Netrik Solutions logo
Report generated by Netrik Solutions

Personal Identification Information Scan Report

CONFIDENTIAL - For authorized personnel only. Handle in accordance with your organization's data protection policies.
Signed HTML
Compliance Report
Date: May 23, 2026 at 12:28 PMSession: 094f4511-7fe7-4d10-8a4a-7eb1fe634353Mode: HYBRIDStatus: Completed
⚙ Configuration Details
Selected country
IN
Selected sector
Other
Selected PII patterns
Phone (India), Aadhaar (India), Aadhaar VID (India), PAN Card (India), Voter ID (India), GSTIN (India), TAN (India), CIN (India), …
Show all 46 patterns
Phone (India), Aadhaar (India), Aadhaar VID (India), PAN Card (India), Voter ID (India), GSTIN (India), TAN (India), CIN (India), Vehicle Registration (India), Ration Card (India), Credit Card (RuPay), UPI ID (India), IFSC (India), ABHA Number (India), ABHA Address (India), Postal Code (India), Passport (India), Driver's License (India), Aadhaar Number (IN), IFSC Code (IN), Indian Passport (IN), Vehicle Plate (IN) (IN), Voter ID (EPIC) (IN), GSTIN (IN), ABHA Health ID (IN), Passport Number (IN), Driving License (IN), Vehicle License Plate (IN), Phone Number (E.164) (IN), EPF UAN Number (IN), Ration Card Number (IN), Corporate ID (CIN) (IN), NPS PRAN Number (IN), Academic Bank of Credits (ABC) ID (IN), Udyam Registration No (IN), Marriage Certificate Serial (IN), Property Index Number (IN), e-Sign Transaction Hash (IN), PAN Card (Income Tax ID) (IN), UPI ID (VPA) (IN), Driving License Number (IN), APAAR / ABC Student ID (IN), DIGIPIN Address (IN), e-Shram Number (IN), Bhu-Aadhar (Land ID) (IN), ESIC IP Number (IN)
Regulations in scope
DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation), PCI DSS v4.0, RBI Tokenization
📄 Scan Details
Scan Session ID
094f4511-7fe7-4d10-8a4a-7eb1fe634353
Scan Mode
HYBRID
Servers Scanned
MySQL
Server IPs
10.192.45.12
Scan Started
5/23/2026, 12:23:09 PM
Scan Completed
2026-05-23 12:23:12
Databases Scanned
1
Tables Scanned
2
📊 Executive summary
58911
Total Findings
9
PII Types
2
Tables
100
Risk Score
⚠ Severity Distribution
37670
CRITICAL
11229
HIGH
10012
MEDIUM
0
LOW
🎨 PII Type Distribution
58911
Total
PII TypeCountShare
Aadhaar (India)
25664.4%
Credit Card
50.0%
IFSC (India)
1000017.0%
PAN Card (India)
895515.2%
Passport
35246.0%
Phone
1122919.1%
Postal Code
1001217.0%
UPI ID (India)
670311.4%
Voter ID
591710.0%
🗃 Database Breakdown
DatabaseTablesFindings
customer_profiles_prod258911
🛡 Scanned, no PII found

These tables were inspected during this session and produced zero PII matches. Listed here so coverage is explicit rather than implied.

HostDatabaseTableScanned At
MySQLcustomer_profiles_produser_activity_logs2026-05-23T12:23:11.895058201+00:00

1 clean table.

🔎 Detailed Findings
#HostDatabaseTableColumnPII TypeClassificationSensitivityCountSeverityConf.ValueCompliance TagsLast Inserted Date
1MySQLcustomer_profiles_prodcustomer_kycaadhaar_numberAadhaar (India)SecretVery High945CRITICAL80%5541 9147 6896DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
2MySQLcustomer_profiles_prodcustomer_kycaadhaar_numberPhoneConfidentialHigh24HIGH80%916149752005DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
3MySQLcustomer_profiles_prodcustomer_kycpan_numberPAN Card (India)SecretVery High8955CRITICAL80%QJIPI7319SDPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
4MySQLcustomer_profiles_prodcustomer_kycpassport_numberPassportSecretVery High3524CRITICAL80%Z9567495DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
5MySQLcustomer_profiles_prodcustomer_kycphonePhoneConfidentialHigh10000HIGH80%+91 6887315806DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
6MySQLcustomer_profiles_prodcustomer_kycpincodePostal CodeInternalMedium10000MEDIUM80%395435DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
7MySQLcustomer_profiles_prodcustomer_kycvoter_idVoter IDSecretVery High5917CRITICAL80%DMS8202274DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
8MySQLcustomer_profiles_prodpayment_methodsbank_account_numberAadhaar (India)SecretVery High266CRITICAL80%2400179938643344DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
9MySQLcustomer_profiles_prodpayment_methodsbank_account_numberCredit CardSecretVery High5CRITICAL80%6088220267141188DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation), PCI DSS v4.0, RBI Tokenization
10MySQLcustomer_profiles_prodpayment_methodsbank_account_numberPhoneConfidentialHigh82HIGH80%09137966800DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
11MySQLcustomer_profiles_prodpayment_methodscredit_card_numberAadhaar (India)SecretVery High1355CRITICAL80%5347 2918 8845DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
12MySQLcustomer_profiles_prodpayment_methodsifsc_codeIFSC (India)SecretVery High10000CRITICAL80%BARB0FD6KSIDPDP Act (Digital Personal Data Protection Act, 2023)
13MySQLcustomer_profiles_prodpayment_methodsupi_idPhoneConfidentialHigh1123HIGH80%7719128618DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
14MySQLcustomer_profiles_prodpayment_methodsupi_idPostal CodeInternalMedium12MEDIUM80%876456DPDP Act (Digital Personal Data Protection Act, 2023), GDPR (General Data Protection Regulation)
15MySQLcustomer_profiles_prodpayment_methodsupi_idUPI ID (India)SecretVery High6703CRITICAL80%shruti.dhillon3062@okaxisDPDP Act (Digital Personal Data Protection Act, 2023)
🛡 Findings by Regulation
DPDP Act (Digital Personal Data Protection Act, 2023)
58911 findings
GDPR (General Data Protection Regulation)
42208 findings
PCI DSS v4.0
5 findings
RBI Tokenization
5 findings
💡 Remediation Hints
  • DPDP: Designate a Data Protection Officer, obtain explicit consent with plain-language notices, and enable data-principal rights (access, correction, erasure) within the prescribed 15 days.
  • GDPR: Document lawful basis for processing, provide data-subject access, and ensure a Data Processing Addendum is in place with every sub-processor.
  • PCI_DSS_V4: Mask PANs (show at most first-6/last-4), rotate encryption keys annually, and segment the cardholder-data environment from the rest of the network.
  • RBI_TOKENIZATION: Replace stored card numbers with network-issued tokens; only card issuers / networks may retain the actual PAN.
  • ISO 27001 / SOC 2: Maintain an asset and data inventory, assign data owners, review access at least quarterly, and retain evidence for audit readiness.
  • NIST Privacy Framework: Map personal-data processing activities, document risk decisions, minimise collection, and track remediation owners with target dates.
  • Data Protection Baseline: Encrypt sensitive data at rest and in transit, rotate keys, enforce least-privilege access, and monitor privileged reads of PII fields.
  • Retention & Disposal: Define retention periods by classification, purge expired records, and verify backups follow the same disposal schedule.
  • Incident Response: Maintain breach triage playbooks, notification decision records, and tested evidence collection procedures for affected data subjects and regulators.