Calendar Icon White
December 2, 2025
Clock Icon
5
 min read

How to Block PII in SharePoint Automatically

Learn how to automatically block personal data (PII) from being uploaded or shared in SharePoint using real-time DLP controls.

How to Block PII in SharePoint Automatically
ChatGPT
Perplexity
Grok
Google AI
Claude
Summarize and analyze this article with:

TL;DR

  • 1. SharePoint cannot block uploads containing PII such as names, SSNs, addresses, emails, or ID numbers.
  • 2. PII leaks into SharePoint through HR forms, ID documents, customer lists, PDFs, spreadsheets, and synced OneDrive directories.
  • 3. Blocking PII is essential for GDPR, CCPA, HIPAA, and global data protection compliance.
  • 4. Manual blocking is impossible because PII hides inside PDFs, scans, multi-tab spreadsheets, and images.
  • 5. Strac blocks PII in SharePoint in real time—preventing risky uploads, edits, external shares, and OneDrive syncs from containing personal data.
  • SharePoint does not inspect document content for personal data and cannot stop files containing PII from being uploaded or shared. Its native controls focus on permissions, not content protection.

    SharePoint’s core limitations:

    • No content inspection to block files containing PII
    • No OCR for images or scanned IDs
    • No blocking for PDFs or multi-sheet Excel files
    • No PII-specific rules for GDPR/CCPA
    • No ability to prevent OneDrive sync uploads containing PII
    • No external sharing blocks based on content
    • No bulk upload prevention for PII-heavy folders

    This means PII can enter SharePoint freely—even into highly sensitive libraries—creating compliance and privacy exposure.

    What PII (Personal Data) Uploads Look Like Inside SharePoint

    PII enters SharePoint across dozens of everyday workflows. Content that often triggers PII blocking includes:

    • HR documents with full names, SSNs, addresses, phone numbers
    • Scanned passports, driver’s licenses, and national ID photos
    • CSV exports with customer lists
    • Payroll documents and tax forms
    • PDFs containing email addresses or signatures
    • Call logs and chat transcripts
    • Screenshots and mobile photos
    • Vendor onboarding forms with personal contact data

    Strac blocks common PII types such as:

    • Full names of employees or customers
    • Phone numbers
    • Addresses
    • Email addresses
    • Government ID numbers
    • Social Security Numbers (SSNs)
    • Tax identifiers
    • Passport and driver’s license numbers
    • Birthdates
    • Contact details stored in spreadsheets
    • PII inside images, scanned forms, and PDFs

    Blocking these uploads ensures PII never enters a non-compliant workspace.

    ✨What It Means to Block PII (Personal Data) in SharePoint

    Blocking PII means preventing sensitive personal data from entering SharePoint at all—or stopping risky actions involving PII.

    Blocking can apply to:

    • File uploads
    • New versions of existing files
    • OneDrive sync activity
    • External sharing
    • Guest access
    • Bulk folder uploads
    • Automated workflows that push PII into libraries

    Strac’s PII blocking engine supports:

    • Real-time content inspection
    • Policy-based blocking
    • AI + OCR detection
    • Multi-file, multi-library rules
    • Per-user or per-department settings
    • Custom PII categories
    • Blocking with full audit logs

    Blocking is the strongest form of PII protection because it prevents exposure before it happens.

    Starc SharePoint DLP

    How to Automatically Block PII (Personal Data) in SharePoint with Strac

    Strac inspects each file as it is uploaded, edited, synced, or shared. If PII is detected, the action is blocked instantly—and the PII never enters SharePoint.

    How Strac blocking works:

    • Scans real-time uploads and edits
    • Uses ML, OCR, and NLP to detect PII
    • Blocks files before they are stored or shared
    • Notifies security/compliance teams
    • Logs all actions for privacy regulations
    • Supports selective blocking (ex: block SSNs but not emails)
    • Supports library-based or site-based rules
    • Protects against risky external shares

    Strac can also block:

    • OneDrive sync events containing PII
    • Automated flows from Power Automate
    • Bulk uploads or imports
    • ZIP folders containing multiple PII files

    Real Examples of PII (Personal Data) Blocking in SharePoint

    Example 1 — HR uploads onboarding packet with SSN
    Strac blocks the upload and logs the incident instantly.

    Example 2 — Employee uploads passport photo
    OCR detects the ID number and blocks the file.

    Example 3 — Customer list spreadsheet with names and emails
    Strac blocks multi-row data containing PII.

    Example 4 — OneDrive tries to sync scanned tax forms
    Sync is blocked before any PII enters SharePoint.

    Each block event includes full metadata and compliance context.

    Why Strac Is the Best Way to Block PII (Personal Data) in SharePoint

    • Blocks PII across SharePoint + OneDrive in real time
    • AI + OCR for images, PDFs, scans, and spreadsheets
    • Supports GDPR, CCPA, HIPAA, FERPA, GLBA and global privacy laws
    • Zero-agent deployment
    • Context-aware blocking reduces false positives
    • Full visibility into PII attempts and incidents
    • Integrates with Slack, Teams, SIEM tools, and email

    🌶️Spicy FAQs on How to Block PII (Personal Data) in SharePoint

    Does SharePoint block files containing PII?

    No. SharePoint cannot detect or block personal data.

    Can Strac block PII inside images and scanned IDs?

    Yes. OCR identifies PII within photos, scans, and screenshots.

    Will Strac block PII in spreadsheets and PDFs?

    Yes. Strac inspects all file types before upload or sync.

    Can we block only certain PII types like SSNs?

    Yes. You can configure rules for specific PII categories.

    Does blocking support compliance with GDPR and CCPA?

    Yes. Blocking prevents unauthorized PII storage and exposure.

    Try Strac for SharePoint PII (Personal Data) Blocking & DLP

    Strac helps you automatically detect, classify, and block personal data (PII) across SharePoint libraries, folders, synced OneDrive content, and shared documents—ensuring compliance and preventing exposure before it happens.

    Discover & Protect Data on SaaS, Cloud, Generative AI
    Strac provides end-to-end data loss prevention for all SaaS and Cloud apps. Integrate in under 10 minutes and experience the benefits of live DLP scanning, live redaction, and a fortified SaaS environment.
    Users Most Likely To Recommend 2024 BadgeG2 High Performer America 2024 BadgeBest Relationship 2024 BadgeEasiest to Use 2024 Badge
    Trusted by enterprises
    Discover & Remediate PII, PCI, PHI, Sensitive Data

    Latest articles

    Browse all

    Get Your Datasheet

    Thank you! Your submission has been received!
    Oops! Something went wrong while submitting the form.
    Close Icon