Why Private Copies Are the Next Privacy Risk Frontier

Why Private Copies Are the Next Privacy Risk Frontier, by Sheila Grela.
Image: EDRM.

[EDRM Editor’s Note: The opinions and positions are those of the author.]


Introduction: The Risk No One Sees Until It Is Too Late

Privacy risk is no longer confined to structured databases or enterprise systems. Increasingly, the most significant exposure lies in what organizations do not track well, unofficial and duplicative copies of information created and stored in the ordinary course of business.

This shift is reflected in the recently updated Information Governance Reference Model version 4.1, which prompted a broader reevaluation of how organizations approach privacy, information governance, and operational risk. The updated model emphasizes lifecycle management, cross functional alignment, and the reality that information moves far beyond formal systems into everyday workflows where controls are less defined.

In practice, these copies exist everywhere, residing on laptops, in shared drives, within email threads, and across collaboration platforms. They are created for convenience and efficiency, yet often exist outside the controls organizations rely on to demonstrate compliance with privacy obligations.

The result is a growing disconnect between how organizations say they manage information and how information is actually handled in practice. That disconnect is where privacy risk is now emerging most clearly.

Defining Private Copies

For purposes of this discussion, private copies refer to unofficial or duplicative instances of information that are created, stored, or shared outside formal systems of record and established governance controls.

These may include locally saved files, email attachments, shared documents in collaboration platforms, or other copies created through routine work activities.

While the term itself is not expressly defined in the Information Governance Reference Model, the updated IGRM recognizes that information is routinely copied and transferred across systems and users throughout its lifecycle. These additional instances of information often fall outside centralized oversight, creating gaps between governance intent and operational reality.

The Shift from Systems to Operational Reality

For years, privacy compliance has been framed around systems of record. Organizations invested heavily in securing databases, implementing access controls, and developing retention schedules tied to formal repositories.

That model is no longer sufficient, particularly as the updated IGRM reinforces that information governance must account for how information is actually used, protected, retained, and transferred across the enterprise. This includes informal handling of data that occurs outside structured systems, especially as information moves through its lifecycle.

Consider a common example.

A business user exports customer data from a system into a spreadsheet for analysis. That spreadsheet is saved locally, shared by email, and later uploaded into a collaboration platform. Each step creates additional copies of personal information, often without consistent controls, tracking, or retention logic.

Even when the original system is well governed, these downstream copies often are not.

A Brief Aside: What Changed in IGRM Version 4.1

While the core concepts of the Information Governance Reference Model remain familiar, version 4.1 reflects a meaningful evolution in how governance is framed.

Earlier versions emphasized stakeholder alignment and coordination between legal, information technology, and records management functions. The updated version retains that foundation but places greater emphasis on:

  • The full lifecycle of information from creation through disposal
  • The integration of privacy as a core stakeholder and risk driver
  • The continuous interaction between policy and operational processes
  • Governance that reflects how information is handled in practice across the enterprise

This evolution brings into focus a reality that many organizations are beginning to confront. Information does not remain confined within controlled systems. Instead, it is copied, shared, and transferred in ways that introduce risk outside traditional governance boundaries. Private copies exist directly within that space.

Why Private Copies Matter More Than Ever

They Undermine Data Minimization

Privacy laws increasingly emphasize limiting retention to what is necessary. Duplicative copies make that difficult to enforce.

If the same dataset exists in multiple locations, deletion in one system does not ensure deletion elsewhere. Over time, organizations accumulate unnecessary data that increases both cost and exposure.

They Disrupt Lifecycle Governance

Information governance frameworks depend on managing data across its lifecycle from creation through disposal. Private copies introduce fragmentation into that lifecycle.

A document subject to defined retention requirements may persist indefinitely when copied into personal storage locations or external tools. This inconsistency between policy and practice undermines defensibility.

They Complicate Discovery and Regulatory Response

From an eDiscovery perspective, private copies increase both volume and uncertainty.

Organizations are often required to locate responsive documents across multiple environments and ensure completeness of their responses. When duplicative copies exist outside tracked systems, these obligations become more difficult to meet.

A common litigation scenario illustrates this point.

An organization produces records from its primary repository. At a later stage, additional responsive documents are identified in employee email accounts or personal storage locations. This increases cost and may raise questions regarding completeness and governance practices.

They Increase Breach and Incident Exposure

Unmanaged copies of sensitive information often lack the protections applied within enterprise systems.

This can lead to delayed detection of unauthorized access and increased difficulty determining the scope of an incident. When organizations cannot clearly identify where information resides, response efforts become more complex and less certain.

They Highlight the Limits of Technical Control

Information technology plays a critical role in enabling privacy compliance, but it cannot fully control data once it is copied outside managed environments.

Modern work environments are decentralized. Employees routinely use multiple tools and platforms to complete their work, often creating and moving data in ways that bypass formal controls.

This is not a failure of technology. It reflects how work is performed.

Privacy risk arises at the intersection of system capability and user behavior. The updated IGRM recognizes this reality by emphasizing cross functional collaboration and alignment between policy and practice.

Associations and Distributed Organizations

Associations and similar organizations may face heightened exposure in this area.

With distributed leadership and reliance on volunteers, information is frequently created and shared outside centralized systems. Member data, donor information, and internal communications may circulate across multiple platforms, often without consistent oversight.

These conditions increase variability in how information is handled and make it more difficult to maintain visibility and enforce consistent practices.

Why Privacy Risk Is Continuous

Privacy risk is not static. It evolves continuously as organizations operate.

Data is constantly created, copied, and shared. Technology platforms evolve, regulatory expectations expand, and business practices change.

The updated IGRM reflects this dynamic by framing governance as a continuous cycle of policy and process rather than a one time implementation.

Private copies illustrate this reality. They emerge through routine work rather than controlled processes, introducing ongoing risk into the environment.

Managing privacy risk therefore requires continuous focus and adaptation.

Rethinking the Approach

Organizations should not expect to eliminate private copies entirely. Instead, the focus should shift toward alignment.

  • Understand how information is created and shared in practice
  • Reduce unnecessary duplication
  • Align governance practices with real workflows
  • Strengthen the ability to demonstrate consistent practices
  • Integrate privacy into broader information governance frameworks

These steps reflect the broader direction of the updated IGRM, which emphasizes governance that reflects how information moves across the enterprise.

“Adopting sound information governance policies is only the first part of an information governance solution. In practice, setting up systems to execute those policies, including workable and consistent processes for applying retention rules to private copies, is essential for effective information control, compliance, and risk reduction.”

David R. Cohen, EDRM, Chair of Project Trustees, ATJustice, CEO.

Looking Ahead

Issues related to duplicative and unmanaged information are likely to receive increasing attention from regulators, courts, and practitioners.

At its core, this is an issue of accountability. Organizations are expected to understand their information environments and manage them in a manner consistent with legal and regulatory obligations.

Where there is a gap between policy and practice, risk emerges.

Conclusion

Private copies are not new. Their significance has changed.

As privacy expectations evolve, unofficial and duplicative forms of information are becoming central to risk analysis. They challenge traditional assumptions about control, visibility, and compliance.

The updated Information Governance Reference Model underscores that governance must reflect the full lifecycle of information and the reality of how it is used across the enterprise. Private copies demonstrate where that alignment often breaks down.

Organizations that recognize this shift and respond accordingly will be better positioned to manage risk in an increasingly complex environment.

Those that do not may find that their greatest exposure lies not in the systems they control, but in the copies they do not.



Assisted by GAI and LLM Technologies per EDRM’s GAI and LLM Policy.

Author

  • Sheila Grela

    Sheila Grela is a paralegal at Buchalter, founder of Virtual Lunch with Leaders at the San Diego Paralegal Association (SDPA), and the Program Director of San Diego Chapter Women in eDiscovery. She is on the Continuing Education Counsel and is a published author for Facts and Findings committee for the National Association of Legal Assistants – The Paralegal Association (NALA). Sheila is an EDRM Global Advisory Council leader and was awarded the Gayle O'Connor (GO) Spirit Award in 2022.

    View all posts