How many records of PII / PHI / PCI / biometric does Applicant process?
Notification cost scales with records, not with revenue. This number is the best predictor of what a breach would cost you.
What the carrier is actually asking
The carrier wants the volume of regulated records you hold or process, broken down by type where the form allows. It is the direct input to modelling the notification and credit monitoring exposure.
Why it is underwritten
Per-record response costs are reasonably predictable, so the record count multiplied by a per-record figure gives a first-order estimate of a breach. That estimate drives limit adequacy. An understated count produces a limit that looks adequate and is not.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Record volumes in the platforms Insurance Posture reads are partly discoverable, which helps ground an estimate that is otherwise guesswork.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Databases | Row counts in systems holding personal data | The structured footprint, including historical and archived records |
| Microsoft 365 | Content discovery for sensitive information types | The unstructured footprint in mail and collaboration, which is routinely omitted from estimates |
| Azure | Storage and database inventory with data classification | Cloud data stores including backups and reporting copies |
| Retention | How long records are kept | Whether historical records could have been deleted, since retained data is exposure |
| Method | How the estimate was produced | A stated method, which is what makes an approximation defensible |
The fastest way to reduce this number is retention enforcement. Most organisations hold years of records they have no reason to keep, and every one of them is inside the notification population. Deletion is the only control that reduces exposure to zero.
What a defensible yes requires
- The estimate covers structured and unstructured data.
- Historical, archived, and backup copies are included.
- The method is stated and repeatable.
- Types are separated, since health and payment records cost differently from general personal data.
- Retention enforcement is in place so the number falls rather than grows.
How this answer goes wrong
The count comes from the active customer table, excluding a decade of historical records, the reporting copy, and the exports in mailboxes. A breach reaches all of them, and the limit was sized against a fraction.
Frequently asked
How precise must this be?
An order of magnitude with a stated method. Precision is impossible and a defensible method is not.
Do employee records count?
Yes, and they are commonly omitted. Human resources records are personal data and often include health information.
Should we count records we process for clients?
Yes, with the distinction noted. Processor obligations differ from controller obligations, and the records are still in scope of an incident.
How does this affect our limit?
Directly. Multiply the count by a per-record response cost and compare it to the limit. The comparison is often uncomfortable and always useful.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture