Nyvika can't sign in to Google as you. Instead you create a service account, a robot account Google provides, share the folder with it as a viewer, and give Nyvika the robot's key file. The whole job takes about ten minutes and the connection is read-only.
.iam.gserviceaccount.com./folders/ in drive.google.com/drive/folders/…. For a shared drive, use the drive's id the same way.gdrive:// prefix.
Here a test sheet in the folder held a phone number, an email address and a PAN. Each is stored masked, with the classifier's confidence. The folder's declared purpose, enquiries, doesn't need a PAN, so the store is flagged un-minimised and the PAN is marked red: either that column goes, or there is a real purpose for it that belongs on your register. That is section 8(4) and the minimisation principle, turned into a red dot.
Make a folder with one Google Sheet of made-up rows (a name, a phone number, an email, a PAN) and connect that before a real one. You'll see exactly what a finding looks like in a minute.
The breach register lets you pick this store as an affected system, impact assessments can reference it, and the record-of-processing report lists it.
When you're done testing, press Remove on the test store so it doesn't stay in reports, or keep it as a known-clean example.

No. A scan reads a bounded sample of each file, classifies it, and keeps only the finding: which identifier types, how many, where, and a masked sample. The service-account key is encrypted on arrival and used only for scans you start.
Not in this release. A service account suits a company drive and keeps the connection working when people leave. A personal sign-in flow is on the roadmap.
Almost always one of two things: the Drive API isn't enabled in the project (Part A, step 2), or the folder isn't shared with the service account's email (Part B, step 1). Fix the one that applies and run the scan again.
Still stuck? Write to us with the exact error message.
Ten data sources scanned for Indian identifiers, plus import
See data discovery →The 72-hour clock, ordered steps, a drafted Board report
See breach response →Hash-chained ledger, nine reports, a compliance score you can read
See ledger, reports & audit →