Structured vs Unstructured Data Risk
The Database Is Governed. The Shared Drive Is Not. Both Hold Your Data.
9 min read · 11 July 2026 · Privacy
A healthcare vendor's data security assessment looked thorough on paper: database encryption confirmed, role-based access controls documented, audit logging enabled, backup encryption verified. The structured data handling was well-governed. What the assessment did not surface , because nobody asked , was that the vendor's customer service team stored patient intake forms, insurance documents, and correspondence in a shared Microsoft Teams channel attached to a SharePoint folder. The folder had never been classified. It had never been included in the data governance program. The permissions had been set by the first person who created the folder and had never been reviewed. The access logs for the SharePoint folder did not exist because SharePoint audit logging had never been enabled for that workspace. A data breach investigation later found that the folder had been accessible to all two hundred employees of the vendor, including contractors, for four years. The structured data was secure. The unstructured data, which contained equivalent sensitivity, had never been within scope of any governance program.
Why this matters
The unstructured data risk dimension matters for TPRM because vendor assessments that focus on structured data security , database encryption, access controls, audit logging , systematically miss the majority of the data surface where customer-sensitive information is likely to exist and least likely to be governed. A vendor whose database is excellently secured and whose collaboration platforms hold years of ungoverned customer correspondence has a data security posture that the structured data assessment accurately describes for twenty percent of the picture and says nothing about for the other eighty.
The regulatory implication is direct. Data protection regulations including GDPR, CCPA, and HIPAA apply to personal data regardless of its format or storage location. A patient's name in a database field and a patient's name in a scanned intake form stored in a SharePoint folder are both personal data subject to the same regulatory protections. The regulator's inquiry about data breach scope will ask about all locations where the patient's information existed , not just the structured database that the vendor's data governance program covers. If the unstructured repositories are ungoverned, their scope, access history, and breach impact cannot be determined , creating the same investigation gap that inadequate logging creates, but arising from data discovery failure rather than logging failure.
From a data minimization perspective, unstructured data accumulation is where most organizations , and their vendors , carry their greatest excess data exposure. Structured databases typically have defined retention policies and automated deletion processes. Unstructured repositories accumulate indefinitely because there is no automated process to review document relevance, apply retention policies to individual files, or delete documents that have exceeded their retention period. A vendor relationship that began years ago may have left a trail of intake documents, support tickets, and correspondence containing customer personal data in unstructured repositories that have never been subject to deletion, never been classified, and never been assessed.
Where most teams get this wrong
The most pervasive failure is scoping data security assessment to structured data systems , databases, data warehouses, and formal data management platforms , without asking about the unstructured data that accumulates through the vendor's operational interactions with customer data. The assessment covers the tier of data the vendor explicitly manages and misses the tier that accumulates through normal business operations. Most TPRM questionnaires ask about database encryption, database access controls, and database audit logging. They rarely ask about document management governance, collaboration platform security, or email retention and access controls.
The second failure is not asking vendors to enumerate all locations where customer data might exist , not just the primary system of record but every system that might contain a copy, a working file, a support ticket, or a communication referencing customer personal data. In most organizations, the actual population of locations where customer data exists is significantly larger than the population of locations that the data governance program explicitly covers. The gap between those two populations is the unstructured data risk that no structured data assessment will surface.
- Assessment scoped to structured data systems , databases and formal data platforms assessed without equivalent coverage of document stores, collaboration platforms, and email systems
- No inventory of all customer data locations , assessment of primary systems without asking where else customer data might accumulate through operational processes
- Collaboration platform governance not assessed , Teams, Slack, SharePoint, and equivalent platforms not included in data security assessment scope
- Shadow file storage not addressed , no assessment of whether vendor employees store working copies of customer data in personal or ungoverned storage
- Retention policy scoped to structured data , deletion and retention governance covering databases but not the document and communication repositories where data accumulates indefinitely
What good looks like
Mature vendor data governance programs treat unstructured data with the same intentionality as structured data , discovering where it exists, classifying it, applying access controls, enforcing retention policies, and including it in audit and monitoring scope. The coverage is comprehensive rather than selective, reflecting the reality that sensitive data exists in documents and communications as surely as it exists in databases.
- Comprehensive data inventory , all locations where customer data may exist documented, including document stores, collaboration platforms, email archives, and helpdesk systems alongside primary databases
- Unstructured data classification and discovery , data discovery tools applied to document repositories and collaboration platforms to identify and classify sensitive content, not just to structured databases
- Collaboration platform governance , access controls, retention policies, and audit logging enabled for collaboration platforms handling customer data, equivalent to governance applied to primary data systems
- Retention automation for unstructured data , automated retention policy enforcement that applies to documents and communications as well as database records, preventing indefinite accumulation
- Shadow storage controls , policies and technical controls preventing vendor employees from storing customer data in personal drives or ungoverned cloud storage
- Incident scope including unstructured data , breach investigation procedures that include unstructured repositories in scope assessment, not limited to primary structured systems
Tooling
Governing unstructured data requires tools that can discover, classify, and apply controls to content across heterogeneous repositories , a fundamentally different technical challenge from structured database governance.
Unstructured Data Discovery and Classification , Microsoft Purview, Varonis, BigID, Spirion
These platforms apply content analysis to unstructured repositories , scanning documents, emails, and collaboration platform content for sensitive data patterns including personal identifiers, financial information, health data, and credentials. Microsoft Purview provides native integration with Microsoft 365 collaboration platforms, enabling classification and governance of Teams, SharePoint, and Exchange content. Varonis specializes in file system and collaboration platform governance, providing access intelligence and alerting for unstructured data repositories. For TPRM practitioners, asking whether a vendor uses data discovery tooling that covers unstructured repositories alongside databases surfaces whether their data governance program reflects the full data surface.
Collaboration Platform Security , Microsoft Defender for Office 365, Google Workspace DLP, Nightfall
Collaboration platform security tools apply DLP policies to Teams, Slack, Google Workspace, and equivalent platforms , detecting and preventing sensitive data from being shared through uncontrolled channels. Nightfall provides API-based DLP for cloud collaboration platforms that may not have native security tooling. For TPRM practitioners, asking whether the vendor has DLP coverage extending to collaboration platforms , not just email and file storage , surfaces whether the most common unstructured data accumulation vector is governed.
Information Lifecycle Management , Microsoft 365 Compliance, OpenText, Micro Focus
Information lifecycle management platforms apply retention policies, legal holds, and deletion governance to unstructured data repositories , ensuring that documents and communications are retained for required periods and deleted when retention requirements are met. Automated retention policy enforcement is the only practical mechanism for managing the volume of unstructured data that accumulates through normal business operations. For TPRM practitioners, asking whether the vendor has automated retention policy enforcement that covers unstructured repositories alongside structured data systems surfaces whether retention governance is systematic or selective.
Endpoint DLP , Microsoft Purview Endpoint DLP, CrowdStrike, Forcepoint
Endpoint DLP tools prevent sensitive data from being copied to removable media, personal cloud storage, or ungoverned file locations from employee devices , addressing the shadow file storage problem at the endpoint level. For vendors whose employees access customer data on managed devices, endpoint DLP provides the technical control that prevents uncontrolled copies from accumulating outside enterprise governance. For TPRM practitioners, asking whether the vendor has endpoint DLP that prevents customer data from being stored in ungoverned locations addresses the shadow storage risk that collaboration platform governance alone does not cover.
Governance challenges
The governance challenge with unstructured data is the discovery problem , you cannot govern what you cannot find, and unstructured data exists across a heterogeneous landscape of repositories that may not be fully known even to the organization's own IT team. A new collaboration workspace created by a product team, a personal OneDrive folder used by a customer success manager, a helpdesk instance spun up for a specific customer segment , each of these can accumulate customer-sensitive content outside the organization's formal governance framework without triggering any alert or requiring any approval. Governing unstructured data requires both technical discovery capability and a cultural expectation that sensitive data is only stored in governed locations.
For TPRM programs, the practical governance question is whether the vendor has a comprehensive data inventory that includes unstructured repositories and whether their data governance program applies to that full inventory rather than just the primary structured systems. The evidence standard for unstructured data governance is necessarily different from structured data , database access logs provide precise evidence, while unstructured data governance evidence may include data discovery tool outputs, DLP policy documentation, and retention policy configuration. Adjusting evidence expectations to reflect the different nature of unstructured data governance is necessary for meaningful assessment.
- Ask for a comprehensive data inventory , all locations where customer data may exist, not just the primary system of record
- Include collaboration platforms in assessment scope , Teams, Slack, SharePoint, and email systems are primary unstructured data repositories for most organizations
- Ask about data discovery tool coverage , whether discovery and classification tooling covers unstructured repositories alongside databases
- Require retention policy evidence for unstructured data , confirmation that retention governance applies to documents and communications, not just database records
- Ask about shadow storage controls , what prevents vendor employees from storing customer data in personal or ungoverned locations
If you are a small team
Add one question to your data security assessment that opens the unstructured data conversation: beyond your primary database systems, what other locations within your environment might contain customer data we have shared with you , including document storage, collaboration platforms, email systems, helpdesk tools, and any working files on employee devices? That question forces a comprehensive data inventory response rather than a database-focused one, and the answer will almost always surface unstructured repositories that were not previously in scope for your assessment. For your highest-risk vendors, follow up by asking what governance applies to those repositories specifically.
- Add a comprehensive data location question to your assessment , all repositories, not just primary databases
- Ask specifically about collaboration platforms , Teams, Slack, SharePoint, and email , as data repositories
- For vendors handling sensitive data long-term, ask about retention policy coverage for unstructured data specifically
- Ask whether data discovery tooling covers unstructured repositories alongside databases
What to require
Ask directly:
"Beyond your primary database systems, where else within your environment might data you have received from us exist , including document management systems, collaboration platforms, email systems, helpdesk tools, and employee devices , and what data governance applies to each of those locations?"
"Do you apply data discovery and classification tooling to unstructured repositories , document stores, collaboration platforms, and email systems , as well as to your structured databases, and can you confirm that sensitive data in those repositories is governed with equivalent controls?"
"What is your retention and deletion policy for unstructured data , documents, emails, and collaboration content , that contains customer personal data, and how is that policy enforced rather than relying on manual deletion?"
Expect as evidence
- Comprehensive data inventory including unstructured repositories alongside primary databases
- Data discovery tool coverage confirmation , unstructured repositories included in discovery and classification scope
- Collaboration platform governance evidence , access controls, DLP policies, and audit logging enabled
- Retention policy documentation covering unstructured data with automated enforcement confirmation
A vendor who responds to the comprehensive data location question with 'all customer data is stored in our database' should be asked where support tickets are stored, where onboarding documents go, and where customer correspondence is kept. The database holds the records. The accumulated operations of the relationship hold everything else.
How to evidence it
GDPR, CCPA, and HIPAA apply to personal data regardless of format or storage type. Regulatory guidance increasingly recognizes that unstructured data governance is a distinct and required element of data protection compliance , not an optional extension of structured data programs. Demonstrating due diligence requires evidence that unstructured data repositories were assessed as part of vendor data security evaluation.
- Vendor assessment records documenting comprehensive data inventory questions including unstructured repositories
- Collaboration platform governance confirmation for vendors using Teams, Slack, or equivalent platforms
- Data discovery coverage evidence for unstructured repositories
- Retention policy compliance evidence for unstructured data
- Shadow storage control confirmation for vendor employee access to customer data
Key Takeaway
Eighty percent of enterprise data is unstructured , in documents, emails, collaboration platforms, and the accumulated artifacts of every operational interaction between your organization and your vendors. Most vendor data security programs govern the structured twenty percent with considerable rigor and the unstructured eighty percent with almost none. The sensitive data in a database and the sensitive data in a SharePoint folder are equally subject to data protection obligations, equally relevant in a breach investigation, and equally likely to be the thing that a regulator asks about. Assessing vendor data security means assessing where the data actually is , not just where the governance program was designed to look.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association