume and uncertainty.
Organizations are often required to locate responsive documents across multiple environments and ensure completeness of their responses. When duplicative copies exist outside tracked systems, these obligations become more difficult to meet.
A common litigation scenario illustrates this point.
An organization produces records from its primary repository. At a later stage, additional responsive documents are identified in employee email accounts or personal storage locations. This increases cost and may raise questions regarding completeness and governance practices.
They Increase Breach and Incident Exposure
Unmanaged copies of sensitive information often lack the protections applied within enterprise systems.
This can lead to delayed detection of unauthorized access and increased difficulty determining the scope of an incident. When organizations cannot clearly identify where information resides, response efforts become more complex and less certain.
They Highlight the Limits of Technical Control
Information technology plays a critical role in enabling privacy compliance, but it cannot fully control data once it is copied outside managed environments.
Modern work environments are decentralized. Employees routinely use multiple tools and platforms to complete their work, often creating and moving data in ways that bypass formal controls.
This is not a failure of technology. It reflects how work is performed.
Privacy risk arises at the intersection of system capability and user behavior. The updated IGRM recognizes this reality by emphasizing cross functional collaboration and alignment between policy and practice.
Associations and Distributed Organizations
Associations and similar organizations may face heightened exposure in this area.
With distributed leadership and reliance on volunteers, information is frequently created and shared outside centralized systems. Member data, donor information, and internal communications may circulate across multiple platforms, often without consistent oversight.
These conditions increase variability in how information is handled and make it more difficult to maintain visibility and enforce consistent practices.
Why Privacy Risk Is Continuous
Privacy risk is not static. It evolves continuously as organizations operate.
Data is constantly created, copied, and shared. Technology platforms evolve, regulatory expectations expand, and business practices change.
The updated IGRM reflects this dynamic by framing governance as a continuous cycle of policy and process rather than a one time implementation.
Private copies illustrate this reality. They emerge through routine work rather than controlled processes, introducing ongoing risk into the environment.
Managing privacy risk therefore requires continuous focus and adaptation.
Rethinking the Approach
Organizations should not expect to eliminate private copies entirely. Instead, the focus should shift toward alignment.
- Understand how information is created and shared in practice
- Reduce unnecessary duplication
- Align governance practices with real workflows
- Strengthen the ability to demonstrate consistent practices
- Integrate privacy into broader information governance frameworks
These steps reflect the broader direction of the updated IGRM, which emphasizes governance that reflects how information moves across the enterprise.
“Adopting sound information governance policies is only the first part of an information governance solution. In practice, setting up systems to execute those policies, including workable and consistent processes for applying retention rules to private copies, is essential for effective information control, compliance, and risk reduction.”
David R. Cohen, EDRM, Chair of Project Trustees, ATJustice, CEO.
Looking Ahead
Issues related to duplicative and unmanaged information are likely to receive increasing attention from regulators, courts, and practitioners.
At its core, this is an issue of accountability. Organizations are expected to understand their information environments and manage them in a manner consistent with legal and regulatory obligations.
Where there is a gap between policy and practice, risk emerges.
Conclusion
Private copies are not new. Their significance has changed.
As privacy expectations evolve, unofficial and duplicative forms of information are becoming central to risk analysis. They challenge traditional assumptions about control, visibility, and compliance.
The updated Information Governance Reference Model underscores that governance must reflect the full lifecycle of information and the reality of how it is used across the enterprise. Private copies demonstrate where that alignment often breaks down.
Organizations that recognize this shift and respond accordingly will be better positioned to manage risk in an increasingly complex environment.
Those that do not may find that their greatest exposure lies not in the systems they control, but in the copies they do not.
Links:
- Information Governance Reference Model – EDRM
- IGRM v4.1 (PNG download)
- IGRM v4.1 User Guide (PDF download)
Assisted by GAI and LLM Technologies per EDRM’s GAI and LLM Policy.

